Multi-level Anomaly Detection in Industrial Control Systems via Package Signatures and LSTM networks

被引:147
作者
Feng, Cheng [1 ]
Li, Tingting [1 ]
Chana, Deeph [1 ]
机构
[1] Imperial Coll London, Inst Secur Sci & Technol, London, England
来源
2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN) | 2017年
基金
英国工程与自然科学研究理事会;
关键词
industrial control systems; anomaly detection; signature database; long short term memory networks; Bloom filters; INTRUSION DETECTION; NETS; TIME;
D O I
10.1109/DSN.2017.34
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We outline an anomaly detection method for industrial control systems (ICS) that combines the analysis of network package contents that are transacted between ICS nodes and their time-series structure. Specifically, we take advantage of the predictable and regular nature of communication patterns that exist between so-called field devices in ICS networks. By observing a system for a period of time without the presence of anomalies we develop a base-line signature database for general packages. A Bloom filter is used to store the signature database which is then used for package content level anomaly detection. Furthermore, we approach time-series anomaly detection by proposing a stacked Long Short Term Memory (LSTM) network-based softmax classifier which learns to predict the most likely package signatures that are likely to occur given previously seen package traffic. Finally, by the inspection of a real dataset created from a gas pipeline SCADA system, we show that an anomaly detection scheme combining both approaches can achieve higher performance compared to various current state-of-the-art techniques.
引用
收藏
页码:261 / 272
页数:12
相关论文
共 56 条
[1]  
[Anonymous], INC RESP ACT NOV 201
[2]  
[Anonymous], IEEE S HIGH ASS SYST
[3]  
[Anonymous], 2016, INT C CRIT INF INFR
[4]  
[Anonymous], ICS CSER YEAR REV
[5]  
[Anonymous], ARXIV151200486
[6]  
[Anonymous], 2012, Power Generation, Operation, and Control
[7]  
[Anonymous], 2008, BOTMINER CLUSTERING
[8]  
[Anonymous], 2013, INT J ADV MANUF TECH, DOI DOI 10.1007/S00170-013-5017-7
[9]  
[Anonymous], 2015, ARXIV150601057
[10]  
[Anonymous], 2011, GUIDE IND CONTROL SY