MEIR KALECH

Senior Academic

Time series processing-based malicious activity detection in SCADA systems

Michael Zaslavski, Meir Kalech

Many critical infrastructures, essential to modern life, such as oil and gas pipeline control and electricity distribution, are managed by SCADA systems. In the contemporary landscape, these systems are interconnected to the internet, rendering them vulnerable to numerous cyber-attacks. Consequently, ensuring SCADA security has become a crucial area of research. This paper focuses on detecting attacks that manipulate the timing of commands within the system, while maintaining their original order and content. To address this challenge, we propose several machine-learning-based methods. The first approach relies on Long-Short-Term Memory model, and the second utilizes Hierarchical Temporal Memory model, both renowned for their effectiveness in detecting patterns in time-series data. We rigorously evaluate our methods using a real-life SCADA system dataset and show that they outperform previous techniques designed to combat such attacks.

Publication language English
Journal Internet of Things (The Netherlands)
Volume 28
Publication status Published - 01.12.2024
Article Number 101355

Keywords

Anomaly detection
Intrusion detection
SCADA
Time-series

ASJC Scopus subject areas

Software
Computer Science (miscellaneous)
Information Systems
Engineering (miscellaneous)
Hardware and Architecture
Computer Science Applications
Artificial Intelligence
Management of Technology and Innovation
Access to Document
10.1016/j.iot.2024.101355
Other files and links
Link to publication in Scopus