Explainable deep learning for attack intelligence and combating cyber-physical attacks

被引:15
作者
Al-Hawawreh, Muna [1 ]
Moustafa, Nour [2 ]
机构
[1] Deakin Univ, Melbourne, Australia
[2] Univ New South Wales, Canberra, Australia
关键词
Deep learning; XAI; Industrial process; Detection; Attack intelligence; Industrial IoT; THREAT INTELLIGENCE;
D O I
10.1016/j.adhoc.2023.103329
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-physical control loops comprising sensors, actuators and controllers pose the most valued and critical part of the industrial Internet of Things (IIoT) as it regulates the state of the physical process, such as water treatment or gas flow. Thus, any malicious activities could lead to physical damage, affecting human safety. Cyber-physical attacks against the physical process are difficult to detect using existing threats and attack intelligence due to the (1) lack of such intelligence for the physical process and operational technology systems and (2) such attacks affect the process parameters and states. Artificial Intelligence (AI)-based attack intelligence is required. This study proposes an attack intelligence framework for identifying cyber- physical attacks and extracting attack intelligence. We propose an attribution module for attack identification using various machine and deep learning algorithms. We also utilize Explainable AI (XAI) to improve the explainability of the attack attribution module and extract attack intelligence. Our proposed framework is evaluated and tested using a gas pipeline dataset as a use case. We demonstrate that the proposed framework improves the understanding of attacks and provides attack rules, assisting security analysts in securing critical physical processes.
引用
收藏
页数:10
相关论文
共 31 条
[1]  
Adebayo J, 2018, Arxiv, DOI [arXiv:1810.03307, DOI 10.48550/ARXIV.1810.03307, 10.48550/arXiv.1810.03307]
[2]   An Online Model to Minimize Energy Consumption of IoT Sensors in Smart Cities [J].
Al-Hawawreh, Muna ;
Elgendi, Ibrahim ;
Munasinghe, Kumudu .
IEEE SENSORS JOURNAL, 2022, 22 (20) :19524-19532
[3]   Deep Learning-Enabled Threat Intelligence Scheme in the Internet of Things Networks [J].
Al-Hawawreh, Muna ;
Moustafa, Nour ;
Garg, Sahil ;
Hossain, M. Shamim .
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (04) :2968-2981
[4]   X-IIoTID: A Connectivity-Agnostic and Device-Agnostic Intrusion Data Set for Industrial Internet of Things [J].
Al-Hawawreh, Muna ;
Sitnikova, Elena ;
Aboutorab, Neda .
IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (05) :3962-3977
[5]   Asynchronous Peer-to-Peer Federated Capability-Based Targeted Ransomware Detection Model for Industrial IoT [J].
Al-Hawawreh, Muna ;
Sitnikova, Elena ;
Aboutorab, Neda .
IEEE ACCESS, 2021, 9 :148738-148755
[6]   A threat intelligence framework for protecting smart satellite-based healthcare networks [J].
Al-Hawawreh, Muna ;
Moustafa, Nour ;
Slay, Jill .
NEURAL COMPUTING & APPLICATIONS, 2024, 36 (01) :15-35
[7]   An Efficient Intrusion Detection Model for Edge System in Brownfield Industrial Internet of Things [J].
AL-Hawawreh, Muna ;
Sitnikova, Elena ;
den Hartog, Frank .
3RD INTERNATIONAL CONFERENCE ON BIG DATA AND INTERNET OF THINGS (BDIOT 2019), 2018, :83-87
[8]   Cyber Threat Intelligence from Honeypot Data using Elasticsearch [J].
AL-Mohannadi, Hamad ;
Awan, Irfan ;
Al Hamar, Jassim ;
Cullen, Andrea ;
Disso, Jules Pagan ;
Armitage, Lorna .
PROCEEDINGS 2018 IEEE 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2018, :900-906
[9]  
Alkhaldi M A., 2017, Proceedings of the 13th International Postgraduate Research Conference (IPGRC), P822
[10]   Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI [J].
Barredo Arrieta, Alejandro ;
Diaz-Rodriguez, Natalia ;
Del Ser, Javier ;
Bennetot, Adrien ;
Tabik, Siham ;
Barbado, Alberto ;
Garcia, Salvador ;
Gil-Lopez, Sergio ;
Molina, Daniel ;
Benjamins, Richard ;
Chatila, Raja ;
Herrera, Francisco .
INFORMATION FUSION, 2020, 58 :82-115