Early Intrusion Detection System using honeypot for industrial control networks

被引:15
|
作者
Pashaei, Abbasgholi [1 ]
Akbari, Mohammad Esmaeil [1 ]
Lighvan, Mina Zolfy [2 ]
Charmin, Asghar [1 ]
机构
[1] Islamic Azad Univ, Dept Elect Engn, Ahar Branch, Ahar, Iran
[2] Tabriz Univ, Dept Elect Engn, Tabriz, Iran
关键词
Intrusion detection; Honeypots; Reinforcement learning; SARSA;
D O I
10.1016/j.rineng.2022.100576
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Man-in-the-Middle (MITM) and Distributed Denial of Service (DDoS) attacks are significant threats, especially to Industrial Control Systems (ICS). The honeypot is one of the most common approaches to protecting the network against such attacks. This study proposes a Markov Decision Process (MDP) called the state-action-reward-state -action (SARSA) for honeypot design. The proposed system using environmental experiments can achieve greater accuracy and convergence speed than traditional IDSs. Here, we use two types of agents, one for classification and the other for the environment. The environmental agent tries to minimize the rewards given to the classi-fying agent. Therefore, the classification agent is forced to learn the most complicated policies, increasing its learning capability in the long term. Thus, the proposed method improves the level of interaction for the early detection of honeypots by recording aggressive behavior. It can be especially suitable for very imbalanced datasets. To evaluate the performance of the proposed method, we compare it with two categories of malicious ICS attacks, including MITM and DDoS. The results show that the proposed model is superior to traditional non-linear IDS models in terms of accuracy (<0.99) and F-measure (0.98).
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Explainable Intrusion Detection in Industrial Control Systems
    Eltomy, Reham
    Lalouani, Wassila
    2024 IEEE 7TH INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER-PHYSICAL SYSTEMS, ICPS 2024, 2024,
  • [22] Intrusion Detection Algorithm of Industrial Control System Based on Improved Bloom Filter
    Chen, Yanru
    Zhang, Yuanyuan
    Lin, Youlin
    Huang, Xinmao
    Xing, Bin
    Long, Ping
    Li, Yang
    Chen, Liangyin
    COMPUTER SUPPORTED COOPERATIVE WORK AND SOCIAL COMPUTING, CHINESECSCW 2021, PT I, 2022, 1491 : 164 - 175
  • [23] Optimization and Implementation of Industrial Control System Network Intrusion Detection by Telemetry Analysis
    Li, Hongbiao
    Qin, Sujuan
    PROCEEDINGS OF 2017 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2017, : 1251 - 1254
  • [24] Ensemble Common Features Technique for Lightweight Intrusion Detection in Industrial Control System
    Otokwala, Uneneibotejit J.
    Petrovski, Andrei
    2023 IEEE 6TH INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER-PHYSICAL SYSTEMS, ICPS, 2023,
  • [25] Intrusion detection of industrial control system based on stacked auto-encoder
    Zhang, Rui
    Chen, Hongwei
    2019 CHINESE AUTOMATION CONGRESS (CAC2019), 2019, : 5638 - 5643
  • [26] Survey on Methodology of Intrusion Detection in Industrial Control System Based on Artificial Intelligence
    Li, Ligang
    Fu, Zhenyu
    Zou, Gaokai
    Mu, Zongjun
    Zhang, Qiaoxia
    Wang, Guangmin
    Wang, Pan
    2022 INTERNATIONAL CONFERENCE ON COMPUTERS AND ARTIFICIAL INTELLIGENCE TECHNOLOGIES, CAIT, 2022, : 93 - 103
  • [27] Intrusion Detection System Based on In-Depth Understandings of Industrial Control Logic
    Sun, Motong
    Lai, Yingxu
    Wang, Yipeng
    Liu, Jing
    Mao, Beifeng
    Gu, Haoran
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (03) : 2295 - 2306
  • [28] A Survey of Using Process Data and Features of Industrial Control Systems in Intrusion Detection
    Storm, Jon-Martin
    Hagen, Janne
    Toftegaard, Oyvind Anders Arntzen
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 2170 - 2177
  • [29] DiPot: A Distributed Industrial Honeypot System
    Cao, Jianhong
    Li, Wei
    Li, Jianjun
    Li, Bo
    SMART COMPUTING AND COMMUNICATION, SMARTCOM 2017, 2018, 10699 : 300 - 309
  • [30] Exploring Ensemble-Based Class Imbalance Learners for Intrusion Detection in Industrial Control Networks
    Louk, Maya Hilda Lestari
    Tama, Bayu Adhi
    BIG DATA AND COGNITIVE COMPUTING, 2021, 5 (04)