Detecting Anomalies by using Self-Organizing Maps in Industrial Environments

被引:6
|
作者
Hormann, Ricardo [1 ]
Fischer, Eric [1 ]
机构
[1] Volkswagen AG, Shopfloor IT, Wolfsburg, Germany
来源
PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP) | 2019年
关键词
Anomaly Detection; Self-Organizing Maps; Profinet;
D O I
10.5220/0007364803360344
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detecting anomalies caused by intruders are a big challenge in industrial environments due to the complex environmental interdependencies and proprietary fieldbus protocols. In this paper, we proposed a network-based method for detecting anomalies by using unsupervised artificial neural networks called Self-Organizing Maps (SOMs). Therefore, we published an algorithm which identifies clusters and cluster centroids in SOMs to gain knowledge about the underlying data structure. In the training phase we created two neural networks, one for clustering the network data and the other one for finding the cluster centroids. In the operating phase our approach is able to detect anomalies by comparing new data samples with the first trained SOM model. We used a confidence interval to decide if the sample is too far from its best matching unit. A novel additional confidence interval for the second SOM is proposed to minimize false positives which have been a major drawback of machine learning methods in anomaly detection. We implemented our approach in a robot cell and infiltrated the network like an intruder would do to evaluate our method. As a result, we significantly reduced the false positive rate to 0.07% using the second interval while providing an accuracy of 99% for the detection of network attacks.
引用
收藏
页码:336 / 344
页数:9
相关论文
共 50 条
  • [1] Self-organizing Maps versus Growing Neural Gas in Detecting Anomalies in Data Centres
    Zapater, Marina
    Fraga, David
    Malagon, Pedro
    Bankovic, Zorana
    Moya, Jose M.
    LOGIC JOURNAL OF THE IGPL, 2015, 23 (03) : 495 - 505
  • [2] Discriminating and visualizing anomalies using negative selection and self-organizing maps
    Gonzalez, Fabio A.
    Galeano, Juan Carlos
    Rojas, Diego Alexander
    Veloza-Suan, Angelica
    GECCO 2005: GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE, VOLS 1 AND 2, 2005, : 297 - 304
  • [3] Detecting anomalous traffic using statistical processing and self-organizing maps
    Baldassari, Paola
    Montesanto, Anna
    Puliti, Paolo
    SECRYPT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2007, : 74 - 79
  • [4] Detecting anomalous network traffic with self-organizing maps
    Ramadas, M
    Ostermann, S
    Tjaden, B
    RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2003, 2820 : 36 - 54
  • [5] Detecting false testimonies in reputation systems using self-organizing maps
    Bankovic, Z.
    Vallejo, J. C.
    Fraga, D.
    Moya, J. M.
    LOGIC JOURNAL OF THE IGPL, 2013, 21 (04) : 549 - 559
  • [6] Detecting Intrusive Activity in the Smart Grid Communications Infrastructure using Self-Organizing Maps
    Baig, Zubair A.
    Ahmad, Saif
    Sait, Sadiq M.
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 1594 - 1599
  • [7] Recognizing environments from action sequences using self-organizing maps
    Yamada, S
    APPLIED SOFT COMPUTING, 2004, 4 (01) : 35 - 47
  • [8] Shape indexing using self-organizing maps
    Suganthan, PN
    IEEE TRANSACTIONS ON NEURAL NETWORKS, 2002, 13 (04): : 835 - 840
  • [9] Wireless localization using self-organizing maps
    Giorgetti, Gianni
    Gupta, Sandeep K. S.
    Manes, Gianfranco
    PROCEEDINGS OF THE SIXTH INTERNATIONAL SYMPOSIUM ON INFORMATION PROCESSING IN SENSOR NETWORKS, 2007, : 293 - 302
  • [10] Regional analysis using self-organizing maps
    Chudy, L
    Farkas, I
    POLITICKA EKONOMIE, 2000, 48 (05) : 685 - 697