A real-time anomaly-based IDS for cyber-attack detection at the industrial process level of Critical Infrastructures
Xavier Clotet,
José Moyano and
Gladys León
International Journal of Critical Infrastructure Protection, 2018, vol. 23, issue C, 11-20
Abstract:
This work presents a real time anomaly-based detection system designed to work at the industrial process level of Critical Infrastructures (CI). The system’s core algorithm is based on negative selection and works in two phases: it first learns from the normal behaviour of the process, and then performs detection and raises alarms each time an abnormal behaviour is found. The main goal of the proposed tool is the detection of attacks targeting the physical components or devices composing the industrial process level of CI such as electric, gas or water utilities. The proposed IDS uses a multi-agent approach to tackle the complex problem of monitoring large amounts of data coming from measurements recorded by Industrial Control Systems. It was built on an open source distributed computation system for real time analysis. This tool was developed, tested, and validated during the EU-funded project PREEMPTIVE. Detection results obtained on a water treatment plant laboratory are presented and discussed.
Keywords: Critical Infrastructure Protection; Cyber security; Negative selection algorithm; Intrusion detection system; Anomaly detection; Industrial process level of critical infrastructures (search for similar items in EconPapers)
Date: 2018
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (4)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S1874548217300884
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:ijocip:v:23:y:2018:i:c:p:11-20
DOI: 10.1016/j.ijcip.2018.08.002
Access Statistics for this article
International Journal of Critical Infrastructure Protection is currently edited by Leon Strous
More articles in International Journal of Critical Infrastructure Protection from Elsevier
Bibliographic data for series maintained by Catherine Liu ().