Industrial Control Malicious Traffic Anomaly Detection System Based on Deep Autoencoder

2021 
Industrial control network is a direct interface between information system and physical control process. Due to the lack of authentication and encryption and other necessary security protection design, it has became the main target of malicious attacks under the trend of increasing openness. In order to protect the industrial control systems, we examine that the detection of abnormal traffic in industrial control network, and propose a method of detecting abnormal traffic in industrial control network based on Auto-Encoder technology. What’s more, a new deep Auto-Encoder model was designed to reduce the dimensionality of traffic data in industrial control network. In this paper, the Kullback-Leibler Divergence was added to the loss function to improve the ability of feature extraction and the ability of recover from raw data. Finally, this model was compared with the traditional data dimensionality reduction method (Principal Component Analysis (PCA), Independent Component Analysis (ICA), Singular Value Decomposition (SVD)) on the gas pipline dataset. The results show that the approach designed in this paper outperforms the three methods in different scenes, in terms of f1score.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    8
    References
    0
    Citations
    NaN
    KQI
    []