Machine Learning for Intrusion Detection in Industrial Control Systems: Applications, Challenges, and Recommendations
Methods from machine learning are being applied to design Industrial Control Systems resilient to cyber-attacks. Such methods focus on two major areas: the detection of intrusions at the network-level using the information acquired through network packets, and detection of anomalies at the physical process level using data that represents the physical behavior of the system. This survey focuses on four types of methods from machine learning in use for intrusion and anomaly detection, namely, supervised, semi-supervised, unsupervised, and reinforcement learning. Literature available in the public domain was carefully selected, analyzed, and placed in a 7-dimensional space for ease of comparison. The survey is targeted at researchers, students, and practitioners. Challenges associated in using the methods and research gaps are identified and recommendations are made to fill the gaps.
Code (0)
등록된 구현이 없습니다.
Tasks
Anomaly DetectionBIG-bench Machine LearningIntrusion DetectionSurveySimilar Papers 제목 키워드 기반
Digital Twin-based Intrusion Detection for Industrial Control Systems
Digital twins have recently gained significant interest in simulation, optimization, and predictive maintenance of Industrial Control Systems (ICS). Recent studies discuss the possibility of using digital twins for intru…
Intrusion DetectionDetecting Cyberattacks in Industrial Control Systems Using Online Learning Algorithms
Industrial control systems are critical to the operation of industrial facilities, especially for critical infrastructures, such as refineries, power grids, and transportation systems. Similar to other information system…
continuous-controlContinuous ControlIntrusion DetectionA False Sense of Security? Revisiting the State of Machine Learning-Based Industrial Intrusion Detection
Anomaly-based intrusion detection promises to detect novel or unknown attacks on industrial control systems by modeling expected system behavior and raising corresponding alarms for any deviations.As manually creating th…
BIG-bench Machine LearningIntrusion DetectionClustering-Enhanced Domain Adaptation for Cross-Domain Intrusion Detection in Industrial Control Systems
Industrial control systems operate in dynamic environments where traffic distributions vary across scenarios, labeled samples are limited, and unknown attacks frequently emerge, posing significant challenges to cross-dom…
Dimensionality ReductionIntrusion DetectionTransfer LearningDomain AdaptationAdversarial Sample Generation for Anomaly Detection in Industrial Control Systems
Machine learning (ML)-based intrusion detection systems (IDS) are vulnerable to adversarial attacks. It is crucial for an IDS to learn to recognize adversarial examples before malicious entities exploit them. In this pap…
Anomaly DetectionIntrusion Detection