Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A comparison of Unsupervised Learning Algorithms for Intrusion Detection in IEC 104 SCADA Protocol
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.ORCID iD: 0000-0001-7486-5216
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.ORCID iD: 0000-0002-8929-7220
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.
2021 (English)In: Proceedings - International Conference on Machine Learning and Cybernetics, IEEE Computer Society , 2021Conference paper, Published paper (Refereed)
Abstract [en]

The power grid is a build-up of a mesh of thousands of sensors, embedded devices, and terminal units that communicate over different media. The heterogeneity of modern and legacy equipment calls for attention towards diverse network security measures. The critical infrastructure employs different security measures to detect and prevent adversaries, e.g., through signature-based tools. These approaches lack the potential to identify unknown attacks. Machine learning has the prospective to address novel attack vectors. This paper systematically evaluates the efficacy of learning algorithms from different families for intrusion detection in IEC 60870-5-104 protocol. One-class SVM and k-Nearest Neighbour unsupervised learning models show small potential when being tested on the IEC 104 unseen dataset with Area Under the Curve score 0.64 and 0.59, in the same order; and Matthews Correlation Coefficient value 0.3 and 0.2, respectively. The experimental results suggest little feasibility of the evaluated unsupervised learning approaches for anomaly detection in IEC 104 communication and recommend coupling it with other anomaly detection techniques. © 2021 IEEE.

Place, publisher, year, edition, pages
IEEE Computer Society , 2021.
Series
PROCEEDINGS OF 2021 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS (ICMLC), ISSN 2160-133X
Keywords [en]
Friedman Test, IEC 60870-5-104, Intrusion Detection, SCADA protocol, Unsupervised Machine Learning, Anomaly detection, Electric power transmission networks, Learning algorithms, Nearest neighbor search, Network security, Support vector machines, Unsupervised learning, Embedded device, Intrusion-Detection, Power grids, SCADA Protocols, Security measure, Unsupervised learning algorithms
National Category
Computer Sciences Computer Systems
Identifiers
URN: urn:nbn:se:bth-22856DOI: 10.1109/ICMLC54886.2021.9737267ISI: 000805238500010Scopus ID: 2-s2.0-85127783347ISBN: 9781665466080 OAI: oai:DiVA.org:bth-22856DiVA, id: diva2:1653611
Conference
20th International Conference on Machine Learning and Cybernetics, ICMLC 2021, Adelaide, Australia, 4 December 2021 through 5 December 2021
Available from: 2022-04-22 Created: 2022-04-22 Last updated: 2022-07-01Bibliographically approved

Open Access in DiVA

fulltext(496 kB)358 downloads
File information
File name FULLTEXT01.pdfFile size 496 kBChecksum SHA-512
d9a77e2450cab09a924ceeaf76dbe2c9cf8b0b6f6852eaa701b1f2581562b74982da3e4e16a90fabdfcc48b89d0d4533d1201c2043454a21d4d29505622a8a93
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Anwar, MahwishBorg, AntonLundberg, Lars

Search in DiVA

By author/editor
Anwar, MahwishBorg, AntonLundberg, Lars
By organisation
Department of Computer Science
Computer SciencesComputer Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 358 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 132 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf