Multi-Stage Learning Framework Using Convolutional Neural Network and Decision Tree-Based Classification for Detection of DDoS Pandemic Attacks in SDN-Based SCADA Systems
Abstract
1. Introduction
1.1. Perspective and Goals
- SDN technology was used in this study, one of the new intelligent technologies recommended to overcome the problems experienced in traditional SCADA systems, such as manageability, service quality, and optimization. In this regard, it raises awareness.
- The dataset used in this study was obtained by creating a specially designed simulated-based experimental SDN-based SCADA architecture. The obtained dataset contains features specific to SDN-based SCADA architecture.
- This study presents a multi-class deep learning and decision tree-based classification approach to identify DDoS attacks on SDN-based SCADA systems. The presented model aims to make identifying DDoS attacks more sensitive and reliable.
- This study focuses on detecting DDoS attacks, which is a significant challenge for the security of industrial control systems. This aims to contribute to the efforts of industrial enterprises to protect their critical infrastructure.
- This study presents experimental results of the proposed approach, confirming that this approach can effectively detect DDoS attacks. These results offer the possibility of use in real-world applications for security experts and network administrators.
1.2. Organization of This Study
2. Previous Studies on the Security of SCADA
3. SDN-Based SCADA Systems
4. Methodology and Experimental Setup
4.1. Creating the Dataset
4.2. Methodology
4.3. Creation of 1D-CNN + Decision Tree Model with MS-LNet Framework
- Stage 1: This is the stage where the 1D-CNN model is trained.
- Stage 2: While training the 1D-CNN model, the 1D-CNN and the decision tree models are combined. The feature extraction capabilities of the 1D-CNN model are combined with the decision tree model. At this stage, the weights of the 1D-CNN model are frozen, so only the decision tree model is trained.
- Stage 3: The 1D-CNN and decision tree models are combined, the weights of both models are frozen, and the resulting new model is tested.
5. Experimental Results
Discussion
6. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Gaushell, D.J.; Block, W.R. SCADA communication techniques and standards. IEEE Comput. Appl. Power 1993, 6, 45–50. [Google Scholar] [CrossRef]
- Söğüt, E.; Erdem, O.A. A Multi-Model Proposal for Classification and Detection of DDoS Attacks on SCADA Systems. Appl. Sci. 2023, 13, 5993. [Google Scholar] [CrossRef]
- Kreutz, D.; Ramos, F.M.V.; Verissimo, P.E.; Rothenberg, C.E.; Azodolmolky, S.; Uhlig, S. Software-Defined Networking: A Comprehensive Survey. Proc. IEEE 2015, 103, 14–76. [Google Scholar] [CrossRef]
- Germano Da Silva, E.; Dias Knob, L.A.; Wickboldt, J.A.; Gaspary, L.P.; Granville, L.Z.; Schaeffer-Filho, A. Capitalizing on SDN-Based SCADA Systems: An Anti-Eavesdropping Case-Study. In Proceedings of the 2015 IFIP/IEEE International Symposium on Integrated Network Management (IM), Ottawa, ON, Canada, 11–15 May 2015; pp. 165–173. [Google Scholar] [CrossRef]
- EUROPOL. Catching the Virus Cybercrime, Disinformation and the COVID-19 Pandemic; EUROPOL: Hague, The Netherlands, 2020; p. 14. [Google Scholar]
- Imperva Research Lab. DDoS Attacks in the Time of COVID-19 Report; Imperva Research Labs: Austin, TX, USA, 2020; pp. 1–11. [Google Scholar]
- Krishnan, P.; Duttagupta, S.; Achuthan, K. SDNFV Based Threat Monitoring and Security Framework for Multi-Access Edge Computing Infrastructure. Mob. Netw. Appl. 2019, 24, 1896–1923. [Google Scholar] [CrossRef]
- ENISA THREAT LANDSCAPE 2021; ENISA: Athens, Greece, 2021; ISBN 9789292045364.
