Abstract
In this paper, we propose an unsupervised anomaly detection method based on the Autoencoder with Long Short-Term Memory (LSTM-Autoencoder) network and Generative Adversarial Network (GAN) to detect anomalies in industrial control system (ICS) using cyber–physical fusion features. This method improves the recall of anomaly detection and overcomes the challenges of unbalanced datasets and insufficient labeled samples in ICS. As a first step, additional network features are extracted and fused with physical features to create a cyber–physical dataset. Following this, the model is trained using normal data to ensure that it can properly reconstruct the normal data. In the testing phase, samples with unknown labels are used as inputs to the model. The model will output an anomaly score for each sample, and whether a sample is anomalous depends on whether the anomaly score exceeds the threshold. Whether using supervised or unsupervised algorithms, experimentation has shown that (1) cyber–physical fusion features can significantly improve the performance of anomaly detection algorithms; (2) the proposed method outperforms several other unsupervised anomaly detection methods in terms of accuracy, recall, and F1 score; (3) the proposed method can detect the majority of anomalous events with a low false negative rate.
Funder
Natural Science Foundation of Sichuan Province
National Natural Science Foundation of China
Key Research and Development Project of Sichuan
Subject
General Mathematics,Engineering (miscellaneous),Computer Science (miscellaneous)
Reference37 articles.
1. A Unified Deep Learning Anomaly Detection and Classification Approach for Smart Grid Environments;Siniosoglou;IEEE Trans. Netw. Serv. Manag.,2021
2. ShadowPLCs: A Novel Scheme for Remote Detection of Industrial Process Control Attacks;Liu;IEEE Trans. Dependable Secur. Comput.,2022
3. Khan, R., Maynard, P., McLaughlin, K., Laverty, D.M., and Sezer, S. (2016, January 23–25). Threat Analysis of BlackEnergy Malware for Synchrophasor based Real-time Control and Monitoring in Smart Grid. Proceedings of the 4th International Symposium for ICS & SCADA Cyber Security Research, Swindon, UK.
4. Industrial Control Systems: Cyberattack trends and countermeasures;Alladi;Comput. Commun.,2020
5. Anomaly Detection, Analysis and Prediction Techniques in IoT Environment: A Systematic Literature Review;Fahim;IEEE Access,2019
Cited by
6 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献