RRCNN: Request Response-Based Convolutional Neural Network for ICS Network Traffic Anomaly Detection

被引:0
|
作者
Du, Yan [1 ,2 ]
Zhang, Shibin [1 ,2 ]
Wan, Guogen [1 ,2 ]
Zhou, Daohua [3 ]
Lu, Jiazhong [1 ,2 ]
Huang, Yuanyuan [1 ,2 ]
Cheng, Xiaoman [4 ]
Zhang, Yi [4 ]
He, Peilin [5 ]
机构
[1] Chengdu Univ Informat Technol, Country Sch Cybersecur, Chengdu 610225, Peoples R China
[2] Adv Cryptog & Syst Secur Key Lab Sichuan Prov, Chengdu 610225, Peoples R China
[3] DAQSOFT CO LTD, Chengdu 610213, Peoples R China
[4] Petro China Southwest Oil & Gas Co, Commun & Informat Technol Ctr, Chengdu 610057, Peoples R China
[5] Univ Pittsburgh, Sch Comp & Informat, Pittsburgh, PA USA
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2023年 / 75卷 / 03期
基金
中国国家自然科学基金;
关键词
Industrial control system (ICS); dataset; network traffic; anomaly detection; INTRUSION DETECTION; INDUSTRIAL; SECURITY;
D O I
10.32604/cmc.2023.035919
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, industrial control system (ICS) has begun to integrate with the Internet. While the Internet has brought convenience to ICS, it has also brought severe security concerns. Traditional ICS network traffic anomaly detection methods rely on statistical features manually extracted using the experience of network security experts. They are not aimed at the original network data, nor can they capture the potential characteristics of network packets. Therefore, the following improvements were made in this study: (1) A dataset that can be used to evaluate anomaly detection algorithms is produced, which provides raw network data. (2) A request response-based convolutional neural network named RRCNN is proposed, which can be used for anomaly detection of ICS network traffic. Instead of using statistical features manually extracted by security experts, this method uses the byte sequences of the original network packets directly, which can extract potential features of the network packets in greater depth. It regards the request packet and response packet in a session as a Request-Response Pair (RRP). The feature of RRP is extracted using a one-dimensional convolutional neural network, and then the RRP is judged to be normal or abnormal based on the extracted feature. Experimental results demonstrate that this model is better than several other machine learning and neural network models, with F1, accuracy, precision, and recall above 99%.
引用
收藏
页码:5743 / 5759
页数:17
相关论文
共 50 条
  • [1] Network traffic anomaly detection method based on chaotic neural network
    Sheng, Shaojun
    Wang, Xin
    ALEXANDRIA ENGINEERING JOURNAL, 2023, 77 : 567 - 579
  • [2] Network Anomaly Detection With Convolutional Neural Network Based Auto Encoders
    Kiziltas, Behlul
    Gul, Ensar
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [3] Few-shot Network Traffic Anomaly Detection Based on Siamese Neural Network
    Xu, Simin
    Han, Xueying
    Tian, Tian
    Jiang, Bo
    Lu, Zhigang
    Zhang, Chen
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 3012 - 3017
  • [4] ANOMALY DETECTION FOR NETWORK TRAFFIC OF I&C SYSTEMS BASED ON NEURAL NETWORK
    Si, Wen
    Li, Jianghai
    Qu, Ronghong
    Huang, Xiaojin
    PROCEEDINGS OF THE 2020 INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING (ICONE2020), VOL 3, 2020,
  • [5] DAN: Neural network based on dual attention for anomaly detection in ICS
    Xu, Lijuan
    Wang, Bailing
    Zhao, Dawei
    Wu, Xiaoming
    EXPERT SYSTEMS WITH APPLICATIONS, 2025, 263
  • [6] Network Traffic Anomaly Detection based on Catastrophe Theory
    Xiong, Wei
    Xiong, Naixue
    Yang, Laurence T.
    Vasilakos, Athanasios V.
    Wang, Qian
    Hu, Hanping
    2010 IEEE GLOBECOM WORKSHOPS, 2010, : 2070 - 2074
  • [7] Spatio-Temporal Network Traffic Estimation and Anomaly Detection Based on Convolutional Neural Network in Vehicular Ad-Hoc Networks
    Nie, Laisen
    Li, Yongkang
    Kong, Xiangjie
    IEEE ACCESS, 2018, 6 : 40168 - 40176
  • [8] Anomaly detection of traffic session based on graph neural network
    Du Peng
    Peng Cheng-Wei
    Xiang Peng
    Li Qing-Shan
    PROCEEDINGS OF THE 2022 INTERNATIONAL CONFERENCE ON CYBER SECURITY, CSW 2022, 2022, : 1 - 9
  • [9] One-hot encoding and convolutional neural network based anomaly detection
    Liang J.
    Chen J.
    Zhang X.
    Zhou Y.
    Lin J.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (07): : 523 - 529
  • [10] An Intrusion Detection System Based on Convolutional Neural Network for Imbalanced Network Traffic
    Zhang, Xiaoxuan
    Ran, Jing
    Mi, Jize
    PROCEEDINGS OF 2019 IEEE 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2019), 2019, : 456 - 460