Temporal Phase Shifts in SCADA Networks

08/15/2018
by   Chen Markman, et al.
0

In Industrial Control Systems (ICS/SCADA), machine to machine data traffic is highly periodic. Previous work showed that in many cases, it is possible to create an automata-based model of the traffic between each individual Programmable Logic Controller (PLC) and the SCADA server, and to use the model to detect anomalies in the traffic. When testing the validity of previous models, we noticed that overall, the models have difficulty in dealing with communication patterns that change over time. In this paper we show that in many cases the traffic exhibits phases in time, where each phase has a unique pattern, and the transition between the different phases is rather sharp. We suggest a method to automatically detect traffic phase shifts, and a new anomaly detection model that incorporates multiple phases of the traffic. Furthermore we present a new sampling mechanism for training set assembly, which enables the model to learn all phases during the training stage with lower complexity. The model presented has similar accuracy and much less permissiveness compared to the previous general DFA model. Moreover, the model can provide the operator with information about the state of the controlled process at any given time, as seen in the traffic phases.

READ FULL TEXT

page 5

page 6

page 8

research
10/12/2020

AttendLight: Universal Attention-Based Reinforcement Learning Model for Traffic Signal Control

We propose AttendLight, an end-to-end Reinforcement Learning (RL) algori...
research
08/28/2023

Traffic Light Control with Reinforcement Learning

Traffic light control is important for reducing congestion in urban mobi...
research
08/11/2017

Time Series Anomaly Detection; Detection of anomalous drops with limited features and sparse examples in noisy highly periodic data

Google uses continuous streams of data from industry partners in order t...
research
11/06/2022

Cementron: Machine Learning the Constituent Phases in Cement Clinker from Optical Images

Cement is the most used construction material. The performance of cement...
research
03/17/2014

Multi-task Feature Selection based Anomaly Detection

Network anomaly detection is still a vibrant research area. As the fast ...
research
09/12/2019

pForest: In-Network Inference with Random Forests

The concept of "self-driving networks" has recently emerged as a possibl...

Please sign up or login with your details

Forgot password? Click here to reset