An Anomaly Detection Method for Industrial System Cybersecurity Based on GGL-WAVE-CNN
摘要
Detecting anomalies in industrial system cybersecurity is critical for enabling automated decision-making. Current approaches often struggle to handle complex, unknown topological time series data, thereby necessitating improved anomaly detection accuracy. This paper introduces a novel two-level anomaly detection framework that combines the generalized graph Laplacian (GGL), wavelet decomposition (WAVE), and an enhanced convolutional neural network (CNN). In the first level, the proposed method employs the GGL to efficiently identify abnormal windows in industrial time series data. In the second level, a precise anomaly detection technique is developed to analyze the abnormal windows identified by GGL, leveraging wavelet decomposition for feature extraction and a refined CNN for classification. The effectiveness of the proposed GGL-WAVE-CNN approach is validated using a real-world dataset capturing SCADA system network traffic from a facility in China. Experimental results demonstrate a true positive rate (TPR) of 97.54%, highlighting the robustness and accuracy of the proposed method in addressing complex industrial cybersecurity challenges.