A Machine Learning Approach for Anomaly Detection in Industrial Control Systems Based on Measurement Data

A Machine Learning Approach for Anomaly Detection in Industrial Control Systems Based on Measurement Data
复制标题

DOI:
10.3390/electronics10040407
复制
发表时间:
2021-02-01
期刊:
影响因子:
2.9
通讯作者:
Sargolzaei, Arman
Sargolzaei, Arman
中科院分区:
工程技术3区
文献类型:
--
作者:
Mokhtari, Sohrab;Abbaspour, Alireza;Sargolzaei, Arman

文献摘要

被引文献

相似文献

工业控制系统(ICS)中的攻击检测问题通常被称为用于检测异常活动的网络流量监控方案。然而,基于网络的入侵检测系统可能会被模仿系统正常活动的攻击者所欺骗。在这项工作中,我们基于监控和​​数据采集(SCADA)系统中的测量数据提出了一种解决该问题的新颖解决方案。所提出的方法称为测量入侵检测系统(MIDS),它使系统能够检测到系统中的任何异常活动,即使攻击者试图将其隐藏在系统的控制层中。生成监督机器学习模型来对 ICS 中的正常和异常活动进行分类,以评估 MIDS 性能。开发了硬件在环(HIL)测试台来模拟发电机组并利用攻击数据集。在所提出的方法中,我们在数据集上应用了多种机器学习模型,这些模型在检测数据集的异常,特别是隐形攻击方面表现出了卓越的性能。结果表明,在根据测试台中的测量数据检测异常方面,随机森林的表现优于其他分类器算法。
Attack detection problems in industrial control systems (ICSs) are commonly known as a network traffic monitoring scheme for detecting abnormal activities. However, a network-based intrusion detection system can be deceived by attackers that imitate the system's normal activity. In this work, we proposed a novel solution to this problem based on measurement data in the supervisory control and data acquisition (SCADA) system. The proposed approach is called measurement intrusion detection system (MIDS), which enables the system to detect any abnormal activity in the system even if the attacker tries to conceal it in the system's control layer. A supervised machine learning model is generated to classify normal and abnormal activities in an ICS to evaluate the MIDS performance. A hardware-in-the-loop (HIL) testbed is developed to simulate the power generation units and exploit the attack dataset. In the proposed approach, we applied several machine learning models on the dataset, which show remarkable performances in detecting the dataset's anomalies, especially stealthy attacks. The results show that the random forest is performing better than other classifier algorithms in detecting anomalies based on measured data in the testbed.