Anomaly Detection via One Class SVM for Protection of SCADA Systems

被引:28
作者
Jiang, Jianmin [1 ]
Yasakethu, Lasith [1 ]
机构
[1] Univ Surrey, Dept Comp, Guildford GU2 7XH, Surrey, England
来源
2013 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC) | 2013年
关键词
Anomaly detection; risk analysis and SVMs;
D O I
10.1109/CyberC.2013.22
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Funded by European Framework-7 (FP7), the CockpicCI project aims at developing intelligent risk detection, analysis and protection techniques for Critical Infrastructures (CI). In this paper, we describes our recent research on automated anomaly detection from central Supervisory Control and Data Acquisition (SCADA) systems and their related commands/measurements in the SCADA-field equipment communications. The work exploits the concept of one-class SVM (Support Vector Machines) and adaptively controls its decision parameter to detect unusual patterns from inputs and generate alarms for on-site engineers to further investigate. Experiments on simulation data sets from telecommunication networks illustrate that the proposed algorithm achieves high detection rates, providing excellent potential for further research and development towards practical tools for protection of SCADA systems.
引用
收藏
页码:82 / 88
页数:7
相关论文
共 10 条
[1]  
[Anonymous], 2001, P ACM CSS WORKSH DAT
[2]   A tutorial on Support Vector Machines for pattern recognition [J].
Burges, CJC .
DATA MINING AND KNOWLEDGE DISCOVERY, 1998, 2 (02) :121-167
[3]  
Dao V.N., 2002, Differential equations and dynamical systems, V10, P201
[4]   Towards a taxonomy of intrusion-detection systems [J].
Debar, H ;
Dacier, M ;
Wespi, A .
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 1999, 31 (08) :805-822
[5]  
Ji Z, 2006, GECCO 2006: GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE, VOL 1 AND 2, P111
[6]  
Lauer Martin, 2001, EUR C MACH LEARN, P300
[7]  
Liu YH, 2006, PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTER SCIENCE AND TECHNOLOGY, P207
[8]  
Ma JS, 2003, IEEE IJCNN, P1741
[9]  
MUKKAMALA S, 2002, P HIGH PERF COMP S H, P178
[10]  
Schölkopf B, 2000, ADV NEUR IN, V12, P582