Two-phase Dual COPOD Method for Anomaly Detection in Industrial Control System

04/30/2023
by   Emmanuel Aboah Boateng, et al.
0

Critical infrastructures like water treatment facilities and power plants depend on industrial control systems (ICS) for monitoring and control, making them vulnerable to cyber attacks and system malfunctions. Traditional ICS anomaly detection methods lack transparency and interpretability, which make it difficult for practitioners to understand and trust the results. This paper proposes a two-phase dual Copula-based Outlier Detection (COPOD) method that addresses these challenges. The first phase removes unwanted outliers using an empirical cumulative distribution algorithm, and the second phase develops two parallel COPOD models based on the output data of phase 1. The method is based on empirical distribution functions, parameter-free, and provides interpretability by quantifying each feature's contribution to an anomaly. The method is also computationally and memory-efficient, suitable for low- and high-dimensional datasets. Experimental results demonstrate superior performance in terms of F1-score and recall on three open-source ICS datasets, enabling real-time ICS anomaly detection.

READ FULL TEXT
research
10/15/2020

Securing Manufacturing Using Blockchain

Due to the rise of Industrial Control Systems (ICSs) cyber-attacks in th...
research
11/12/2019

Anomaly Detection for Industrial Control Systems Using Sequence-to-Sequence Neural Networks

This study proposes an anomaly detection method for operational data of ...
research
01/31/2023

Real-Time Outlier Detection with Dynamic Process Limits

Anomaly detection methods are part of the systems where rare events may ...
research
08/19/2023

Practical Anomaly Detection over Multivariate Monitoring Metrics for Online Services

As modern software systems continue to grow in terms of complexity and v...
research
05/25/2023

Towards Total Online Unsupervised Anomaly Detection and Localization in Industrial Vision

Although existing image anomaly detection methods yield impressive resul...
research
03/24/2023

Interpretable Anomaly Detection via Discrete Optimization

Anomaly detection is essential in many application domains, such as cybe...
research
06/21/2018

Anomaly detection; Industrial control systems; convolutional neural networks

This paper presents a study on detecting cyberattacks on industrial cont...

Please sign up or login with your details

Forgot password? Click here to reset