A Data-Driven Approach to Intrusion Detection for Industrial Control Systems
摘要
Industrial Control Systems (ICS) are increasingly targeted by sophisticated cyber-physical attacks, threatening the safety and reliability of critical infrastructure. Existing Intrusion Detection Systems (IDS) often struggle to address the complexity and evolving nature of such threats. This study aims to enhance IDS for ICS by applying machine learning (ML) techniques and introducing a structured classification of attack types. Using the Secure Water Treatment (SWaT) dataset, which captures real-world operational data and 36 attack scenarios, we propose a novel taxonomy of cyber-physical attacks—Physical Manipulation, Control Override, Sensor Tampering, Instrumentation/Measurement Manipulation, and Function Enabling/Disabling—enabling more precise vulnerability assessment. Multiple ML models, including Convolutional Neural Networks (CNN), K-Nearest Neighbors (KNN), Support Vector Machines, Decision Trees, Random Forests, Logistic Regression, and Multilayer Perceptrons, were evaluated through rigorous preprocessing, feature engineering, and hyperparameter tuning. Results show CNN and KNN achieving the highest detection accuracy of 98%, with strong performance across other models as well. Beyond algorithmic evaluation, the study analyzes hardware-level vulnerabilities, linking specific components to attack vectors and offering actionable recommendations. These contributions position the SWaT dataset as a benchmark for ICS cybersecurity research and support the design of resilient IDS frameworks. The findings have significant practical implications for securing critical infrastructure, reducing system downtime, and safeguarding public services.