Industrial control system device classification using network traffic features and neural network embeddings

被引:3
作者
Chakraborty, Indrasis [1 ]
Kelley, Brian M. [1 ]
Gallagher, Brian [1 ]
机构
[1] Lawrence Livermore National Laboratory, Livermore,CA, United States
关键词
Cybersecurity - SCADA systems - Network embeddings - Classification (of information);
D O I
10.1016/j.array.2021.100081
中图分类号
学科分类号
摘要
Characterization of modern cyber–physical Industrial Control System (ICS) devices is critical to the evaluation of their security posture and an understanding of the underlying industrial processes with which they interact. In this work, we address two related ICS device identification tasks: (1) separating ICS from non-ICS devices and (2) identifying specific ICS device types. We propose two distinct methods (one based on the existing IP2Vec method, and a novel traffic-features-based method) for achieving the first task. For transferability of the first task between two datasets, the traffic-features-based method performs significantly better (75% overall accuracy) compared to IP2Vec (22.5% overall accuracy). We further propose a novel method called DNP2Vec to address the second task. DNP2Vec is evaluated on two different datasets and achieves perfect multi-class classification accuracy (100%) for both datasets. © 2021 The Authors
引用
收藏
相关论文
empty
未找到相关数据