Questioning the Myth: Investigating ICS Traffic Homogeneity from an Anomaly Detection Perspective
摘要
Attack detection in industrial control systems (ICS) using machine learning (ML) is a frequently addressed problem. Due to the lack of real-world traffic data in this area, the design and evaluation of attack detection approaches for operational technology (OT) traffic often exclusively rely on public datasets generated from testbeds. A frequently pursued approach is anomaly detection identifying attacks as deviations from normal activities. Its potential is usually motivated by the homogeneity of ICS communication, although this assumption has hardly been proven. In this work, we examine how representative currently available OT traffic datasets are by comparing detection-relevant characteristics with OT traffic captured in three real OT networks. Furthermore, we quantify the homogeneity degree of all datasets from the perspective of self-learning anomaly detection systems when applied to this traffic. From both analyses, we derive implications for the design and evaluation of such systems and their reliable operation in real OT networks.