CPS-GUARD: Intrusion detection for cyber-physical systems and IoT devices using outlier-aware deep autoencoders

被引:44
作者
Catillo, Marta [1 ]
Pecchia, Antonio [1 ]
Villano, Umberto [1 ]
机构
[1] Univ Sannio, Benevento, Italy
关键词
Cyber-physical systems; Internet of things; Outlier detection; Intrusion detection; Deep learning; ANOMALY DETECTION; NETWORK;
D O I
10.1016/j.cose.2023.103210
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detecting attacks to Cyber-Physical Systems (CPSs) is of utmost importance, due to their increasingly fre-quent use in many critical assets. Intrusion detection in CPSs and other domains, such as the Internet of Things, is often addressed through machine and deep learning. However, many existing proposals tend to favor the application of complex detection models over the usability in real-world operations. This paper presents CPS-GUARD, a novel intrusion detection approach based on a single semi-supervised au-toencoder and a technique to set the threshold used to discriminate normal operations from attacks. The technique is outlier-aware, in that it relies on outlier detection to mitigate inherent imperfections of the training data.CPS-GUARD is evaluated by means of direct experiments with normal and intrusion data points pertain-ing to individual sensing devices, an HTTP server and four full-fledged systems, including CPSs. Exper-iments are based on a wide spectrum of attacks available in six state-of-the-art datasets. The intrusion detection results of CPS-GUARD are within 0.949-1.0 0 0 recall, 0.961-0.999 precision and 0.006-0.027 false positive rate depending on the specific system. The results are competitive with other existing intrusion detection methods. The evaluation is complemented by a comparative study on alternative threshold se-lection and outlier detection techniques.(c) 2023 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 66 条
[1]   IoT Botnet Detection Using Salp Swarm and Ant Lion Hybrid Optimization Model [J].
Abu Khurma, Ruba ;
Almomani, Iman ;
Aljarah, Ibrahim .
SYMMETRY-BASEL, 2021, 13 (08)
[2]   Unsupervised intelligent system based on one class support vector machine and Grey Wolf optimization for IoT botnet detection [J].
Al Shorman, Amaal ;
Faris, Hossam ;
Aljarah, Ibrahim .
JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (07) :2809-2825
[3]  
Ali O, 2018, 2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), P229, DOI 10.1109/UEMCON.2018.8796637
[4]   Industrial Control Systems: Cyberattack trends and countermeasures [J].
Alladi, Tejasvi ;
Chamola, Vinay ;
Zeadally, Sherali .
COMPUTER COMMUNICATIONS, 2020, 155 :1-8
[5]   SoK: The Impact of Unlabelled Data in Cyberthreat Detection [J].
Apruzzese, Giovanni ;
Laskov, Pavel ;
Tastemirova, Aliya .
2022 IEEE 7TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P 2022), 2022, :20-42
[6]   A Review on Outlier/Anomaly Detection in Time Series Data [J].
Blazquez-Garcia, Ane ;
Conde, Angel ;
Mori, Usue ;
Lozano, Jose A. .
ACM COMPUTING SURVEYS, 2022, 54 (03)
[7]   LOF: Identifying density-based local outliers [J].
Breunig, MM ;
Kriegel, HP ;
Ng, RT ;
Sander, J .
SIGMOD RECORD, 2000, 29 (02) :93-104
[8]  
Catillo M., 2022, P ACM INT C AV REL S
[9]  
Chawathe S.S., 2018, 2018 IEEE 17 INT S N, P1, DOI 10.1109/NCA.2018.8548330
[10]   Applying separately cost-sensitive learning and Fisher's discriminant analysis to address the class imbalance problem: A case study involving a virtual gas pipeline SCADA system [J].
Choubineh, Abouzar ;
Wood, David A. ;
Choubineh, Zahak .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2020, 29