Improving SIEM for Critical SCADA Water Infrastructures Using Machine Learning
Network Control Systems (NAC) have been used in many industrial processes. They aim to reduce the human factor burden and efficiently handle the complex process and communication of those systems. Supervisory control and data acquisition (SCADA) systems are used in industrial, infrastructure and facility processes (e.g. manufacturing, fabrication, oil and water pipelines, building ventilation, etc.) Like other Internet of Things (IoT) implementations, SCADA systems are vulnerable to cyber-attacks, therefore, a robust anomaly detection is a major requirement. However, having an accurate anomaly detection system is not an easy task, due to the difficulty to differentiate between cyber-attacks and system internal failures (e.g. hardware failures). In this paper, we present a model that detects anomaly events in a water system controlled by SCADA. Six Machine Learning techniques have been used in building and evaluating the model. The model classifies different anomaly events including hardware failures (e.g. sensor failures), sabotage and cyber-attacks (e.g. DoS and Spoofing). Unlike other detection systems, our proposed work helps in accelerating the mitigation process by notifying the operator with additional information when an anomaly occurs. This additional information includes the probability and confidence level of event(s) occurring. The model is trained and tested using a real-world dataset.
Files in this item
Showing items related by title, author, creator and subject.
Communication avec acteMERIEN, Thibaud; BELLEKENS, Xavier; BROSSET, David; CLARAMUNT, Christophe (IEEE, 2018)Computer networks are ubiquitous and growing exponentially, with a predicted 50 billion devices connected by 2050. This tremendous growth dramatically increases the attack surface of both private and public networks. These ...
Article dans une revue avec comité de lectureBELLILI, Amar; DAVID, Nicolas; WANG, Qingxiao; GOUTILLE, Yannick; RICHAUD, Emmanuel (Elsevier, 2012)This paper reports a study of mineral oil diffusion through a filled ethylene-vinyl acetate crosslinked polymer, together with some comparisons with aliphatic linear hydrocarbons. Permeation was monitored by classical ...
A flexible decision-aid system for sites selection and technology options for a marine energy system Communication avec acteMASLOV, Nicolas; BROSSET, David; CLARAMUNT, Christophe; CHARPENTIER, Jean-Frederic (IET, 2014)The aim of the paper is to introduce a flexible system whose objective is to help industrials and decision-makers to efficiently install a marine energy farm in a suitable area and to facilitate expertise between stakeholders. ...
Local and global spatio-temporal entropy indices based on distance- ratios and co-occurrences distributions Article dans une revue avec comité de lectureLEIBOVICI, Didier G.; CLARAMUNT, Christophe; LE GUYADER, Damien; BROSSET, David (Taylor & Francis, 2014)When it comes to characterize the distribution of ‘things’ observed spatially and identified by their geometries and attributes, the Shannon entropy has been widely used in different domains such as ecology, regional ...
Article dans une revue avec comité de lectureMASLOV, Nicolas; BROSSET, David; CLARAMUNT, Christophe; CHARPENTIER, Jean-Frederic (MDPI, 2014)The objective of this paper is to devise a strategy for developing a flexible tool to efficiently install a marine energy farm in a suitable area. The current methodology is applied to marine tidal current, although it can ...