论文标题

二进制过程数据中的入侵检测:将锤距引入矩阵概况

Intrusion Detection in Binary Process Data: Introducing the Hamming-distance to Matrix Profiles

论文作者

Anton, Simon D Duque, Schotten, Hans Dieter

论文摘要

行业的数字化提供了大量新型应用,可提高灵活性并减少设置和维护时间以及成本。此外,新颖的用例是由行业数字化(通常称为工业4.0)或工业互联网的数字化创建的,应用程序利用了通信和计算技术的使用。这使新型业务用例,例如数字双胞胎,客户个体生产和数据市场。但是,这些用例的连接性依赖性也大大增加了工业企业的攻击表面。破坏性和间谍活动针对数据,这已成为企业中最关键的资产。由于工业网络中对安全解决方案的要求与办公网络固有不同,因此需要开发入侵检测的新方法。在这项工作中,分析了包含攻击的实际水处理过程的过程数据。分析是通过矩阵轮廓的扩展(一种时间序列的基线发现算法的扩展)进行的。通过使用HammingDistance度量标准扩展矩阵配置文件,可以将二进制执行器和第三级执行器以有意义的方式集成到分析中。该算法需要较低的训练工作,同时提供准确的结果。此外,它可以以实时的方式使用。分析数据集中选定的执行器,以突出显示扩展矩阵配置文件的适用性。

The digitisation of industry provides a plethora of novel applications that increase flexibility and reduce setup and maintenance time as well as cost. Furthermore, novel use cases are created by the digitisation of industry, commonly known as Industry 4.0 or the Industrial Internet of Things, applications make use of communication and computation technology that is becoming available. This enables novel business use cases, such as the digital twin, customer individual production, and data market places. However, the inter-connectivity such use cases rely on also significantly increases the attack surface of industrial enterprises. Sabotage and espionage are aimed at data, which is becoming the most crucial asset of an enterprise. Since the requirements on security solutions in industrial networks are inherently different from office networks, novel approaches for intrusion detection need to be developed. In this work, process data of a real water treatment process that contains attacks is analysed. Analysis is performed by an extension of Matrix Profiles, a motif discovery algorithm for time series. By extending Matrix Profiles with a Hammingdistance metric, binary and tertiary actuators can be integrated into the analysis in a meaningful fashion. This algorithm requires low training effort while providing accurate results. Furthermore, it can be employed in a real-time fashion. Selected actuators in the data set are analysed to highlight the applicability of the extended Matrix Profiles.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源