SwePub
Sök i LIBRIS databas

  Utökad sökning

id:"swepub:oai:DiVA.org:mdh-64624"
 

Sökning: id:"swepub:oai:DiVA.org:mdh-64624" > A hybrid behavior- ...

A hybrid behavior- and Bayesian network-based framework for cyber–physical anomaly detection

Faramondi, Luca (författare)
Unit of Automatic Control, University Campus Bio-Medico di Roma, Via Alvaro del Portillo 21, 00128, Rome, Italy
Flammini, Francesco, Senior Lecturer, 1978- (författare)
Mälardalens universitet,Innovation och produktrealisering
Guarino, Simone (författare)
Unit of Automatic Control, University Campus Bio-Medico di Roma, Via Alvaro del Portillo 21, 00128, Rome, Italy
visa fler...
Setola, Roberto (författare)
IDSIA USI-SUPSI, Department of Innovative Technologies, University of Applied Sciences and Arts of Southern Switzerland, 6962 Lugano, Switzerland
visa färre...
 (creator_code:org_t)
2023
2023
Engelska.
Ingår i: Computers & electrical engineering. - 0045-7906 .- 1879-0755. ; 112
  • Tidskriftsartikel (refereegranskat)
Abstract Ämnesord
Stäng  
  • In recent years, the increasing Internet connectivity and heterogeneity of industrial protocols have been raising the number and nature of cyber-attacks against Industrial Control Systems (ICS). Such cyber-attacks may lead to cyber anomalies and further to the failure of physical components, thus leading to cyber–physical attacks. In this paper, we present a novel unsupervised cyber–physical anomaly detection framework based on a hybrid “multi-formalism” approach that combines the outcomes of multiple unsupervised behavior-based anomaly detectors through a Bayesian network-based probabilistic modeling of the ICS. More precisely, the framework consists of two behavior-based anomaly detection modules that monitor separately and simultaneously the behavior of cyber and physical data acquired from the ICS. The outputs of such modules are filtered and combined through a Bayesian network-based modeling in order to improve the trustworthiness of the detected anomalies and to provide the detection probability of cyber, physical, and cyber–physical anomalies, taking into account possible cascading effects over the cyber–physical process. The outcomes achieved through the implementation of our framework on the hardware-in-the-loop Water Distribution Testbed (WDT) dataset show very high detection performance with a strong ability to reject false positive events and to isolate and localize the anomalies over the cyber–physical process.

Ämnesord

TEKNIK OCH TEKNOLOGIER  -- Elektroteknik och elektronik -- Datorsystem (hsv//swe)
ENGINEERING AND TECHNOLOGY  -- Electrical Engineering, Electronic Engineering, Information Engineering -- Computer Systems (hsv//eng)

Publikations- och innehållstyp

ref (ämneskategori)
art (ämneskategori)

Hitta via bibliotek

Till lärosätets databas

Sök utanför SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy