SCADA intrusion detection scheme exploiting the fusion of modified decision tree and Chi-square feature selection

被引:42
作者
Ahakonye, Love Allen Chijioke [1 ]
Nwakanma, Cosmas Ifeanyi [1 ]
Lee, Jae-Min [1 ]
Kim, Dong-Seong [1 ]
机构
[1] Kumoh Natl Inst Technol, IT Convergence Engn, Gumi, South Korea
关键词
Anomaly detection; Chi-square; Feature selection; Mathews correlation coefficient; IIoT; ICS; SCADA intrusion detection; MODEL; NETWORKS; SECURITY; ENSEMBLE; SYSTEM;
D O I
10.1016/j.iot.2022.100676
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The industrial internet of things (IIoT) and supervisory control and data acquisition (SCADA) have experienced ubiquitous growth recently. This growth comes with the challenge of an increased number of unusual attacks constituting threats. The existence and effect of intruders and their innovative attack techniques are rising. Although the existing intrusion detection systems (IDS) safeguard the networks, they have been computationally expensive. In real -time domains, available methods lag, necessitating additional research into effective feature extraction schemes with time exigency. An IDS with a fused feature selection (FS) approach for detecting and classifying attacks in a real-time SCADA network is imperative. It is to enable the resolution of computationally complex vulnerability detection schemes. The proposed technique is in three (3) phases: (a) data preparation which involves data cleansing and normalization, and (b) a fused feature selection approach built to obtain an optimal subset of features using Chi-square. (c) deployment of the modified decision tree (MDT) for anomaly detection and classification. Lastly, the reliability of the proposed model was validated, demonstrating suitability in precisely detecting abnormalities while minimizing computational time. This improvement enables adaptability for the IDS deployment scheme in a real-time situation, which could be in the control center. The validation results reveal that when the proposed chi-square-based (fused) feature extraction is employed, it performs optimally to other FS techniques and ML classifiers, compared across four (4) publicly available datasets. Cohen's kappa coefficient (CKC) further validates the proposed model's reliability. Further demonstrating the experimental results with recourse to false positive rates (FPR), the Mathews correlation coefficient (MCC) was employed. It also shows the resilience of the proposed model performance on an imbalanced dataset validating its suitability in real scenarios.
引用
收藏
页数:17
相关论文
共 53 条
[41]   Intrusion Detection Technique in Wireless Sensor Network using Grid Search Random Forest with Boruta Feature Selection Algorithm [J].
Subbiah, Sridevi ;
Anbananthen, Kalaiarasi Sonai Muthu ;
Thangaraj, Saranya ;
Kannan, Subarmaniam ;
Chelliah, Deisy .
JOURNAL OF COMMUNICATIONS AND NETWORKS, 2022, 24 (02) :264-273
[42]   SCADA System Testbed for Cybersecurity Research Using Machine Learning Approach [J].
Teixeira, Marcio Andrey ;
Salman, Tara ;
Zolanvari, Maede ;
Jain, Raj ;
Meskin, Nader ;
Samaka, Mohammed .
FUTURE INTERNET, 2018, 10 (08)
[43]   Integrated Intrusion Detection Model Using Chi-Square Feature Selection and Ensemble of Classifiers [J].
Thaseen, I. Sumaiya ;
Kumar, Ch. Aswani ;
Ahmad, Amir .
ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) :3357-3368
[44]   Intrusion Detection Model Using Chi Square Feature Selection and Modified Naive Bayes Classifier [J].
Thaseen, I. Sumaiya ;
Kumar, Ch. Aswani .
PROCEEDINGS OF THE 3RD INTERNATIONAL SYMPOSIUM ON BIG DATA AND CLOUD COMPUTING CHALLENGES (ISBCC - 16'), 2016, 49 :81-91
[45]  
Sheikh NU, 2018, Arxiv, DOI arXiv:1811.04582
[46]   Machine learning for intrusion detection in industrial control systems: Applications, challenges, and recommendations [J].
Umer, Muhammad Azmi ;
Junejo, Khurum Nazir ;
Jilani, Muhammad Taha ;
Mathur, Aditya P. .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 38
[47]   Intrusion Detection in SCADA Based Power Grids: Recursive Feature Elimination Model With Majority Vote Ensemble Algorithm [J].
Upadhyay, Darshana ;
Manero, Jaume ;
Zaman, Marzia ;
Sampalli, Srinivas .
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (03) :2559-2574
[48]   Gradient Boosting Feature Selection With Machine Learning Classifiers for Intrusion Detection on Power Grids [J].
Upadhyay, Darshana ;
Manero, Jaume ;
Zaman, Marzia ;
Sampalli, Srinivas .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01) :1104-1116
[49]   Architecture and security of SCADA systems: A review [J].
Yadav, Geeta ;
Paul, Kolin .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2021, 34
[50]   Feature Selection Based on Random Forest for Partial Discharges Characteristic Set [J].
Yao, Rui ;
Li, Jun ;
Hui, Meng ;
Bai, Lin ;
Wu, Qisheng .
IEEE ACCESS, 2020, 8 :159151-159161