An HMM-Based Anomaly Detection Approach for SCADA Systems - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

An HMM-Based Anomaly Detection Approach for SCADA Systems

Artemios G. Voyiatzis
  • Fonction : Auteur
  • PersonId : 1022684

Résumé

We describe the architecture of an anomaly detection system based on the Hidden Markov Model (HMM) for intrusion detection in Industrial Control Systems (ICS) and especially in SCADA systems interconnected using TCP/IP. The proposed system exploits the unique characteristics of ICS networks and protocols to efficiently detect multiple attack vectors. We evaluate the proposed system in terms of detection accuracy using as reference datasets made available by other researchers. These datasets refer to real industrial networks and contain a variety of identified attack vectors. We benchmark our findings against a large set of machine learning algorithms and demonstrate that our proposal exhibits superior performance characteristics.
Fichier principal
Vignette du fichier
421627_1_En_6_Chapter.pdf (295.94 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01639609 , version 1 (20-11-2017)

Licence

Paternité

Identifiants

Citer

Kyriakos Stefanidis, Artemios G. Voyiatzis. An HMM-Based Anomaly Detection Approach for SCADA Systems. 10th IFIP International Conference on Information Security Theory and Practice (WISTP), Sep 2016, Heraklion, Greece. pp.85-99, ⟨10.1007/978-3-319-45931-8_6⟩. ⟨hal-01639609⟩
207 Consultations
350 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More