Hybrid attack detection framework for industrial control systems using 1D-convolutional neural network and isolation forest
Author | Elnour, M. |
Author | Meskin, Nader |
Author | Khan, K.M. |
Available date | 2022-04-14T08:45:39Z |
Publication Date | 2020 |
Publication Name | CCTA 2020 - 4th IEEE Conference on Control Technology and Applications |
Resource | Scopus |
Identifier | http://dx.doi.org/10.1109/CCTA41146.2020.9206394 |
Abstract | Industrial control systems (ICSs) are used in various infrastructures and industrial plants for realizing their control operation and ensuring their safety. Concerns about the cybersecurity of industrial control systems have raised due to the increased number of cyber-attack incidents on critical infrastructures in the light of the advancement in the cyber activity of ICSs. Nevertheless, the operation of the industrial control systems is bind to vital aspects in life, which are safety, economy, and security. This paper presents a semi-supervised, hybrid attack detection approach for industrial control systems by combining Isolation Forest and Convolutional Neural Network (CNN) models. The proposed framework is developed using the normal operational data, and it is composed of a feature extraction model implemented using a One-Dimensional Convolutional Neural Network (1D-CNN) and an isolation forest model for the detection. The two models are trained independently such that the feature extraction model aims to extract useful features from the continuous-time signals that are then used along with the binary actuator signals to train the isolation forest-based detection model. The proposed approach is applied to a down-scaled industrial control system, which is a water treatment plant known as the Secure Water Treatment (SWaT) testbed. The performance of the proposed method is compared with the other works using the same testbed, and it shows an improvement in terms of the detection capability. |
Sponsor | Qatar Foundation; Qatar National Research Fund |
Language | en |
Publisher | Institute of Electrical and Electronics Engineers Inc. |
Subject | Accident prevention Continuous time systems Control systems Convolution Convolutional neural networks Extraction Feature extraction Forestry Security of data Testbeds Actuator signals Attack detection Continuous-time signal Control operations Detection capability Detection models Industrial control systems Operational data Industrial water treatment |
Type | Conference |
Pagination | 877-884 |
Files in this item
Files | Size | Format | View |
---|---|---|---|
There are no files associated with this item. |
This item appears in the following Collection(s)
-
Electrical Engineering [2811 items ]