• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类
Advanced Search
Yang An, Hu Yan, Zhou Liang, Zheng Weimin, Shi Zhiqiang, Sun Limin. An Industrial Control System Anomaly Detection Algorithm Fusion by Information Flow and State Flow[J]. Journal of Computer Research and Development, 2018, 55(11): 2532-2542. DOI: 10.7544/issn1000-1239.2018.20170671
Citation: Yang An, Hu Yan, Zhou Liang, Zheng Weimin, Shi Zhiqiang, Sun Limin. An Industrial Control System Anomaly Detection Algorithm Fusion by Information Flow and State Flow[J]. Journal of Computer Research and Development, 2018, 55(11): 2532-2542. DOI: 10.7544/issn1000-1239.2018.20170671

An Industrial Control System Anomaly Detection Algorithm Fusion by Information Flow and State Flow

More Information
  • Published Date: October 31, 2018
  • Industrial control system (ICS) has highly correlation with physical environment. As a unique type of ICS attack, sequence attack injects the normal operations into the wrong sequence positions, which disturbs the process or even destroys the equipment. At present, most anomaly detection methods for sequence attack just detect the operation sequence acquiring from information flow. However, ICS is weak in protecting itself from cyber-attacks, which means that the data of information flow can be faked by attackers. The fake data is one of the main issues that can severely affect the detection accuracy. To remedy this problem, a fusion ICS anomaly detection algorithm is proposed in this paper. This algorithm utilizes the state information of equipment to establish the state flow. Via fusing state flow with information flow, the anomaly of operation sequence can be detected from the aspects of time and order. Meanwhile, to extend the detection range and reduce the detection latency, we use the data of state flow to recognize the anomaly state of equipment between two operations, which is caused by the sequence attack or other attacks. The experimental results in an ICS testbed demonstrate that our detection algorithm can detect sequence attack efficiently and recognize part of anomaly state of ICS equipment.
  • Cited by

    Periodical cited type(7)

    1. 李翔硕,畅广辉,苏盛,阮冲,吴坡,李斌. 变电监控系统网络安全威胁指标研究综述与展望. 电力科学与技术学报. 2024(04): 1-10 .
    2. 高莉莉,高雪,林钰浩,吴钰博,范金鹏. 楼宇建筑空调系统设备错误连接关系自动检测算法. 制冷与空调(四川). 2022(02): 311-316+323 .
    3. 马标,胡梦娜,张重豪,周正寅,贾俊铖,杨荣举. 基于融合马尔科夫模型的工控网络流量异常检测方法. 信息安全学报. 2022(03): 17-32 .
    4. 燕敏,阮秀琴,赵阳,郑宏涛. 基于小样本学习的物联网异常状态修正算法. 计算机仿真. 2022(08): 389-393 .
    5. 张书钦,白光耀,李红,张敏智. 多源数据融合的物联网安全知识推理方法. 计算机研究与发展. 2022(12): 2735-2749 . 本站查看
    6. 陈国瑞,袁旭华. 基于HDFS开源架构的异常数据实时检测算法. 计算机仿真. 2021(08): 445-449 .
    7. 谢胜平. 石灰粉一体化加工设备状态检测与故障维修系统. 机械设计与制造工程. 2021(09): 44-48 .

    Other cited types(5)

Catalog

    Article views (1108) PDF downloads (484) Cited by(12)
    Turn off MathJax
    Article Contents

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return