Early Intrusion Detection System using honeypot for industrial control networks

被引:15
|
作者
Pashaei, Abbasgholi [1 ]
Akbari, Mohammad Esmaeil [1 ]
Lighvan, Mina Zolfy [2 ]
Charmin, Asghar [1 ]
机构
[1] Islamic Azad Univ, Dept Elect Engn, Ahar Branch, Ahar, Iran
[2] Tabriz Univ, Dept Elect Engn, Tabriz, Iran
关键词
Intrusion detection; Honeypots; Reinforcement learning; SARSA;
D O I
10.1016/j.rineng.2022.100576
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Man-in-the-Middle (MITM) and Distributed Denial of Service (DDoS) attacks are significant threats, especially to Industrial Control Systems (ICS). The honeypot is one of the most common approaches to protecting the network against such attacks. This study proposes a Markov Decision Process (MDP) called the state-action-reward-state -action (SARSA) for honeypot design. The proposed system using environmental experiments can achieve greater accuracy and convergence speed than traditional IDSs. Here, we use two types of agents, one for classification and the other for the environment. The environmental agent tries to minimize the rewards given to the classi-fying agent. Therefore, the classification agent is forced to learn the most complicated policies, increasing its learning capability in the long term. Thus, the proposed method improves the level of interaction for the early detection of honeypots by recording aggressive behavior. It can be especially suitable for very imbalanced datasets. To evaluate the performance of the proposed method, we compare it with two categories of malicious ICS attacks, including MITM and DDoS. The results show that the proposed model is superior to traditional non-linear IDS models in terms of accuracy (<0.99) and F-measure (0.98).
引用
收藏
页数:11
相关论文
共 50 条
  • [11] Intrusion detection algorithm based on OCSVM in industrial control system
    Shang, Wenli
    Zeng, Peng
    Wan, Ming
    Li, Lin
    An, Panfeng
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (10) : 1040 - 1049
  • [12] Attack signal estimation for intrusion detection in industrial control system
    Miao, Kelei
    Shi, Xiufang
    Zhang, Wen-An
    COMPUTERS & SECURITY, 2020, 96
  • [13] Traffic Load Learning Towards Early Detection of Intrusion in Industrial mMTC Networks
    Zhao, Zixiao
    Du, Qinghe
    Song, Houbing
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (07) : 8441 - 8451
  • [14] Intrusion Detection Scheme Using Traffic Prediction for Wireless Industrial Networks
    Wei, Min
    Kim, Keecheon
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2012, 14 (03) : 310 - 318
  • [15] Traffic Modeling by Recurrent Neural Networks for Intrusion Detection in Industrial Control Systems
    Sokolov, Alexander N.
    Alabugin, Sergei K.
    Pyatnitsky, Ilya A.
    2019 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING, APPLICATIONS AND MANUFACTURING (ICIEAM), 2019,
  • [16] An Intrusion Detection Method for Industrial Control System Based on Machine Learning
    Cao, Yixin
    Zhang, Lei
    Zhao, Xiaosong
    Jin, Kai
    Chen, Ziyi
    INFORMATION, 2022, 13 (07)
  • [17] INDUSTRIAL CONTROL SYSTEM TRAFFIC DATA SETS FOR INTRUSION DETECTION RESEARCH
    Morris, Thomas
    Gao, Wei
    CRITICAL INFRASTRUCTURE PROTECTION VIII, 2014, 441 : 65 - +
  • [18] HAMIDS: Hierarchical Monitoring Intrusion Detection System for Industrial Control Systems
    Ghaeini, Hamid Reza
    Tippenhauer, Nils Ole
    CPS-SPC'16: PROCEEDINGS OF THE 2ND ACM WORKSHOP ON CYBER-PHYSICAL SYSTEMS SECURITY & PRIVACY, 2016, : 101 - 109
  • [19] Physics Reasoning for Intrusion Detection in Industrial Networks
    Yahya, Mohammad
    Sharaf, Nasir
    Rrushi, Julian L.
    Tay, Ho Ming
    Liu, Bing
    Xu, Kai
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 273 - 283
  • [20] A survey of intrusion detection on industrial control systems
    Hu, Yan
    Yang, An
    Li, Hong
    Sun, Yuyan
    Sun, Limin
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (08):