Assessment of Cyber-Physical Intrusion Detection and Classification for Industrial Control Systems

02/18/2022
by   Nils Müller, et al.
0

The increasing interaction of industrial control systems (ICSs) with public networks and digital devices introduces new cyber threats to power systems and other critical infrastructure. Recent cyber-physical attacks such as Stuxnet and Irongate revealed unexpected ICS vulnerabilities and a need for improved security measures. Intrusion detection systems constitute a key security technology, which typically monitor network data for detecting malicious activities. However, a central characteristic of modern ICSs is the increasing interdependency of physical and cyber network processes. Thus, the integration of network and physical process data is seen as a promising approach to improve predictability in intrusion detection for ICSs by accounting for physical constraints and underlying process patterns. This work systematically assesses real-time cyber-physical intrusion detection and multiclass classification, based on a comparison to its purely network data-based counterpart and evaluation of misclassifications and detection delay. Multiple supervised machine learning models are applied on a recent cyber-physical dataset, describing various cyber attacks and physical faults on a generic ICS. A key finding is that integration of physical process data improves detection and classification of all attack types. In addition, it enables simultaneous processing of attacks and faults, paving the way for holistic cross-domain cause analysis.

READ FULL TEXT
research
05/08/2019

Convolutional Neural Network for Intrusion Detection System In Cyber Physical Systems

The extensive use of Information and Communication Technology in critica...
research
10/25/2021

Anomaly-Based Intrusion Detection System for Cyber-Physical System Security

Over the past decade, industrial control systems have experienced a mass...
research
10/14/2022

Let's Talk Through Physics! Covert Cyber-Physical Data Exfiltration on Air-Gapped Edge Devices

Although organizations are continuously making concerted efforts to hard...
research
11/08/2019

Intrusion Detection for Industrial Control Systems: Evaluation Analysis and Adversarial Attacks

Neural networks are increasingly used in security applications for intru...
research
01/18/2021

Multi-Source Data Fusion for Cyberattack Detection in Power Systems

Cyberattacks can cause a severe impact on power systems unless detected ...
research
01/29/2020

Intrusion Detection Systems: A Cross-Domain Overview

The cybersecurity ecosystem continuously changes with the growth of cybe...
research
04/11/2023

Late Breaking Results: Scalable and Efficient Hyperdimensional Computing for Network Intrusion Detection

Cybersecurity has emerged as a critical challenge for the industry. With...

Please sign up or login with your details

Forgot password? Click here to reset