A Machine Learning Model for Industrial Control System Network Attack Detection
Open Access DepositedIndustrial Control System (ICS) networks, driving physical processes that comprise our Critical Infrastructure (CI), are increasingly interconnected with new technology that may introduce new vulnerabilities. Due to the sophisticated integration of systems, ICS networks may not always possess the visibility to recognize and address network intrusion quickly and efficiently. The purpose of this praxis is to use Machine Learning (ML) to detect malicious network traffic through network packet captures and data historian logs of Modbus TCP/IP communications in an ICS environment. While previous ML research in ICS security is limited to the examination of network data or physical logs, this praxis explores new methods and models for using both network and physical data to determine potential network security alerts.The dataset used to analyze network traffic patterns and produce ML models in this praxis is published in IEEE Dataport and contains approximately 4.5 gigabytes of network traffic data and 4.5 megabytes of physical traffic data. Through exploratory analysis, feature selection, model development, and evaluation, this praxis proves that ML can detect specific classes of network intrusion and attacks with a high degree of accuracy, precision, and recall. With this research and ML-based solutions, operators may be alerted to network intrusion detection in a timely fashion to enforce corrective actions and improve ICS network availability.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.