Detecting Anomalies by using Self-Organizing Maps in Industrial Environments

被引:6
|
作者
Hormann, Ricardo [1 ]
Fischer, Eric [1 ]
机构
[1] Volkswagen AG, Shopfloor IT, Wolfsburg, Germany
来源
PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP) | 2019年
关键词
Anomaly Detection; Self-Organizing Maps; Profinet;
D O I
10.5220/0007364803360344
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Detecting anomalies caused by intruders are a big challenge in industrial environments due to the complex environmental interdependencies and proprietary fieldbus protocols. In this paper, we proposed a network-based method for detecting anomalies by using unsupervised artificial neural networks called Self-Organizing Maps (SOMs). Therefore, we published an algorithm which identifies clusters and cluster centroids in SOMs to gain knowledge about the underlying data structure. In the training phase we created two neural networks, one for clustering the network data and the other one for finding the cluster centroids. In the operating phase our approach is able to detect anomalies by comparing new data samples with the first trained SOM model. We used a confidence interval to decide if the sample is too far from its best matching unit. A novel additional confidence interval for the second SOM is proposed to minimize false positives which have been a major drawback of machine learning methods in anomaly detection. We implemented our approach in a robot cell and infiltrated the network like an intruder would do to evaluate our method. As a result, we significantly reduced the false positive rate to 0.07% using the second interval while providing an accuracy of 99% for the detection of network attacks.
引用
收藏
页码:336 / 344
页数:9
相关论文
共 50 条
  • [11] Project Management Using Self-Organizing Maps
    Parvizian, Jamshid
    Tarkesh, Named
    Atighehchian, Arezoo
    Farid, Sara
    INDUSTRIAL ENGINEERING AND MANAGEMENT SYSTEMS, 2005, 5 (01): : 23 - 31
  • [12] Detecting Bad-Mouthing Attacks on Reputation Systems Using Self-Organizing Maps
    Bankovic, Z.
    Vallejo, J. C.
    Fraga, D.
    Moya, J. M.
    COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS, 2011, 6694 : 9 - 16
  • [13] Decentralizing Self-organizing Maps
    Khan, Md Mohiuddin
    Kasmarik, Kathryn
    Garratt, Matt
    AI 2021: ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, 13151 : 480 - 493
  • [14] Internet-based remote supervision of industrial processes using self-organizing maps
    Dominguez, M.
    Fuertes, J. J.
    Reguera, P.
    Diaz, I.
    Cuadrado, A. A.
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2007, 20 (06) : 757 - 765
  • [15] Robust self-organizing maps
    Allende, H
    Moreno, S
    Rogel, C
    Salas, R
    PROGRESS IN PATTERN RECOGNITION, IMAGE ANALYSIS AND APPLICATIONS, 2004, 3287 : 179 - 186
  • [16] WiP: Distributed Intrusion Detection System for TCP/IP-Based Connections in Industrial Environments Using Self-organizing Maps
    Kharitonov, Aleksei
    Zimmermann, Axel
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2021, 2021, 12809 : 231 - 251
  • [17] A clustering method using hierarchical self-organizing maps
    Endo, M
    Ueno, M
    Tanabe, T
    JOURNAL OF VLSI SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2002, 32 (1-2): : 105 - 118
  • [18] Automatic Feature Engineering Using Self-Organizing Maps
    Rodrigues, Ericks da Silva
    Martins, Denis Mayr Lima
    de Lima Neto, Fernando Buarque
    2021 IEEE LATIN AMERICAN CONFERENCE ON COMPUTATIONAL INTELLIGENCE (LA-CCI), 2021,
  • [19] Segmentation of hyperspectral images using self-organizing maps
    Sanocki, Pawel
    Kawulok, Michal
    Smolka, Bogdan
    Nalepa, Jakub
    REAL-TIME IMAGE PROCESSING AND DEEP LEARNING 2021, 2021, 11736
  • [20] Local Password Validation Using Self-Organizing Maps
    Monica, Diogo
    Ribeiro, Carlos
    COMPUTER SECURITY - ESORICS 2014, PT I, 2014, 8712 : 94 - 111