LSTM-Based Detection of OT Cyber-Attacks for an Offshore HVAC-Cooling Process

Ligia Soster Ramos, Zhenyu Yang*

*Kontaktforfatter

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

1 Citationer (Scopus)

Abstract

This work explored the possibility to use a deep machine learning method for cost-effective development of an Intrusion Detection System (IDS) for an offshore Operational Technology (OT) cooling process driven by a HVAC system. Two types of cyber-attacks, namely Man-in-the-Middle (MitM) attack and Deny-of-Service (DoS), are considered at different intruding locations within a Modbus-based Supervisory-Control-And-Data-Acquisition (SCADA) and Programmable Logic Controller (PLC) network. By using the Long Short-Term Memory Neural Network (LSTM-NN) as a middle layer, the IDS is developed as a multi-layer feature classifier, which consists of sequential input, LSTM, dense, softmax and classifier layers. Training and testing data are produced from a corresponding simulation system. The IDS system uses the measurements from the ongoing system (i.e., compressor status) and the relevant process (i.e., ambient and room temperatures) along with the network information to monitor potential abnormal behaviors induced by dedicated cyber-attacks in an real-time manner. All considered attack scenarios can be successfully detected by the developed IDS within 2 min after the attack occurs. There is only one situation in which the IDS cannot identify the abnormal phenomenon is caused by a MitM(2) or DoS attack due to lack of extra signals to distinguish them. In general, this study showed a clear benefit for cost-effective development of OT IDS system using the machine learning method, subject to good availability of sufficient and high-quality data.

OriginalsprogEngelsk
Titel2023 IEEE 6th International Conference on Electronic Information and Communication Technology (ICEICT)
Antal sider6
ForlagIEEE (Institute of Electrical and Electronics Engineers)
Publikationsdato2023
Sider943-948
Artikelnummer10245766
ISBN (Trykt)979-8-3503-9906-6
ISBN (Elektronisk)979-8-3503-9905-9
DOI
StatusUdgivet - 2023
Begivenhed6th IEEE International Conference on Electronic Information and Communication Technology, ICEICT 2023 - Qingdao, Kina
Varighed: 21 jul. 202324 jul. 2023

Konference

Konference6th IEEE International Conference on Electronic Information and Communication Technology, ICEICT 2023
Land/OmrådeKina
ByQingdao
Periode21/07/202324/07/2023
NavnIEEE International Conference on Electronic Information and Communication Technology
ISSN2836-7774

Bibliografisk note

Publisher Copyright:
© 2023 IEEE.

Fingeraftryk

Dyk ned i forskningsemnerne om 'LSTM-Based Detection of OT Cyber-Attacks for an Offshore HVAC-Cooling Process'. Sammen danner de et unikt fingeraftryk.

Citationsformater