Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Inter-Domain Fusion for Enhanced Intrusion Detection in Power Systems: An Evidence Theoretic and Meta-Heuristic Approach

Journal Article · · Sensors
DOI:https://doi.org/10.3390/s22062100· OSTI ID:1854055

False alerts due to misconfigured or compromised intrusion detection systems (IDS) in industrial control system (ICS) networks can lead to severe economic and operational damage. However, research using deep learning to reduce false alerts often requires the physical and cyber sensor data to be trustworthy. Implicit trust is a major problem for artificial intelligence or machine learning (AI/ML) in cyber-physical system (CPS) security, because when these solutions are most urgently needed is also when they are most at risk (e.g., during an attack). To address this, the Inter-Domain Evidence theoretic Approach for Inference (IDEA-I) is proposed that reframes the detection problem as how to make good decisions given uncertainty. Specifically, an evidence theoretic approach leveraging Dempster–Shafer (DS) combination rules and their variants is proposed for reducing false alerts. A multi-hypothesis mass function model is designed that leverages probability scores obtained from supervised-learning classifiers. Using this model, a location-cum-domain-based fusion framework is proposed to evaluate the detector’s performance using disjunctive, conjunctive, and cautious conjunctive rules. The approach is demonstrated in a cyber-physical power system testbed, and the classifiers are trained with datasets from Man-In-The-Middle attack emulation in a large-scale synthetic electric grid. For evaluating the performance, we consider plausibility, belief, pignistic, and general Bayesian theorem-based metrics as decision functions. To improve the performance, a multi-objective-based genetic algorithm is proposed for feature selection considering the decision metrics as the fitness function. Finally, we present a software application to evaluate the DS fusion approaches with different parameters and architectures.

Sponsoring Organization:
USDOE
Grant/Contract Number:
OE0000895
OSTI ID:
1854055
Alternate ID(s):
OSTI ID: 1981184
Journal Information:
Sensors, Journal Name: Sensors Journal Issue: 6 Vol. 22; ISSN SENSC9; ISSN 1424-8220
Publisher:
MDPI AGCopyright Statement
Country of Publication:
Switzerland
Language:
English

References (22)

Dempster's rule of combination is #P-complete journal July 1990
The transferable belief model journal April 1994
Conjunctive and disjunctive combination of belief functions induced by nondistinct bodies of evidence journal February 2008
Lightweight and secure authentication scheme for IoT network based on publish–subscribe fog computing model journal November 2021
Network Anomaly Detection System using Genetic Algorithm and Fuzzy Logic journal February 2018
An efficient intrusion detection system based on hypergraph - Genetic algorithm for parameter optimization and feature selection in support vector machine journal October 2017
Man‐in‐the‐middle attacks and defence in a power system cyber‐physical testbed journal June 2021
Design and evaluation of a cyber‐physical testbed for improving attack resilience of power systems journal June 2021
A neural network classifier based on Dempster-Shafer theory journal March 2000
A fast and elitist multiobjective genetic algorithm: NSGA-II journal April 2002
Multi-Source Multi-Domain Data Fusion for Cyberattack Detection in Power Systems journal January 2021
A Framework for Cyber-Physical Model Creation and Evaluation conference December 2019
Artificially Intelligent Electronic Money journal July 2021
The real story of stuxnet journal March 2013
Classifier Fusion Using Dempster-Shafer theory of evidence to Predict Breast Cancer Tumors conference November 2006
Genetic Algorithms in the Framework of Dempster-Shafer Theory of Evidence for Maintenance Optimization Problems journal June 2015
A Cyber-Physical Modeling and Assessment Framework for Power Grid Infrastructures journal September 2015
Distributed Combined Authentication and Intrusion Detection With Data Fusion in High-Security Mobile Ad Hoc Networks journal March 2011
Prioritizing intrusion analysis using Dempster-Shafer theory conference January 2011
A survey of intrusion detection on industrial control systems journal August 2018
Survey of intrusion detection systems: techniques, datasets and challenges journal July 2019
Cyber-Physical Dataset for MiTM attacks in Power Systems dataset January 2021

Similar Records

Related Subjects