RRCNN: Request Response-Based Convolutional Neural Network for ICS Network Traffic Anomaly Detection

被引:0
作者
Du, Yan [1 ,2 ]
Zhang, Shibin [1 ,2 ]
Wan, Guogen [1 ,2 ]
Zhou, Daohua [3 ]
Lu, Jiazhong [1 ,2 ]
Huang, Yuanyuan [1 ,2 ]
Cheng, Xiaoman [4 ]
Zhang, Yi [4 ]
He, Peilin [5 ]
机构
[1] Chengdu Univ Informat Technol, Country Sch Cybersecur, Chengdu 610225, Peoples R China
[2] Adv Cryptog & Syst Secur Key Lab Sichuan Prov, Chengdu 610225, Peoples R China
[3] DAQSOFT CO LTD, Chengdu 610213, Peoples R China
[4] Petro China Southwest Oil & Gas Co, Commun & Informat Technol Ctr, Chengdu 610057, Peoples R China
[5] Univ Pittsburgh, Sch Comp & Informat, Pittsburgh, PA USA
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2023年 / 75卷 / 03期
基金
中国国家自然科学基金;
关键词
Industrial control system (ICS); dataset; network traffic; anomaly detection; INTRUSION DETECTION; INDUSTRIAL; SECURITY;
D O I
10.32604/cmc.2023.035919
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, industrial control system (ICS) has begun to integrate with the Internet. While the Internet has brought convenience to ICS, it has also brought severe security concerns. Traditional ICS network traffic anomaly detection methods rely on statistical features manually extracted using the experience of network security experts. They are not aimed at the original network data, nor can they capture the potential characteristics of network packets. Therefore, the following improvements were made in this study: (1) A dataset that can be used to evaluate anomaly detection algorithms is produced, which provides raw network data. (2) A request response-based convolutional neural network named RRCNN is proposed, which can be used for anomaly detection of ICS network traffic. Instead of using statistical features manually extracted by security experts, this method uses the byte sequences of the original network packets directly, which can extract potential features of the network packets in greater depth. It regards the request packet and response packet in a session as a Request-Response Pair (RRP). The feature of RRP is extracted using a one-dimensional convolutional neural network, and then the RRP is judged to be normal or abnormal based on the extracted feature. Experimental results demonstrate that this model is better than several other machine learning and neural network models, with F1, accuracy, precision, and recall above 99%.
引用
收藏
页码:5743 / 5759
页数:17
相关论文
共 50 条
  • [11] A Spectrogram Image-Based Network Anomaly Detection System Using Deep Convolutional Neural Network
    Khan, Adnan Shahid
    Ahmad, Zeeshan
    Abdullah, Johari
    Ahmad, Farhan
    IEEE ACCESS, 2021, 9 : 87079 - 87093
  • [12] A network traffic classification and anomaly detection method based on parallel cross-convolutional neural networks
    Zou, Bailin
    Liu, Tianhang
    International Journal of Security and Networks, 2024, 19 (02) : 92 - 100
  • [13] SADCNN: Supervised anomaly detection based on convolutional neural network models
    Hatami, Maryam
    Gharaee, Hossein
    Mohammadzadeh, Naser
    INFORMATION SECURITY JOURNAL, 2025,
  • [14] Network Traffic Anomaly Detection Based on Wavelet Analysis
    Du, Zhen
    Ma, Lipeng
    Li, Huakang
    Li, Qun
    Sun, Guozi
    Liu, Zichang
    2018 IEEE/ACIS 16TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT AND APPLICATION (SERA), 2018, : 94 - 101
  • [15] Network anomaly traffic detection algorithm based on SVM
    Lei, Yang
    2017 INTERNATIONAL CONFERENCE ON ROBOTS & INTELLIGENT SYSTEM (ICRIS), 2017, : 217 - 220
  • [16] A Traffic Sign Detection Algorithm Based on Deep Convolutional Neural Network
    Xiong Changzhen
    Wang Cong
    Ma Weixin
    Shan Yanmei
    2016 IEEE INTERNATIONAL CONFERENCE ON SIGNAL AND IMAGE PROCESSING (ICSIP), 2016, : 676 - 679
  • [17] Neural Network based Anomaly Detection
    Callegari, Christian
    Giordano, Stefano
    Pagano, Michele
    2014 IEEE 19TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2014, : 310 - 314
  • [18] Network Anomaly Detection With Temporal Convolutional Network and U-Net Model
    Mezina, Anzhelika
    Burget, Radim
    Travieso-Gonzalez, Carlos M.
    IEEE ACCESS, 2021, 9 : 143608 - 143622
  • [19] Anomaly detection based on a deep graph convolutional neural network for reliability improvement
    Xu, Gang
    Hu, Jie
    Qie, Xin
    Rong, Jingguo
    FRONTIERS IN ENERGY RESEARCH, 2024, 12
  • [20] Industrial Anomaly Detection and Attack Classification Method Based on Convolutional Neural Network
    Lai, Yingxu
    Zhang, Jingwen
    Liu, Zenghui
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019