Defense-in-Depth and Machine Learning-Based Intrusion Detection for Industrial Control Systems
摘要
Industrial Control Systems (ICS), particularly Supervisory Control and Data Acquisition (SCADA) systems, face increasing security challenges due to sophisticated cyberattacks capable of breaching multiple layers of traditional Defense in Depth (DiD) protections. These attacks can potentially compromise entire control systems, posing serious risks to critical infrastructure. Addressing this challenge requires adaptive security mechanisms that dynamically respond to evolving threats without sacrificing operational efficiency. This paper proposes a new DiD architecture leveraging Service Function Chaining (SFC) enhanced with machine learning-based dynamic traffic classification and routing. Our solution deploys diverse security mechanisms—including Network Intrusion Detection Systems (NIDS) and Deep Packet Inspection (DPI)—across multiple layers to prevent attackers from circumventing all protections within any single layer. Central to this architecture is the Security Monitoring System (SMS), a novel machine learning anomaly detector that validates and refines traffic classifications made by existing tools, ensuring more accurate and reliable threat detection. Experimental evaluation demonstrates that SMS improves traffic classification reliability by 28.6% compared to conventional approaches, marking a significant advancement in ICS security. Our layered framework improves the defense of industrial environments and introduces adaptive capabilities that evolve with emerging attacks, providing a practical and resilient solution for critical infrastructure protection.