In order to detect abnormal communication behaviors efficiently in today's industrial control system, a new intrusion detection algorithm based on One-Class Support Vector Machine (OCSVM) is proposed in this paper. In this algorithm, a normal communication behavior model is established by using OCSVM, and the Particle Swarm Optimization algorithm is designed to optimize OCSVM model parameters. Furthermore, we adopt the normal Modbus function code sequence to train OCSVM model, and then use this model to detect abnormal Modbus TCP traffic. Our simulation results show that the proposed algorithm not only is efficient and reliable but also meets the real-time requirements of anomaly detection in industrial control system.
CITATION STYLE
Shang, W., Zeng, P., Wan, M., Li, L., & An, P. (2016). Intrusion detection algorithm based on OCSVM in industrial control system. Security and Communication Networks, 9(10), 1040–1049. https://doi.org/10.1002/sec.1398
Mendeley helps you to discover research relevant for your work.