Next Article in Journal
Epidemic Source Detection over Dynamic Networks
Next Article in Special Issue
Blockchain-Based Reputation Systems: Implementation Challenges and Mitigation
Previous Article in Journal
Analytical Drain Current Model for a-SiGe:H Thin Film Transistors Considering Density of States
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data

1
School of Computer Science & Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia
2
Department of Computer Science, College of Computer Science & Information Technology, Al Baha University, Al Baha 65527, Saudi Arabia
3
Distributed Systems and Networking (DSN) Discipline, School of Computer Science and Information Technology (CSIT), RMIT University, Melbourne, VIC 3000, Australia
4
Department of Information Systems and Technology, College of Computer Science & Engineering, Jeddah University, Jeddah 23218, Saudi Arabia
5
Center for Research in Data Sciences, Universiti Teknologi PETRONAS, Seri Iskandar 32610, Malaysia
*
Authors to whom correspondence should be addressed.
Electronics 2020, 9(6), 1017; https://doi.org/10.3390/electronics9061017
Submission received: 17 April 2020 / Revised: 6 June 2020 / Accepted: 12 June 2020 / Published: 18 June 2020
(This article belongs to the Special Issue Security and Trust in Next Generation Cyber-Physical Systems)

Abstract

Supervisory control and data acquisition (SCADA) systems monitor and supervise our daily infrastructure systems and industrial processes. Hence, the security of the information systems of critical infrastructures cannot be overstated. The effectiveness of unsupervised anomaly detection approaches is sensitive to parameter choices, especially when the boundaries between normal and abnormal behaviours are not clearly distinguishable. Therefore, the current approach in detecting anomaly for SCADA is based on the assumptions by which anomalies are defined; these assumptions are controlled by a parameter choice. This paper proposes an add-on anomaly threshold technique to identify the observations whose anomaly scores are extreme and significantly deviate from others, and then such observations are assumed to be ”abnormal”. The observations whose anomaly scores are significantly distant from ”abnormal” ones will be assumed as ”normal”. Then, the ensemble-based supervised learning is proposed to find a global and efficient anomaly threshold using the information of both ”normal”/”abnormal” behaviours. The proposed technique can be used for any unsupervised anomaly detection approach to mitigate the sensitivity of such parameters and improve the performance of the SCADA unsupervised anomaly detection approaches. Experimental results confirm that the proposed technique achieved a significant improvement compared to the state-of-the-art of two unsupervised anomaly detection algorithms.
Keywords: SCADA security; intrusion detection; unsupervised learning; Industrial Internet of Things (IIoT); information-security; security threats; vulnerability measurement SCADA security; intrusion detection; unsupervised learning; Industrial Internet of Things (IIoT); information-security; security threats; vulnerability measurement

Share and Cite

MDPI and ACS Style

Almalawi, A.; Fahad, A.; Tari, Z.; Khan, A.I.; Alzahrani, N.; Bakhsh, S.T.; Alassafi, M.O.; Alshdadi, A.; Qaiyum, S. Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data. Electronics 2020, 9, 1017. https://doi.org/10.3390/electronics9061017

AMA Style

Almalawi A, Fahad A, Tari Z, Khan AI, Alzahrani N, Bakhsh ST, Alassafi MO, Alshdadi A, Qaiyum S. Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data. Electronics. 2020; 9(6):1017. https://doi.org/10.3390/electronics9061017

Chicago/Turabian Style

Almalawi, Abdulmohsen, Adil Fahad, Zahir Tari, Asif Irshad Khan, Nouf Alzahrani, Sheikh Tahir Bakhsh, Madini O. Alassafi, Abdulrahman Alshdadi, and Sana Qaiyum. 2020. "Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data" Electronics 9, no. 6: 1017. https://doi.org/10.3390/electronics9061017

APA Style

Almalawi, A., Fahad, A., Tari, Z., Khan, A. I., Alzahrani, N., Bakhsh, S. T., Alassafi, M. O., Alshdadi, A., & Qaiyum, S. (2020). Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data. Electronics, 9(6), 1017. https://doi.org/10.3390/electronics9061017

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop