By monitoring system activity and categorising it as either normal or anomalous, an anomaly-based intrusion detection system can identify computer and network intrusions as well as misuse. In Cyber Physical Systems, anomaly-based intrusion detection is a crucial task as it can help prevent system failures, ensure safety, and optimise performance. This research work evaluates the effectiveness of various Machine Learning models for anomaly-based intrusion detection in training using the confusion matrix of expected outcomes. Elliptic Envelope, Isolation Forest, and One-class SVM anomaly detection techniques are utilized here. Subsequently, the models underwent training, testing on input data, and parameter tuning to achieve the peak performance. The results with the functionality of the Elliptic Envelope seems to be lacking, especially in approach 2. In approach 1, the combination of the OC-SVM and Isolation Forest takes into consideration of individual variables. On the other hand, approach 2 suggests that the OC-SVM should be prioritized due to the intricate nature of matching algorithms. This analysis aims to enhance the capacity to identify intrusions and protect continuous processes from deviations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cognitive Computing in Cyber Physical Systems: A Robust Computational Strategy for Anomaly Detection

  • K. S. Aakaash,
  • N. D. Patel,
  • Ajeet Singh

摘要

By monitoring system activity and categorising it as either normal or anomalous, an anomaly-based intrusion detection system can identify computer and network intrusions as well as misuse. In Cyber Physical Systems, anomaly-based intrusion detection is a crucial task as it can help prevent system failures, ensure safety, and optimise performance. This research work evaluates the effectiveness of various Machine Learning models for anomaly-based intrusion detection in training using the confusion matrix of expected outcomes. Elliptic Envelope, Isolation Forest, and One-class SVM anomaly detection techniques are utilized here. Subsequently, the models underwent training, testing on input data, and parameter tuning to achieve the peak performance. The results with the functionality of the Elliptic Envelope seems to be lacking, especially in approach 2. In approach 1, the combination of the OC-SVM and Isolation Forest takes into consideration of individual variables. On the other hand, approach 2 suggests that the OC-SVM should be prioritized due to the intricate nature of matching algorithms. This analysis aims to enhance the capacity to identify intrusions and protect continuous processes from deviations.