Deep Learning-Based Anomaly Detection in Industrial Control System Network Traffic
摘要
Through this paper, we investigate the use of AI approaches for the purpose of enhancing industrial control system (ICS) network security. As traditional ICS physical testbeds are expensive and lack flexibility, in contrast, ICS simulators offer cost-effectiveness and versatile scenario selection. Our study uses an open-source ICS simulator for a water bottle-filling scenario. We collected network traffic data during normal operations and subjected the system to various attacks, including DDoS, MITM, and replay attacks. This data served as the basis for training a deep neural network designed for classifying network traffic into two categories: normal and malicious. We used a domain transfer technique to transform network traffic into the visual domain and used a convolutional neural network to perform traffic classification. Our findings were highly compelling, demonstrating AI’s effectiveness in detecting malicious traffic within operational technology (OT) and ICS networks. Looking ahead, our future research aims to expand this study to encompass a wider range of ICS scenarios and a broader spectrum of cyberattacks.