Anomaly-based Intrusion Detection in Industrial Data with SVM and Random Forests

07/24/2019
by   Simon D. Duque Anton, et al.
0

Attacks on industrial enterprises are increasing in number as well as in effect. Since the introduction of industrial control systems in the 1970's, industrial networks have been the target of malicious actors. More recently, the political and warfare-aspects of attacks on industrial and critical infrastructure are becoming more relevant. In contrast to classic home and office IT systems, industrial IT, so-called OT systems, have an effect on the physical world. Furthermore, industrial devices have long operation times, sometimes several decades. Updates and fixes are tedious and often not possible. The threats on industry with the legacy requirements of industrial environments creates the need for efficient intrusion detection that can be integrated into existing systems. In this work, the network data containing industrial operation is analysed with machine learning- and time series- based anomaly detection algorithms in order to discover the attacks introduced to the data. Two different data sets are used, one Modbus-based gas pipeline control traffic and one OPC UA-based batch processing traffic. In order to detect attacks, two machine learning-based algorithms are used, namely SVM and Random Forest. Both perform well, with Random Forest slightly outperforming SVM. Furthermore, extracting and selecting features as well as handling missing data is addressed in this work.

READ FULL TEXT
research
05/28/2019

Evaluation of Machine Learning-based Anomaly Detection Algorithms on an Industrial Modbus/TCP Data Set

In the context of the Industrial Internet of Things, communication techn...
research
04/29/2023

POET: A Self-learning Framework for PROFINET Industrial Operations Behaviour

Since 2010, multiple cyber incidents on industrial infrastructure, such ...
research
05/28/2019

Implementing SCADA Scenarios and Introducing Attacks to Obtain Training Data for Intrusion Detection Methods

There are hardly any data sets publicly available that can be used to ev...
research
04/27/2021

Extending Isolation Forest for Anomaly Detection in Big Data via K-Means

Industrial Information Technology (IT) infrastructures are often vulnera...
research
12/08/2019

Detecting Cyberattacks in Industrial Control Systems Using Online Learning Algorithms

Industrial control systems are critical to the operation of industrial f...
research
08/31/2023

Towards Low-Barrier Cybersecurity Research and Education for Industrial Control Systems

The protection of Industrial Control Systems (ICS) that are employed in ...
research
11/02/2019

Anomaly Detection for Industrial Control Networks using Machine Learning with the help from the Inter-Arrival Curves

Industrial Control Networks (ICN) such as Supervisory Control and Data A...

Please sign up or login with your details

Forgot password? Click here to reset