- Ghosh, S.; Sampalli, S. A Survey of Security in SCADA Networks: Current Issues and Future Challenges. IEEE Access 2019, 7, 135812–135831. [Google Scholar] [CrossRef]
- Saghezchi, F.B.; Mantas, G.; Violas, M.A.; de Oliveira Duarte, A.M.; Rodriguez, J. Machine Learning for DDoS Attack Detection in Industry 4.0 CPPSs. Electronics 2022, 11, 602. [Google Scholar] [CrossRef]
- Ozkan-Okay, M.; Samet, R.; Aslan, Ö.; Kosunalp, S.; Iliev, T.; Stoyanov, I. A Novel Feature Selection Approach to Classify Intrusion Attacks in Network Communications. Appl. Sci. 2023, 13, 11067. [Google Scholar] [CrossRef]
- Wang, Z.; Li, Z.; He, D.; Chan, S. A Lightweight Approach for Network Intrusion Detection in Industrial Cyber-Physical Systems Based on Knowledge Distillation and Deep Metric Learning. Expert Syst. Appl. 2022, 206, 117671. [Google Scholar] [CrossRef]
- Diaba, S.Y.; Elmusrati, M. Proposed Algorithm for Smart Grid DDoS Detection Based on Deep Learning. Neural Netw. 2023, 159, 175–184. [Google Scholar] [CrossRef]
- Wang, W.; Harrou, F.; Bouyeddou, B.; Senouci, S.M.; Sun, Y. Cyber-Attacks Detection in Industrial Systems Using Artificial Intelligence-Driven Methods. Int. J. Crit. Infrastruct. Prot. 2022, 38, 100542. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Shu, L.; Djallel, H.; Choo, K.K.R. Deep Learning-Based Intrusion Detection for Distributed Denial of Service Attack in Agriculture 4.0. Electronics 2021, 10, 1257. [Google Scholar] [CrossRef]
- Wang, W.; Harrou, F.; Bouyeddou, B.; Senouci, S.M.; Sun, Y. A Stacked Deep Learning Approach to Cyber-Attacks Detection in Industrial Systems: Application to Power System and Gas Pipeline Systems. Clust. Comput. 2022, 25, 561–578. [Google Scholar] [CrossRef]
- Mohammed, A.S.; Anthi, E.; Rana, O.; Saxena, N.; Burnap, P. Detection and Mitigation of Field Flooding Attacks on Oil and Gas Critical Infrastructure Communication. Comput. Secur. 2023, 124, 103007. [Google Scholar] [CrossRef]
- Ortega-Fernandez, I.; Sestelo, M.; Burguillo, J.C.; Piñón-Blanco, C. Network Intrusion Detection System for DDoS Attacks in ICS Using Deep Autoencoders. Wirel. Netw. 2023, 3. [Google Scholar] [CrossRef]
- Altaha, M.; Hong, S. Anomaly Detection for SCADA System Security Based on Unsupervised Learning and Function Codes Analysis in the DNP3 Protocol. Electronics 2022, 11, 2184. [Google Scholar] [CrossRef]
- Khan, F.; Alturki, R.; Rahman, M.A.; Mastorakis, S.; Razzak, I.; Shah, S.T. Trustworthy and Reliable Deep-Learning-Based Cyberattack Detection in Industrial IoT. IEEE Trans. Ind. Inform. 2023, 19, 1030–1038. [Google Scholar] [CrossRef] [PubMed]
- Rehmani, M.H.; Davy, A.; Jennings, B.; Assi, C. Software Defined Networks-Based Smart Grid Communication: A Comprehensive Survey. IEEE Commun. Surv. Tutor. 2019, 21, 2637–2670. [Google Scholar] [CrossRef]
- Yadav, G.; Paul, K. Architecture and Security of SCADA Systems: A Review. Int. J. Crit. Infrastruct. Prot. 2021, 34, 100433. [Google Scholar] [CrossRef]
- Pliatsios, D.; Sarigiannidis, P.; Lagkas, T.; Sarigiannidis, A.G. A Survey on SCADA Systems: Secure Protocols, Incidents, Threats and Tactics. IEEE Commun. Surv. Tutor. 2020, 22, 1942–1976. [Google Scholar] [CrossRef]
- Lins, T.; Oliveira, R.A.R. Energy Efficiency in Industry 4.0 Using SDN. In Proceedings of the 2017 IEEE 15th International Conference on Industrial Informatics (INDIN), Emden, Germany, 24–26 July 2017; pp. 609–614. [Google Scholar] [CrossRef]
