收录:
摘要:
In the field of industrial control systems (ICSs), a broad application background and the different characteristics of a system determine the diversity and particularity of an intrusion detection system. We propose an abnormal detection method based on a behavior model. The method extracts behavior data sequences from industrial control network traffic, builds a normal behavior model of the controller and the controlled process of an ICS, and compares tested behavior data and prediction behavior data to detect any exceptions. According to experimental results, our method can effectively detect abnormal behavior data and control program manipulation attacks. (C) 2019 Elsevier Ltd. All rights reserved.
关键词:
通讯作者信息:
电子邮件地址: