Attack detection in industrial control systems (ICS) using machine learning (ML) is a frequently addressed problem. Due to the lack of real-world traffic data in this area, the design and evaluation of attack detection approaches for operational technology (OT) traffic often exclusively rely on public datasets generated from testbeds. A frequently pursued approach is anomaly detection identifying attacks as deviations from normal activities. Its potential is usually motivated by the homogeneity of ICS communication, although this assumption has hardly been proven. In this work, we examine how representative currently available OT traffic datasets are by comparing detection-relevant characteristics with OT traffic captured in three real OT networks. Furthermore, we quantify the homogeneity degree of all datasets from the perspective of self-learning anomaly detection systems when applied to this traffic. From both analyses, we derive implications for the design and evaluation of such systems and their reliable operation in real OT networks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Questioning the Myth: Investigating ICS Traffic Homogeneity from an Anomaly Detection Perspective

  • Franka Schuster,
  • Hartmut König

摘要

Attack detection in industrial control systems (ICS) using machine learning (ML) is a frequently addressed problem. Due to the lack of real-world traffic data in this area, the design and evaluation of attack detection approaches for operational technology (OT) traffic often exclusively rely on public datasets generated from testbeds. A frequently pursued approach is anomaly detection identifying attacks as deviations from normal activities. Its potential is usually motivated by the homogeneity of ICS communication, although this assumption has hardly been proven. In this work, we examine how representative currently available OT traffic datasets are by comparing detection-relevant characteristics with OT traffic captured in three real OT networks. Furthermore, we quantify the homogeneity degree of all datasets from the perspective of self-learning anomaly detection systems when applied to this traffic. From both analyses, we derive implications for the design and evaluation of such systems and their reliable operation in real OT networks.