Anomaly Detection and Cybersecurity Monitoring in Industrial Control Networks using SCADA Systems
Abstract
During the last decade or so, isolation in SCADA systems has been largely replaced by significant networking, which not only enabled remote operation but also opened up an entirely new threat class. Signature-based IDS systems were not designed for the challenges that follow. Our contribution is a classifier, based on 1D-CNN and trained using a labelled sample of SCADA attacks, where special consideration has been taken for two topics which seem to be underrepresented in the literature: imbalance between normal and attack instances, and extraction of Modbus/DNP3 fields as additional input features (rather than treating all inputs equally). For the imbalance problem, we used SMOTE; for the instability experienced due to sparse industrial feature vectors, we combined Leaky-ReLU and Batch Normalisation. Result of our system on the test dataset was 78% accuracy, F1=0.69, and FAR=1.5%. Out of these three figures, the latter should be considered the most important one when talking about industrial applications of SCADA monitoring since it keeps us significantly under the 5-8% false alarms rate for similar, rule-based approaches.