Multigranularity Feature Automatic Marking-Based Deep Learning for Anomaly Detection of Industrial Control Systems

被引:1
|
作者
Du, Xinyi [1 ,2 ,3 ]
Xu, Chi [2 ,3 ]
Li, Lin [2 ]
Li, Xinchun [1 ]
机构
[1] Liaoning Tech Univ, Sch Elect & Informat Engn, Huludao 125105, Peoples R China
[2] Chinese Acad Sci, Shenyang Inst Automat, State Key Lab Robot, Shenyang 110016, Peoples R China
[3] Chinese Acad Sci, Key Lab Networked Control Syst, Shenyang 110016, Peoples R China
来源
IEEE OPEN JOURNAL OF INSTRUMENTATION AND MEASUREMENT | 2024年 / 3卷
基金
中国国家自然科学基金;
关键词
Protocols; Feature extraction; Anomaly detection; Deep learning; Industrial control; Convolutional neural networks; Security; convolutional neural network; deep learning; feature automatic marking; feature extraction; industrial control protocol (ICP);
D O I
10.1109/OJIM.2024.3418466
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Industrial control systems are facing ever-increasing security challenges due to the large-scale access of heterogeneous devices in the open Internet environment. Existing anomaly detection methods are mainly based on the priori knowledge of industrial control protocols (ICPs) whose protocol specifications, communication mechanism, and data format are already known. However, when these knowledge are blank, namely, unknown ICPs, existing methods become powerless to detect the anomaly data. To tackle this challenge, we propose a multigranularity feature automatic marking-based deep learning method to classify unknown ICPs for anomaly detection. First, to obtain the feature sequences without priori knowledge assisting, we propose a multigranularity feature extraction algorithm to extract both byte and half-byte information by fully utilizing the intensive key information in the header field of the application layer. Then, to label the feature sequences for deep learning, we propose a feature automatic marking algorithm that utilizes the inconsistency feature sequences to dynamically update the feature sequence set. With the labeled feature sequences, we employ deep learning with 1-D convolutional neural network and gated recurrent unit to classify the unknown ICPs and realize anomaly detection. Extensive experiments on two public datasets show that both the accuracy and precision of the proposed method reach above 98.4%, which is better than the three benchmark methods.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] Federated Learning-Based Explainable Anomaly Detection for Industrial Control Systems
    Huong, Truong Thu
    Bac, Ta Phuong
    Ha, Kieu Ngan
    Hoang, Nguyen Viet
    Hoang, Nguyen Xuan
    Hung, Nguyen Tai
    Tran, Kim Phuc
    IEEE ACCESS, 2022, 10 : 53854 - 53872
  • [32] Deep Autoencoder-Based Integrated Model for Anomaly Detection and Efficient Feature Extraction in IoT Networks
    Alaghbari, Khaled A.
    Lim, Heng-Siong
    Saad, Mohamad Hanif Md
    Yong, Yik Seng
    IOT, 2023, 4 (03): : 345 - 365
  • [33] Deep Generative Models-Based Anomaly Detection for Spacecraft Control Systems
    Ahn, Hyojung
    Jung, Dawoon
    Choi, Han-Lim
    SENSORS, 2020, 20 (07)
  • [34] Metric Learning-Based Fault Diagnosis and Anomaly Detection for Industrial Data With Intraclass Variance
    Huang, Keke
    Wu, Shujie
    Sun, Bei
    Yang, Chunhua
    Gui, Weihua
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (01) : 547 - 558
  • [35] Leveraging feature subset selection with deer hunting optimizer based deep learning for anomaly detection in secure cloud environment
    Bai, V. Sujatha
    Punithavalli, M.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (25) : 65949 - 65966
  • [36] A hybrid prototype selection-based deep learning approach for anomaly detection in industrial machines
    Monteiro, Rodrigo de Paula
    Lozada, Mariela Cerrada
    Mendieta, Diego Roman Cabrera
    Loja, Rene Vinicio Sanchez
    Filho, Carmelo Jose Albanez Bastos
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 204
  • [37] SoK of Machine Learning and Deep Learning Based Anomaly Detection Methods for Automatic Dependent Surveillance- Broadcast
    Cevik, Nursah
    Akleylek, Sedat
    IEEE ACCESS, 2024, 12 : 35643 - 35662
  • [38] BGP Anomaly Detection Based on Automatic Feature Extraction by Neural Network
    Xu, Mengying
    Li, Xing
    PROCEEDINGS OF 2020 IEEE 5TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2020), 2020, : 46 - 50
  • [39] Anomaly Detection Based on Data Super-Resolution in Industrial CyberPhysical Systems With Multirate Sampling
    Du, Xin
    Zhou, Chunjie
    Tian, Yu-Chu
    Wang, Kunkun
    IEEE SENSORS JOURNAL, 2024, 24 (10) : 16478 - 16490
  • [40] Research on Feature Selection of Intrusion Detection Based on Deep Learning
    Xin, Mingyuan
    Wang, Yong
    2020 16TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC, 2020, : 1431 - 1434