A False Sense of Security? Revisiting the State of Machine Learning-Based Industrial Intrusion Detection

05/18/2022
by   Dominik Kus, et al.
0

Anomaly-based intrusion detection promises to detect novel or unknown attacks on industrial control systems by modeling expected system behavior and raising corresponding alarms for any deviations.As manually creating these behavioral models is tedious and error-prone, research focuses on machine learning to train them automatically, achieving detection rates upwards of 99 these approaches are typically trained not only on benign traffic but also on attacks and then evaluated against the same type of attack used for training. Hence, their actual, real-world performance on unknown (not trained on) attacks remains unclear. In turn, the reported near-perfect detection rates of machine learning-based intrusion detection might create a false sense of security. To assess this situation and clarify the real potential of machine learning-based industrial intrusion detection, we develop an evaluation methodology and examine multiple approaches from literature for their performance on unknown attacks (excluded from training). Our results highlight an ineffectiveness in detecting unknown attacks, with detection rates dropping to between 3.2 14.7 further research on machine learning-based approaches to ensure clarity on their ability to detect unknown attacks.

READ FULL TEXT

page 7

page 9

research
12/22/2021

Detect Reject for Transferability of Black-box Adversarial Attacks Against Network Intrusion Detection Systems

In the last decade, the use of Machine Learning techniques in anomaly-ba...
research
05/28/2019

Implementing SCADA Scenarios and Introducing Attacks to Obtain Training Data for Intrusion Detection Methods

There are hardly any data sets publicly available that can be used to ev...
research
09/23/2021

An Anomaly-based Multi-class Classifier for Network Intrusion Detection

Network intrusion detection systems (NIDS) are one of several solutions ...
research
07/20/2022

Digital Twin-based Intrusion Detection for Industrial Control Systems

Digital twins have recently gained significant interest in simulation, o...
research
11/01/2020

Unsupervised Intrusion Detection System for Unmanned Aerial Vehicle with Less Labeling Effort

Along with the importance of safety, an IDS has become a significant tas...
research
05/27/2020

Identifying Vulnerabilities of Industrial Control Systems using Evolutionary Multiobjective Optimisation

In this paper we propose a novel methodology to assist in identifying vu...

Please sign up or login with your details

Forgot password? Click here to reset