Ensuring the security of information systems requires processing many system security events and their correlation. Such events can indicate possible threats, failures or unusual behavior, and their analysis helps to better understand attacks, determine their sources and targets. This is especially important for critical industrial equipment that is constantly monitored by multiple sensors. As a rule, for such systems, it is possible to identify several behavior patterns that are reflected in security events. The paper presents a comparative analysis of methods for identifying representative security events based on clustering of sensor data. These methods allow the grouping of security events without previously known categories, which is often found in real-world data. Each group can be represented by a feature vector that can be used for security tasks. We compare a few clustering methods such as DBSCAN, Mean-Shift and Birch on how well they separate groups of similar events. As an example of the use of representative security events, we solve the problem of anomaly detection in the SWaT (Safe Water Treatment) dataset based on a graph approach and a deep neural network.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Clustering-Based Identification of Representative Security Events for Anomaly Detection in Multivariate Sensor Data

  • Diana Levshun,
  • Igor Kotenko

摘要

Ensuring the security of information systems requires processing many system security events and their correlation. Such events can indicate possible threats, failures or unusual behavior, and their analysis helps to better understand attacks, determine their sources and targets. This is especially important for critical industrial equipment that is constantly monitored by multiple sensors. As a rule, for such systems, it is possible to identify several behavior patterns that are reflected in security events. The paper presents a comparative analysis of methods for identifying representative security events based on clustering of sensor data. These methods allow the grouping of security events without previously known categories, which is often found in real-world data. Each group can be represented by a feature vector that can be used for security tasks. We compare a few clustering methods such as DBSCAN, Mean-Shift and Birch on how well they separate groups of similar events. As an example of the use of representative security events, we solve the problem of anomaly detection in the SWaT (Safe Water Treatment) dataset based on a graph approach and a deep neural network.