Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Utilizing Genetic Programming to Identify Failures in ICS Networks

Journal Article · · International Journal of Industrial Control Systems Security
OSTI ID:1326905
 [1];  [1];  [1]
  1. Sandia National Lab. (SNL-NM), Albuquerque, NM (United States)
Previously, researchers have attempted to apply machine learning techniques to network anomaly detection problems. Due to the staggering amount of variety that can occur in normal networks, the results have often been underwhelming. These challenges are far less pronounced when considering industrial control system (ICS) networks. The recurrent nature of these networks results in less noise and more consistent patterns for a machine learning algorithm to recognize. Here, we propose a method of evolving decision trees through genetic programming (GP) in order to detect network anomalies, such as device outages. Our approach extracts over a dozen features from network packet captures and netflows, normalizes them, and relates them in decision trees using fuzzy logic operators. Furthermore, the trees were used to detect three specific network events from three different points on the network across a statistically significant number of runs and achieved 100% accuracy on five of the nine experiments. When the trees attempted to detect more challenging events at points of presence further from the occurrence, the accuracy averaged to above 98%. Finally, using our method, all of the evolutionary cycles of the GP algorithm are computed a-priori, allowing the best resultant trees to be deployed as semi-real-time sensors with little overhead.
Research Organization:
Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA)
Grant/Contract Number:
AC04-94AL85000
OSTI ID:
1326905
Report Number(s):
SAND--2016-0481J; 618671
Journal Information:
International Journal of Industrial Control Systems Security, Journal Name: International Journal of Industrial Control Systems Security Journal Issue: 1 Vol. 1; ISSN 9999-0049
Publisher:
Infonomics SocietyCopyright Statement
Country of Publication:
United States
Language:
English

Similar Records

Fast Change Point Detection for Electricity Market Analysis
Conference · Sun Aug 25 00:00:00 EDT 2013 · OSTI ID:1165211

A Cyber-Physical Anomaly Detection for Wide-Area Protection Using Machine Learning
Journal Article · Tue Mar 16 20:00:00 EDT 2021 · IEEE Transactions on Smart Grid · OSTI ID:1985651

Master State Threat Identifier (masti)
Software · Mon Jun 27 20:00:00 EDT 2022 · OSTI ID:code-99314

Related Subjects