Visible to the public An Enhanced EWMA for Alert Reduction and Situation Awareness in Industrial Control Networks

TitleAn Enhanced EWMA for Alert Reduction and Situation Awareness in Industrial Control Networks
Publication TypeConference Paper
Year of Publication2022
AuthorsJiang, Baoxiang, Liu, Yang, Liu, Huixiang, Ren, Zehua, Wang, Yun, Bao, Yuanyi, Wang, Wenqing
Conference Name2022 IEEE 18th International Conference on Automation Science and Engineering (CASE)
Date Publishedaug
Keywordscomposability, control charts, integrated circuits, Intrusion detection, Manuals, Network security, Predictive Metrics, process control, pubcrawl, Resiliency, security situational awareness, simulation
Abstract

Intrusion detection systems (IDSs) are widely deployed in the industrial control systems to protect network security. IDSs typically generate a huge number of alerts, which are time-consuming for system operators to process. Most of the alerts are individually insignificant false alarms. However, it is not the best solution to discard these alerts, as they can still provide useful information about network situation. Based on the study of characteristics of alerts in the industrial control systems, we adopt an enhanced method of exponentially weighted moving average (EWMA) control charts to help operators in processing alerts. We classify all detection signatures as regular and irregular according to their frequencies, set multiple control limits to detect anomalies, and monitor regular signatures for network security situational awareness. Extensive experiments have been performed using real-world alert data. Simulation results demonstrate that the proposed enhanced EWMA method can greatly reduce the volume of alerts to be processed while reserving significant abnormal information.

DOI10.1109/CASE49997.2022.9926545
Citation Keyjiang_enhanced_2022