Early Intrusion Detection System using honeypot for industrial control networks

被引:15
|
作者
Pashaei, Abbasgholi [1 ]
Akbari, Mohammad Esmaeil [1 ]
Lighvan, Mina Zolfy [2 ]
Charmin, Asghar [1 ]
机构
[1] Islamic Azad Univ, Dept Elect Engn, Ahar Branch, Ahar, Iran
[2] Tabriz Univ, Dept Elect Engn, Tabriz, Iran
关键词
Intrusion detection; Honeypots; Reinforcement learning; SARSA;
D O I
10.1016/j.rineng.2022.100576
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Man-in-the-Middle (MITM) and Distributed Denial of Service (DDoS) attacks are significant threats, especially to Industrial Control Systems (ICS). The honeypot is one of the most common approaches to protecting the network against such attacks. This study proposes a Markov Decision Process (MDP) called the state-action-reward-state -action (SARSA) for honeypot design. The proposed system using environmental experiments can achieve greater accuracy and convergence speed than traditional IDSs. Here, we use two types of agents, one for classification and the other for the environment. The environmental agent tries to minimize the rewards given to the classi-fying agent. Therefore, the classification agent is forced to learn the most complicated policies, increasing its learning capability in the long term. Thus, the proposed method improves the level of interaction for the early detection of honeypots by recording aggressive behavior. It can be especially suitable for very imbalanced datasets. To evaluate the performance of the proposed method, we compare it with two categories of malicious ICS attacks, including MITM and DDoS. The results show that the proposed model is superior to traditional non-linear IDS models in terms of accuracy (<0.99) and F-measure (0.98).
引用
收藏
页数:11
相关论文
共 50 条
  • [41] Intrusion Detection using Deep Belief Networks
    Alom, Md. Zahangir
    Bontupalli, VenkataRamesh
    Taha, Tarek M.
    PROCEEDINGS OF THE 2015 IEEE NATIONAL AEROSPACE AND ELECTRONICS CONFERENCE (NAECON), 2015, : 339 - 344
  • [42] Intrusion Detection Using Evolutionary Neural Networks
    Michailidis, Emmanuel
    Katsikas, Sokratis K.
    Georgopoulos, Efstratios
    PCI 2008: 12TH PAN-HELLENIC CONFERENCE ON INFORMATICS, PROCEEDINGS, 2008, : 8 - +
  • [43] Intrusion Detection of Industrial Control System Based on Correlation Information Entropy and CNN-BiLSTM
    Shi L.
    Zhu H.
    Liu Y.
    Liu J.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2019, 56 (11): : 2330 - 2338
  • [44] Industrial control system intrusion detection method based on belief rule base with gradient descent
    Li, Jinyuan
    Qian, Guangyu
    He, Wei
    Zhang, Wei
    COMPUTERS & SECURITY, 2025, 155
  • [45] MODELING MESSAGE SEQUENCES FOR INTRUSION DETECTION IN INDUSTRIAL CONTROL SYSTEMS
    Caselli, Marco
    Zambon, Emmanuele
    Petit, Jonathan
    Kargl, Frank
    CRITICAL INFRASTRUCTURE PROTECTION IX, 2015, 466 : 49 - 71
  • [46] An Experimental Study of Hierarchical Intrusion Detection for Wireless Industrial Sensor Networks
    Shin, Sooyeon
    Kwon, Taekyoung
    Jo, Gil-Yong
    Park, Youngman
    Rhy, Haekyu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2010, 6 (04) : 744 - 757
  • [47] Real Time Intrusion Detection System For IoT Networks
    Hattarki, Rhishabh
    Houji, Shruti
    Dhage, Manisha
    2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
  • [48] Hybrid intrusion detection system for wireless sensor networks
    Hai, Tran Hoang
    Khan, Faraz
    Huh, Eui-Nam
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2007, PT 2, PROCEEDINGS, 2007, 4706 : 383 - 396
  • [49] NeuralPot: An Industrial Honeypot Implementation Based On Deep Neural Networks
    Siniosoglou, Ilias
    Efstathopoulos, Georgios
    Pliatsios, Dimitrios
    Moscholios, Ioannis D.
    Sarigiannidis, Antonios
    Sakellari, Georgia
    Loukas, Georgios
    Sarigiannidis, Panagiotis
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 638 - 644
  • [50] Distributed Intrusion Detection System for Wireless Sensor Networks
    Medhat, Karen
    Ramadan, Rabie A.
    Talkhan, Ihab
    2015 9TH INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPLICATIONS, SERVICES AND TECHNOLOGIES (NGMAST 2015), 2015, : 234 - 239