Loading [MathJax]/extensions/MathZoom.js
Detecting Anomalies in Industrial Control Systems with LSTM Neural Networks and UEBA | IEEE Conference Publication | IEEE Xplore

Detecting Anomalies in Industrial Control Systems with LSTM Neural Networks and UEBA


Abstract:

The increasing adoption of the Industrial Internet of Things and integration of operational technology with information technology networks have made industrial control s...Show More

Abstract:

The increasing adoption of the Industrial Internet of Things and integration of operational technology with information technology networks have made industrial control systems (ICS) more vulnerable to cyber-attacks, which can cause severe consequences such as disruption of critical infrastructure, loss of data, and significant financial losses. To enhance the security and resilience of these systems, anomaly detection in ICS has gained significant attention in recent years. This paper introduces ongoing research focused on using Long Short-Term Memory (LSTM) neural networks for forecasting and subsequent anomaly detection over device logs. This approach involves User and Entity Behaviour Analytics (UEBA) to analyze and define entities of interest from a real industrial plant and extract a baseline behaviour model through features that are fed into the LSTM model for predicting future events and detecting anomalies. The proposed solution has the potential to provide real-time detection of cyber and physical threats, thereby enhancing the security and resilience of industrial control systems.
Date of Conference: 21-23 June 2023
Date Added to IEEE Xplore: 07 August 2023
ISBN Information:
Conference Location: Vigo, Spain

Funding Agency:

No metrics found for this document.

I. Introduction

In the past decade, there has been a significant increase in security and safety incidents in industrial environments and critical infrastructure. Some of these incidents have led to devastating consequences, such as the Stuxnet (2010) [1] computer worm’s takeover of several Programmable Logic Controller (PLCs), resulting in the destruction of centrifuge tubes at a uranium enrichment plant in Iran. Malware attacks like BlackEnergy (2015) [2] and Industroyer (2016) [3] on Ukrainian power grids caused outages that affected thousands of users. These events highlight the vulnerability of critical infrastructures to cyber-attacks, as well as the need for effective means of detecting spurious behaviour that may represent the first signs of a threat.

Usage
Select a Year
2025

View as

Total usage sinceAug 2023:296
05101520JanFebMarAprMayJunJulAugSepOctNovDec9160000000000
Year Total:25
Data is updated monthly. Usage includes PDF downloads and HTML views.
Contact IEEE to Subscribe

References

References is not available for this document.