Graph Convolutional Network-based Suspicious Communication Pair Estimation for Industrial Control Systems

07/17/2020
by   Tatsumi Oba, et al.
0

Whitelisting is considered an effective security monitoring method for networks used in industrial control systems, where the whitelists consist of observed tuples of the IP address of the server, the TCP/UDP port number, and IP address of the client (communication triplets). However, this method causes frequent false detections. To reduce false positives due to a simple whitelist-based judgment, we propose a new framework for scoring communications to judge whether the communications not present in whitelists are normal or anomalous. To solve this problem, we developed a graph convolutional network-based suspicious communication pair estimation using relational graph convolution networks, and evaluated its performance. For this, we collected the network traffic of three factories owned by Panasonic Corporation, Japan. The proposed method achieved a receiver operating characteristic area under the curve of 0.957, which outperforms baseline approaches such as DistMult, a method that directly optimizes the node embeddings, and heuristics, which score the triplets using first- and second-order proximities of multigraphs. This method enables security operators to concentrate on significant alerts.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/28/2021

Interaction-GCN: a Graph Convolutional Network based framework for social interaction recognition in egocentric videos

In this paper we propose a new framework to categorize social interactio...
research
12/30/2019

ICSTrace: A Malicious IP Traceback Model for Attacking Data of Industrial Control System

Considering the attacks against industrial control system are mostly org...
research
12/18/2021

GCN-Geo: A Graph Convolution Network-based Fine-grained IP Geolocation Framework

Classical fine-grained measurement-based IP geolocation algorithms often...
research
04/29/2020

Directed Graph Convolutional Network

Graph Convolutional Networks (GCNs) have been widely used due to their o...
research
10/17/2019

Detecting intracranial aneurysm rupture from 3D surfaces using a novel GraphNet approach

Intracranial aneurysm (IA) is a life-threatening blood spot in human's b...
research
01/18/2022

Deep Graph Convolutional Network and LSTM based approach for predicting drug-target binding affinity

Development of new drugs is an expensive and time-consuming process. Due...
research
11/09/2017

IP Video Conferencing: A Tutorial

Video conferencing is a well-established area of communications, which h...

Please sign up or login with your details

Forgot password? Click here to reset