Early Intrusion Detection System using honeypot for industrial control networks

被引:15
|
作者
Pashaei, Abbasgholi [1 ]
Akbari, Mohammad Esmaeil [1 ]
Lighvan, Mina Zolfy [2 ]
Charmin, Asghar [1 ]
机构
[1] Islamic Azad Univ, Dept Elect Engn, Ahar Branch, Ahar, Iran
[2] Tabriz Univ, Dept Elect Engn, Tabriz, Iran
关键词
Intrusion detection; Honeypots; Reinforcement learning; SARSA;
D O I
10.1016/j.rineng.2022.100576
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Man-in-the-Middle (MITM) and Distributed Denial of Service (DDoS) attacks are significant threats, especially to Industrial Control Systems (ICS). The honeypot is one of the most common approaches to protecting the network against such attacks. This study proposes a Markov Decision Process (MDP) called the state-action-reward-state -action (SARSA) for honeypot design. The proposed system using environmental experiments can achieve greater accuracy and convergence speed than traditional IDSs. Here, we use two types of agents, one for classification and the other for the environment. The environmental agent tries to minimize the rewards given to the classi-fying agent. Therefore, the classification agent is forced to learn the most complicated policies, increasing its learning capability in the long term. Thus, the proposed method improves the level of interaction for the early detection of honeypots by recording aggressive behavior. It can be especially suitable for very imbalanced datasets. To evaluate the performance of the proposed method, we compare it with two categories of malicious ICS attacks, including MITM and DDoS. The results show that the proposed model is superior to traditional non-linear IDS models in terms of accuracy (<0.99) and F-measure (0.98).
引用
收藏
页数:11
相关论文
共 50 条
  • [1] A hybrid honeypot framework for improving intrusion detection systems in protecting organizational networks
    Artail, Hassan
    Safa, Haidar
    Sraj, Malek
    Kuwatly, Iyad
    Al-Masri, Zaid
    COMPUTERS & SECURITY, 2006, 25 (04) : 274 - 288
  • [2] Research on the application of honeypot technology in Intrusion Detection System
    Suo, Xiangfeng
    Han, Xue
    Gao, Yunhui
    PROCEEDINGS OF 2014 IEEE WORKSHOP ON ADVANCED RESEARCH AND TECHNOLOGY IN INDUSTRY APPLICATIONS (WARTIA), 2014, : 1030 - 1032
  • [3] A Two Stage Intrusion Detection System for Industrial Control Networks Based on Ethernet/IP
    Yu, Wenbin
    Wang, Yiyin
    Song, Lei
    ELECTRONICS, 2019, 8 (12)
  • [4] An Intelligent Approach for Intrusion Detection in Industrial Control System
    Alkhalil, Adel
    Aljaloud, Abdulaziz
    Uliyan, Diaa
    Altameemi, Mohammed
    Abdelrhman, Magdy
    Altameemi, Yaser
    Ahmad, Aakash
    Mansour, Romany Fouad
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 77 (02): : 2049 - 2078
  • [5] Honeypot-Based Intrusion Detection System: A Performance Analysis
    Kondra, Janardhan Reddy
    Bharti, Santosh Kumar
    Mishra, Sambit Kumar
    Babu, Korra Sathya
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 2347 - 2351
  • [6] Honeypot Based Industrial Threat Detection Using Game Theory in Cyber-Physical System
    Zhou, Xiangming
    Almutairi, Laila
    Alsenani, Theyab R.
    Ahmad, Mohammad Nazir
    JOURNAL OF GRID COMPUTING, 2023, 21 (04)
  • [7] Honeypot Based Industrial Threat Detection Using Game Theory in Cyber-Physical System
    Xiangming Zhou
    Laila Almutairi
    Theyab R. Alsenani
    Mohammad Nazir Ahmad
    Journal of Grid Computing, 2023, 21
  • [8] Distributed Architecture of an Intrusion Detection System in Industrial Control Systems
    Abid, Ahlem
    Jemili, Farah
    Korbaa, Ouajdi
    ADVANCES IN COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2022, 2022, 1653 : 472 - 484
  • [9] Industrial Control System Network Intrusion Detection by Telemetry Analysis
    Ponomarev, Stanislav
    Atkison, Travis
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2016, 13 (02) : 252 - 260
  • [10] Assessing Industrial Control System Attack Datasets for Intrusion Detection
    Wang, Xuelei
    Foo, Ernest
    2018 THIRD INTERNATIONAL CONFERENCE ON SECURITY OF SMART CITIES, INDUSTRIAL CONTROL SYSTEM AND COMMUNICATIONS (SSIC), 2018,