Improving anomaly detection in SCADA network communication with attribute extension

被引:0
|
作者
Anwar M. [1 ]
Lundberg L. [1 ]
Borg A. [1 ]
机构
[1] Department of Computer Science, Blekinge Institute of Technology, 371 79, Karlskrona
关键词
Attribute extension; IEC; 60870-5-104; Machine learning; Network intrusion detection; Supervisory control and data acquisition;
D O I
10.1186/s42162-022-00252-1
中图分类号
学科分类号
摘要
Network anomaly detection for critical infrastructure supervisory control and data acquisition (SCADA) systems is the first line of defense against cyber-attacks. Often hybrid methods, such as machine learning with signature-based intrusion detection methods, are employed to improve the detection results. Here an attempt is made to enhance the support vector-based outlier detection method by leveraging behavioural attribute extension of the network nodes. The network nodes are modeled as graph vertices to construct related attributes that enhance network characterisation and potentially improve unsupervised anomaly detection ability for SCADA network. IEC 104 SCADA protocol communication data with good domain fidelity is utilised for empirical testing. The results demonstrate that the proposed approach achieves significant improvements over the baseline approach (average F1 score increased from 0.6 to 0.9, and Matthews correlation coefficient (MCC) from 0.3 to 0.8). The achieved outcome also surpasses the unsupervised scores of related literature. For critical networks, the identification of attacks is indispensable. The result shows an insignificant missed-alert rate (0.3 % on average), the lowest among related works. The gathered results show that the proposed approach can expose rouge SCADA nodes reasonably and assist in further pruning the identified unusual instances. © 2022, The Author(s).
引用
收藏
相关论文
共 50 条
  • [21] Improving Network-Based Anomaly Detection in Smart Home Environment
    Li, Xiaonan
    Ghodosi, Hossein
    Chen, Chao
    Sankupellay, Mangalam
    Lee, Ickjai
    SENSORS, 2022, 22 (15)
  • [22] A generic sampling framework for improving anomaly detection in the next generation network
    Hashim, Fazirulhisyam
    Jamalipour, Abbas
    SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (08) : 919 - 936
  • [23] Improving Data Generalization With Variational Autoencoders for Network Traffic Anomaly Detection
    Monshizadeh, Mehrnoosh
    Khatri, Vikramajeet
    Gamdou, Marah
    Kantola, Raimo
    Yan, Zheng
    IEEE ACCESS, 2021, 9 : 56893 - 56907
  • [24] Entropy-based Robust PCA for Communication Network Anomaly Detection
    Liu, Duo
    Lung, Chung-Horng
    Seddigh, Nabil
    Nandy, Biswajit
    2014 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2014, : 171 - 175
  • [25] Anomaly Detection System of Wireless Communication Network Based on Data Mining
    Chen Ningjun
    Gao Zhinian
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON COMMUNICATION, ELECTRONICS AND AUTOMATION ENGINEERING, 2013, 181 : 1257 - 1262
  • [26] Towards Model-Based Anomaly Detection in Network Communication Protocols
    Bieniasz, Jedrzej
    Sapiecha, Piotr
    Smolarczyk, Milosz
    Szczypiorski, Krzysztof
    2016 2ND INTERNATIONAL CONFERENCE ON FRONTIERS OF SIGNAL PROCESSING (ICFSP), 2015, : 126 - 130
  • [27] Communication-Efficient Federated Learning for Network Traffic Anomaly Detection
    Cui, Xiao
    Han, Xiaohui
    Liu, Guangqi
    Zuo, Wenbo
    Wang, Zhiwen
    2023 19TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN 2023, 2023, : 398 - 405
  • [28] Alarm Based Anomaly Detection of Insider Attacks in SCADA System
    Nasr, Payam Mahmoudi
    Varjani, Ali Yazdian
    2014 SMART GRID CONFERENCE (SGC), 2014,
  • [29] Wind Turbine Anomaly Detection Based on SCADA Data Mining
    Liu, Xiaoyuan
    Lu, Senxiang
    Ren, Yan
    Wu, Zhenning
    ELECTRONICS, 2020, 9 (05)
  • [30] A SCADA Data based Anomaly Detection Method for Wind Turbines
    Du, Mian
    Ma, Shichong
    He, Qing
    2016 CHINA INTERNATIONAL CONFERENCE ON ELECTRICITY DISTRIBUTION (CICED), 2016,