Utilizing Genetic Programming to Identify Failures in ICS Networks
Journal Article
·
· International Journal of Industrial Control Systems Security
OSTI ID:1326905
- Sandia National Lab. (SNL-NM), Albuquerque, NM (United States)
Previously, researchers have attempted to apply machine learning techniques to network anomaly detection problems. Due to the staggering amount of variety that can occur in normal networks, the results have often been underwhelming. These challenges are far less pronounced when considering industrial control system (ICS) networks. The recurrent nature of these networks results in less noise and more consistent patterns for a machine learning algorithm to recognize. Here, we propose a method of evolving decision trees through genetic programming (GP) in order to detect network anomalies, such as device outages. Our approach extracts over a dozen features from network packet captures and netflows, normalizes them, and relates them in decision trees using fuzzy logic operators. Furthermore, the trees were used to detect three specific network events from three different points on the network across a statistically significant number of runs and achieved 100% accuracy on five of the nine experiments. When the trees attempted to detect more challenging events at points of presence further from the occurrence, the accuracy averaged to above 98%. Finally, using our method, all of the evolutionary cycles of the GP algorithm are computed a-priori, allowing the best resultant trees to be deployed as semi-real-time sensors with little overhead.
- Research Organization:
- Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)
- Sponsoring Organization:
- USDOE National Nuclear Security Administration (NNSA)
- Grant/Contract Number:
- AC04-94AL85000
- OSTI ID:
- 1326905
- Report Number(s):
- SAND--2016-0481J; 618671
- Journal Information:
- International Journal of Industrial Control Systems Security, Journal Name: International Journal of Industrial Control Systems Security Journal Issue: 1 Vol. 1; ISSN 9999-0049
- Publisher:
- Infonomics SocietyCopyright Statement
- Country of Publication:
- United States
- Language:
- English
Similar Records
Fast Change Point Detection for Electricity Market Analysis
A Cyber-Physical Anomaly Detection for Wide-Area Protection Using Machine Learning
Master State Threat Identifier (masti)
Conference
·
Sun Aug 25 00:00:00 EDT 2013
·
OSTI ID:1165211
A Cyber-Physical Anomaly Detection for Wide-Area Protection Using Machine Learning
Journal Article
·
Tue Mar 16 20:00:00 EDT 2021
· IEEE Transactions on Smart Grid
·
OSTI ID:1985651
Master State Threat Identifier (masti)
Software
·
Mon Jun 27 20:00:00 EDT 2022
·
OSTI ID:code-99314