A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control Systems
Cheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph Chana
Abstract
Industrial Control Systems (ICS) consisting of integrated hardware and software components designed to monitor and control a variety of industrial processes, are typically deployed in critical infrastructures such as water treatment plants, power grids and gas pipelines. Unlike conventional IT systems, the consequences of deviations from normal operation in ICS have the potential to cause significant physical damage to equipment, the environment and even human life. The active monitoring of invariant rules that define the physical conditions that must be maintained for the normal operation of ICS provides a means to improve the security and dependability of such systems by which early detection of anomalous system states may be achieved, allowing for timely mitigating actions – such as fault checking, system shutdown – to be taken. Generally, invariant rules are predefined by system engineers during the design phase of a given ICS build. However, this manually intensive process is costly, error-prone and, in typically complex systems, sub-optimal. In this paper we propose a novel framework that is designed to systematically generate invariant rules from information contained within ICS operational data logs, using a combination of several machine learning and data mining techniques. The effectiveness of our approach is demonstrated by experiments on two real world ICS testbeds: a water distribution system and a water treatment plant. We show that sets of invariant rules, far larger than those defined manually, can be successfully derived by our framework and that they may be used to deliver significant improvements in anomaly detection compared with the invariant rules defined by system engineers as well as the commonly used residual errorbased anomaly detection model for ICS. Keywords—industrial control systems, anomaly detection, invariant rules, machine learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 92e2698f-6d01-4101-aeb9-622fc26ed49eCited by top-tier papers11
- Active fuzzing for testing and securing cyber-physical systemsYuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun et al.ISSTA 2020 · 25 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Code integrity attestation for PLCs using black box neural network predictionsYuqi Chen, Christopher M. Poskitt, Jun SunFSE 2021 · 16 citations
- PGPatch: Policy-Guided Logic Bug Patching for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi et al.S&P 2022 · 15 citations
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan et al.USENIX Security 2024 · 9 citations
Builds on3
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer et al.CCS 2016 · 351 citations
- Who's in Control of Your Control System? Device Fingerprinting for Cyber-Physical SystemsDavid Formby, Preethi Srinivasan, Andrew M. Leonard, Jonathan D. Rogers et al.NDSS 2016 · 171 citations
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 135 citations
Related papers
- CoToRu: Automatic Generation of Network Intrusion Detection Rules from CodeHeng Chuan Tan, Carmen Cheh, Binbin ChenINFOCOM 2022 · 12 citations
- Attributions for ML-based ICS Anomaly Detection: From Theory to PracticeClement Fung, Eric Zeng, Lujo BauerNDSS 2024
- MINES: Explainable Anomaly Detection through Web API Invariant InferenceWenjie Zhang, Yun Lin, Chun Fung Amos Kwok, Xiwen Teoh et al.ICSE 2026
- RuleTwin: Physics-Constrained Rule Induction for Anomaly Detection in Industrial Multivariate Time SerieJingzheng Mao, Runjie Pu, Zhen Song, Yanbin Sun et al.KDD 2026
- Robust and Transferable Log-based Anomaly DetectionPeng Jia, Shaofeng Cai, Beng Chin Ooi, Pinghui Wang et al.SIGMOD 2023 · 26 citations
