Electronic Thesis/Dissertation
 

Detecting Early-Stage Threat Actor Activity in Industrial Internet of Things (IIoT) Networks

Open Access Deposited

Categorical Boosting Classifier (CatBoost), Decision Tree Classifier (DT), Extreme Trees Classifier (ET), Extreme Gradient Boosting (XGBoost), HistGradientBoostingClassifier (HGBT), K-Nearest Neighbors (KNN), Light Gradient Boosting Machine (LightGBM), Naïve Bayes (NB), Random Forest (RF), and Support Vector Machine (SVM). Unsupervised algorithms, K-Means Clustering (KMC) and Isolation Forest (IsoF), were also compared against the binary instantiation of the supervised learning models. Finally, a supervised deep learning model, Gated Recurrent Unit (GRU), was included in the pool of candidates. The models are trained on a modern dataset, X-IIoTID (Al-Hawawreh et al., 2022), to provide exposure to various protocols and devices within the IIoT ecosystem and adversarial Tactics, Techniques, and Procedures (TTP). CatBoost, HGBT, LightGBM, and XGBoost were selected for hyperparameter tuning to optimize the F1 score in a conservative approach that balances false positives and negatives. This research confirms that CatBoost was the most effective of the four optimized models evaluated for detecting threat actor reconnaissance and lateral movement activities within the Industrial Internet of Things (IIoT) ecosystem. The CatBoost model proved to be the most effective when evaluated by the Matthews Correlation Coefficient (MCC) and F1 score, achieving 97.34% and 97.86% for binary classification, respectively. CatBoost also achieved the highest MCC score for the three-class (Normal vs. Reconnaissance and Lateral Movement) and eight-class multiclassification (Normal vs. seven attack techniques) tasks, at 96.64% and 94.51% respectively.

Detecting Early-Stage Threat Actor Activity in Industrial Internet of Things (IIoT) Networks The rate of attacks on the world's critical infrastructure increased by 30% between 2022 and 2023 (Forescout Technologies, 2024), raising concerns among policymakers and the public about vulnerabilities in this sector. Threat actors' ability to infiltrate networks, conduct reconnaissance, and move undetected is a significant concern. This research demonstrates how a detection model based on supervised or unsupervised machine learning can be leveraged across the Industrial Internet of Things (IIoT) ecosystem to enhance intrusion detection capabilities. This research explicitly targets the detection of threat actor activity post-exploitation. Internal network reconnaissance and lateral movement are the initial steps after a threat actor gains a foothold. Additionally, these activities are typically stealthy and less destructive compared to the more aggressive actions often associated with achieving the objective (e.g., ransomware or denial of service). The semi-benign nature of reconnaissance and lateral movement is necessary as the threat actor must remain undetected long enough to achieve their goal. A comparative analysis was conducted among supervised and unsupervised learning models for detecting threat actor reconnaissance and lateral movement activities inside the IIoT network. The shallow supervised models include

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Dash_gwu_0075A_17457.pdf Dash_gwu_0075A_17457.pdf 2025-12-11 Open Access