- Polat, H.; Türkoğlu, M.; Polat, O.; Şengür, A. A Novel Approach for Accurate Detection of the DDoS Attacks in SDN-Based SCADA Systems Based on Deep Recurrent Neural Networks. Expert Syst. Appl. 2022, 197, 116748. [Google Scholar] [CrossRef]
- Shwartz-Ziv, R.; Armon, A. Tabular Data: Deep Learning Is Not All You Need. Inf. Fusion 2022, 81, 84–90. [Google Scholar] [CrossRef]
- Alzubaidi, L.; Zhang, J.; Humaidi, A.J.; Al-Dujaili, A.; Duan, Y.; Al-Shamma, O.; Santamaría, J.; Fadhel, M.A.; Al-Amidie, M.; Farhan, L. Review of Deep Learning: Concepts, CNN Architectures, Challenges, Applications, Future Directions; Springer International Publishing: Cham, Switzerland, 2021; Volume 8, ISBN 4053702100444. [Google Scholar]
- Carl, G.; Kesidis, G.; Brooks, R.R.; Rai, S. Denial-of-Service Attack-Detection Techniques. IEEE Internet Comput. 2006, 10, 82–89. [Google Scholar] [CrossRef]









| Layer | Params | Output Size | 
|---|---|---|
| Input | Input Model | |
| Conv1D | filters: 16, kernals: 5 | |
| ReLU | ||
| Conv1D | filters: 32, kernals: 5 | |
| ReLU | ||
| Conv1D | filters: 64, kernals: 5 | |
| ReLU | ||
| Flatten | ||
| Dense | nerons: 256 | |
| ReLU | ||
| Dense | nerons: 256 | |
| ReLU | ||
| Dense | nerons: 4 | |
| Softmax | Output Model | |
| Model | Accuracy | Recall | Precision | F1_Score | Specificity | 
|---|---|---|---|---|---|
| Flatten | 97.80 | 97.80 | 97.84 | 97.79 | 99.35 | 
| FC1 | 96.15 | 96.15 | 96.17 | 96.15 | 98.86 | 
| FC2 | 96.51 | 96.51 | 96.50 | 96.51 | 98.96 | 
| Ref. | Datasets | ML Algorithms | Accuracy (%) | 
|---|---|---|---|
| [12] | NSL-KDD and CICIDS2017 | KD-TCNN | Average 98 | 
| [13] | CICIDS-2017 | GRU+CNN | 99.7 | 
| [14] | Mississippi State University SCADA Laboratory | NetStack | Average 93 | 
| [15] | CIC-DDoS2019 and TON_IoT | CNN RNN DNN | Average 98 | 
| [14] | Mississippi State University SCADA Laboratory | NetStack | 97.36 | 
| [15] | Their own dataset | XGBoost | 99 | 
| [16] | ICS | Deep autoencoder | - | 
| [28] | Their own dataset | Autoencoder | 95 | 
| [20] | Their own dataset | PRU and DT | 98.5 | 
| Proposed Study | Proposed dataset in this paper | 1D-CNN and decision tree-based learning model | 97.80 | 
| Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. | 
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Polat, O.; Türkoğlu, M.; Polat, H.; Oyucu, S.; Üzen, H.; Yardımcı, F.; Aksöz, A. Multi-Stage Learning Framework Using Convolutional Neural Network and Decision Tree-Based Classification for Detection of DDoS Pandemic Attacks in SDN-Based SCADA Systems. Sensors 2024, 24, 1040. https://doi.org/10.3390/s24031040
Polat O, Türkoğlu M, Polat H, Oyucu S, Üzen H, Yardımcı F, Aksöz A. Multi-Stage Learning Framework Using Convolutional Neural Network and Decision Tree-Based Classification for Detection of DDoS Pandemic Attacks in SDN-Based SCADA Systems. Sensors. 2024; 24(3):1040. https://doi.org/10.3390/s24031040
Chicago/Turabian StylePolat, Onur, Muammer Türkoğlu, Hüseyin Polat, Saadin Oyucu, Hüseyin Üzen, Fahri Yardımcı, and Ahmet Aksöz. 2024. "Multi-Stage Learning Framework Using Convolutional Neural Network and Decision Tree-Based Classification for Detection of DDoS Pandemic Attacks in SDN-Based SCADA Systems" Sensors 24, no. 3: 1040. https://doi.org/10.3390/s24031040
APA StylePolat, O., Türkoğlu, M., Polat, H., Oyucu, S., Üzen, H., Yardımcı, F., & Aksöz, A. (2024). Multi-Stage Learning Framework Using Convolutional Neural Network and Decision Tree-Based Classification for Detection of DDoS Pandemic Attacks in SDN-Based SCADA Systems. Sensors, 24(3), 1040. https://doi.org/10.3390/s24031040
 
        





 
       