扫描手机二维码

欢迎您的访问
您是第 位访客

开通时间:..

最后更新时间:..

  • 皮德常 ( 教授 )

    的个人主页 http://faculty.nuaa.edu.cn/pdc/zh_CN/index.htm

  •   教授   博士生导师
  • 招生学科专业:
    计算机科学与技术 -- 【招收博士、硕士研究生】 -- 计算机科学与技术学院
    软件工程 -- 【招收博士、硕士研究生】 -- 计算机科学与技术学院
    网络空间安全 -- 【招收硕士研究生】 -- 计算机科学与技术学院
    电子信息 -- 【招收博士、硕士研究生】 -- 计算机科学与技术学院
论文成果 当前位置: 中文主页 >> 科学研究 >> 论文成果
Hml-ids: A hybrid-multilevel anomaly prediction approach for intrusion detection in scada systems

点击次数:
所属单位:计算机科学与技术学院/人工智能学院/软件学院
发表刊物:IEEE Access
摘要:Critical infrastructures, e.g., electricity generation and dispersal networks, chemical processing plants, and gas distribution, are governed and monitored by supervisory control and data acquisition systems (SCADA). Detecting intrusion is a prevalent area of study for numerous years, and several intrusion detection systems have been suggested in the literature for cyber-physical systems and industrial control system (ICS). In recent years, the viruses seismic net, duqu, and flame against ICS attacks have caused tremendous damage to nuclear facilities and critical infrastructure in some countries. These intensified attacks have sounded the alarm for the security of the ICS in many countries. The challenge in constructing an intrusion detection framework is to deal with unbalanced intrusion datasets, i.e. when one class is signified by a lesser amount of instances (minority class). To this end, we outline an approach to deal with this issue and propose an anomaly detection method for the ICS. Our proposed approach uses a hybrid model that takes advantage of the anticipated and consistent nature of communication patterns that occur among ground devices in ICS setups. First, we applied some preprocessing techniques to standardize and scale the data. Second, the dimensionality reduction algorithms are applied to improve the process of anomaly detection. Third, we employed an edited nearest-neighbor rule algorithm to balance the dataset. Fourth, by using the Bloom filter, a signature database is created by noting the system for a specific period lacking the occurrence of abnormalities. Finally, to detect new attacks, we combined our package contents-level detection with another instance-based learner to make a hybrid method for anomaly detection. The experimental results with a real large-scale dataset generated from a gas pipeline SCADA system show that the proposed approach HML-IDS outperforms the benchmark models with an accuracy rate of 97%. © 2013 IEEE.
是否译文:否
发表时间:2019-01-01
合写作者:Khan, Izhar Ahmed,Khan, Zaheer Ullah,Hussain, Yasir,Nawaz, Asif
通讯作者:皮德常

 

版权所有©2018- 南京航空航天大学·信息化处(信息化技术中心)