3.8 Proceedings Paper

Research and Application of Anomaly Detection of Industrial Control System Based on Improved Zoe Algorithm

Journal

CYBERSPACE SAFETY AND SECURITY, PT I
Volume 11982, Issue -, Pages 3-12

Publisher

SPRINGER INTERNATIONAL PUBLISHING AG
DOI: 10.1007/978-3-030-37337-5_1

Keywords

Zoe algorithm; Sequence coverage; Industrial control system; Anomaly detection

Funding

  1. National Natural Science Foundation of China [61762037]
  2. Science and Technology Key Research and Development Program of Jiangxi Province [20192ACB50027]

Ask authors/readers for more resources

Due to the complexity of components and the diversity of protocols in industrial control systems, it is difficult to simply use content-based anomaly detection system with the background. This paper proposes an improved Zoe algorithm. In the algorithm, the similarity between traffics is calculated through sequence coverage. And we use Count-Mean-Min Sketch to store and count the sub-strings. Finally, we utilize clustering to achieve the anomaly detection of the industrial control system. The experimental results show that this algorithm can achieve higher detection rate and lower false positive rate of anomaly detection in industrial control systems.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available