FALCON: Framework for Anomaly Detection in Industrial Control Systems

FALCON: Framework for Anomaly Detection in Industrial Control Systems
复制标题

DOI:
10.3390/electronics9081192
复制
发表时间:
2020-08-01
期刊:
影响因子:
2.9
通讯作者:
Mehrpouyan, Hoda
Mehrpouyan, Hoda
中科院分区:
工程技术3区
文献类型:
--
作者:
Sapkota, Subin;Mehdy, A. K. M. Nuhil;Mehrpouyan, Hoda

文献摘要

被引文献

相似文献

工业控制系统 (ICS) 用于控制关键基础设施中的物理过程。这些系统广泛用于水处理、发电和配电以及制造等各种操作中。虽然这些系统的安全性和安保问题令人严重关切,但最近的报告显示,旨在操纵物理过程以造成灾难性后果的针对性攻击有所增加。这一趋势强调需要提供弹性和智能攻击检测机制来保护 ICS 的算法和工具。在本文中,我们提出了一种基于深度神经网络的 ICS 异常检测框架。所提出的方法使用扩张卷积和长短期记忆 (LSTM) 层来学习 ICS 中传感器和执行器数据内的时间和长期依赖性。传感器/执行器数据通过独特的特征工程管道传递,其中对传感器信号应用小波变换以提取输入模型的特征。此外,本文还探讨了监督深度学习模型的四种变体,以及针对该问题的无监督支持向量机(SVM)模型。所提出的框架在安全水处理测试台结果上得到了验证。与之前发布的方法相比,该框架可以在更短的时间内检测到更多的攻击。
Industrial Control Systems (ICS) are used to control physical processes in critical infrastructure. These systems are used in a wide variety of operations such as water treatment, power generation and distribution, and manufacturing. While the safety and security of these systems are of serious concern, recent reports have shown an increase in targeted attacks aimed at manipulating physical processes to cause catastrophic consequences. This trend emphasizes the need for algorithms and tools that provide resilient and smart attack detection mechanisms to protect ICS. In this paper, we propose an anomaly detection framework for ICS based on a deep neural network. The proposed methodology uses dilated convolution and long short-term memory (LSTM) layers to learn temporal as well as long term dependencies within sensor and actuator data in an ICS. The sensor/actuator data are passed through a unique feature engineering pipeline where wavelet transformation is applied to the sensor signals to extract features that are fed into the model. Additionally, this paper explores four variations of supervised deep learning models, as well as an unsupervised support vector machine (SVM) model for this problem. The proposed framework is validated on Secure Water Treatment testbed results. This framework detects more attacks in a shorter period of time than previously published methods.