A three-tiered intrusion detection system for industrial control systems
A three-tiered intrusion detection system for industrial control systems
复制标题
工业控制系统的三层入侵检测系统
DOI:
10.1093/cybsec/tyab006
复制
发表时间:
2021
影响因子:
3.9
通讯作者:
Anthi E
中科院分区:
文献类型:
--
作者:
Anthi E
This article presents three-tiered intrusion detection systems, which uses a supervised approach to detect cyber-attacks in industrial control systems networks. The proposed approach does not only aim to identify malicious packets on the network but also attempts to identify the general and finer grain attack type occurring on the network. This is key in the industrial control systems environment as the ability to identify exact attack types will lead to an increased response rate to the incident and the defence of the infrastructure. More specifically, the proposed system consists of three stages that aim to classify: (i) whether packets are malicious; (ii) the general attack type of malicious packets (e.g. Denial of Service); and (iii) finer-grained cyber-attacks (e.g. bad cyclic redundancy check, attack). The effectiveness of the proposed intrusion detection systems is evaluated on network data collected from a real industrial gas pipeline system. In addition, an insight is provided as to which features are most relevant in detecting such malicious behaviour. The performance of the system results in anF-measure of: (i) 87.4%, (ii) 74.5% and (iii) 41.2%, for each of the layers, respectively. This demonstrates that the proposed architecture can successfully distinguish whether network activity is malicious and detect which general attack was deployed.
DOI:
--
发表时间:
2006
期刊:
--
影响因子:
--
作者:
K. Stouffer;J. Falco;K. Kent;T. Grance;R. Ross
通讯作者:
K. Stouffer;J. Falco;K. Kent;T. Grance;R. Ross
DOI:
--
发表时间:
2019
期刊:
ARES
影响因子:
--
作者:
H. R. Ghaeini;Nils Ole Tippenhauer;Jianying Zhou
通讯作者:
Jianying Zhou
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
Ian P. Turnipseed
通讯作者:
Ian P. Turnipseed