Anomaly detection is a significant problem in Operational Technology (OT) networks. Given a collection of network traffic, detecting anomalies is paramount due to safety and functionality concerns. This paper seeks to prove the effectiveness of anomaly-based Intrusion Detection Systems (IDS) to protect Industrial Control Systems (ICS) from cyberattacks. Our two-stage anomaly detection strategy employs heuristics and the byte histogram data structure to detect malicious activity as packets enter the network. The novelty of our byte histogram data structure is the ability to detect anomalies in packets where the details of every protocol in the packet are unknown. This paper discusses the heuristics used in Stage One, the usage and effectiveness of byte histograms used in Stage Two, and the algorithms used to process packet information. Using an OT network traffic dataset, we evaluate our approach using multiple attack examples, achieving an average F2 Score of 99.81%.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Using Heuristics and Byte Histograms to Detect Anomalies in OT Network Traffic

  • Philip Rahal,
  • Jack Nunnelee,
  • Alex Howe,
  • Mauricio Papa

摘要

Anomaly detection is a significant problem in Operational Technology (OT) networks. Given a collection of network traffic, detecting anomalies is paramount due to safety and functionality concerns. This paper seeks to prove the effectiveness of anomaly-based Intrusion Detection Systems (IDS) to protect Industrial Control Systems (ICS) from cyberattacks. Our two-stage anomaly detection strategy employs heuristics and the byte histogram data structure to detect malicious activity as packets enter the network. The novelty of our byte histogram data structure is the ability to detect anomalies in packets where the details of every protocol in the packet are unknown. This paper discusses the heuristics used in Stage One, the usage and effectiveness of byte histograms used in Stage Two, and the algorithms used to process packet information. Using an OT network traffic dataset, we evaluate our approach using multiple attack examples, achieving an average F2 Score of 99.81%.