Anomaly Detection of ICS based on EB-OCSVM

7Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Industrial process anomaly detection mechanisms have been proposed to protect industrial control system to minimize the risk of damage or loss of resources. In this paper, an one-class Support Vector Machine based extended boundary (EB-OSCVM) is used to detect anomalies in industrial multivariate time series data from a simulated Tennessee Eastman Process (TEP) with many cyber attacks. In detail, determine the change points of each process variable and capture the causality relationship between the variables based on the location and time delay of the change points. Then, by monitoring the leaf nodes in the causality graph, we can know whether the system is abnormal, it can effectively reduce the dimension of process data. The EB-OSCVM extend classification boundary of OCSVM in order to reduce the error of noise, if data is outside the boundary of EB-OCSVM, there is an anomaly. Finally, tracing the anomaly source according to causal direction. An experiment is used to verify the effectiveness of the proposed approach, the results demonstrate that the approach presents a high-accuracy solution and traces the source of anomaly correctly.

Cite

CITATION STYLE

APA

Zhang, R. B., Xia, L. H., & Lu, Y. (2019). Anomaly Detection of ICS based on EB-OCSVM. In Journal of Physics: Conference Series (Vol. 1267). Institute of Physics Publishing. https://doi.org/10.1088/1742-6596/1267/1/012054

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free