Visible to the public Detecting Cyber Attacks in Industrial Control Systems Using Convolutional Neural Networks

TitleDetecting Cyber Attacks in Industrial Control Systems Using Convolutional Neural Networks
Publication TypeConference Paper
Year of Publication2018
AuthorsKravchik, Moshe, Shabtai, Asaf
Conference NameProceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy
PublisherACM
ISBN Number978-1-4503-5992-4
Keywordsanomaly detection, control theory, convolutional neural networks, industrial control systems, privacy, pubcrawl, resilience, Resiliency, Scalability, scalable
Abstract

This paper presents a study on detecting cyber attacks on industrial control systems (ICS) using convolutional neural networks. The study was performed on a Secure Water Treatment testbed (SWaT) dataset, which represents a scaled-down version of a real-world industrial water treatment plant. We suggest a method for anomaly detection based on measuring the statistical deviation of the predicted value from the observed value. We applied the proposed method by using a variety of deep neural network architectures including different variants of convolutional and recurrent networks. The test dataset included 36 different cyber attacks. The proposed method successfully detected 31 attacks with three false positives thus improving on previous research based on this dataset. The results of the study show that 1D convolutional networks can be successfully used for anomaly detection in industrial control systems and outperform recurrent networks in this setting. The findings also suggest that 1D convolutional networks are effective at time series prediction tasks which are traditionally considered to be best solved using recurrent neural networks. This observation is a promising one, as 1D convolutional neural networks are simpler, smaller, and faster than the recurrent neural networks.

URLhttps://dl.acm.org/citation.cfm?doid=3264888.3264896
DOI10.1145/3264888.3264896
Citation Keykravchik_detecting_2018