Towards Low-Barrier Cybersecurity Research and Education for Industrial Control Systems

Towards Low-Barrier Cybersecurity Research and Education for Industrial Control Systems
复制标题

DOI:
10.1109/isi58743.2023.10297207
复制
发表时间:
2023-08
期刊:
2023 IEEE International Conference on Intelligence and Security Informatics (ISI)
影响因子:
--
通讯作者:
Colman McGuan;Chansu Yu;Qin Lin
Colman McGuan;Chansu Yu;Qin Lin
中科院分区:
其他
文献类型:
--
作者:
Colman McGuan;Chansu Yu;Qin Lin

文献摘要

相似文献

由于网络攻击可能造成灾难性的物理损害,因此保护公共关键基础设施中使用的工业控制系统 (ICS) 至关重要。研究界需要测试平台来验证和比较各种入侵检测算法以保护 ICS。然而,由于昂贵的硬件、软件以及操纵现实世界系统的固有危险,ICS 网络安全领域的研究和教育存在很高的进入壁垒。为了缩小差距,我们在最近开发的 3D 高保真模拟器的基础上,进一步展示了我们的集成框架,用于自动发起网络攻击、收集数据、训练机器学习模型以及评估实用的化学和制造流程。在我们的测试平台上,我们验证了我们提出的名为最小阈值和窗口 SVM (MinTWin SVM) 的入侵检测模型,该模型通过一类 SVM 结合滑动窗口和分类阈值利用无监督机器学习。结果表明,MinTWin SVM 最大限度地减少了误报,并且能够响应物理过程异常。此外,我们通过在本科机器学习课程中使用我们的数据集,将我们的框架与 ICS 网络安全教育相结合,学生可以通过实际的 ICS 数据集获得实践机器学习理论的实践经验。我们所有的实现都是开源的。
The protection of Industrial Control Systems (ICS) that are employed in public critical infrastructures is of utmost importance due to catastrophic physical damages cyberattacks may cause. The research community requires testbeds for validation and comparing various intrusion detection algorithms to protect ICS. However, there exist high barriers to entry for research and education in the ICS cybersecurity domain due to expensive hardware, software, and inherent dangers of manipulating real-world systems. To close the gap, built upon recently developed 3D high-fidelity simulators, we further showcase our integrated framework to automatically launch cyberattacks, collect data, train machine learning models, and evaluate for practical chemical and manufacturing processes. On our testbed, we validate our proposed intrusion detection model called Minimal Threshold and Window SVM (MinTWin SVM) that utilizes unsupervised machine learning via a one-class SVM in combination with a sliding window and classification threshold. Results show that MinTWin SVM minimizes false positives and is responsive to physical process anomalies. Furthermore, we incorporate our framework with ICS cybersecurity education by using our dataset in an undergraduate machine learning course where students gain hands-on experience in practicing machine learning theory with a practical ICS dataset. All of our implementations have been open-sourced.