| Literature DB >> 30071595 |
Daniel Ramotsoela1, Adnan Abu-Mahfouz2,3, Gerhard Hancke4,5.
Abstract
The increased use of Industrial Wireless Sensor Networks (IWSN) in a variety of different applications, including those that involve critical infrastructure, has meant that adequately protecting these systems has become a necessity. These cyber-physical systems improve the monitoring and control features of these systems but also introduce several security challenges. Intrusion detection is a convenient second line of defence in case of the failure of normal network security protocols. Anomaly detection is a branch of intrusion detection that is resource friendly and provides broader detection generality making it ideal for IWSN applications. These schemes can be used to detect abnormal changes in the environment where IWSNs are deployed. This paper presents a literature survey of the work done in the field in recent years focusing primarily on machine learning techniques. Major research gaps regarding the practical feasibility of these schemes are also identified from surveyed work and critical water infrastructure is discussed as a use case.Entities:
Keywords: critical infrastructure; cyber-physical systems; industrial informatics; industrial sensor network; water monitoring
Year: 2018 PMID: 30071595 PMCID: PMC6111931 DOI: 10.3390/s18082491
Source DB: PubMed Journal: Sensors (Basel) ISSN: 1424-8220 Impact factor: 3.576
Figure 1Generic Anomaly detection framework.
Parametric vs. Non-parametric anomaly detection.
| Parametric | Non-Parametric | |
|---|---|---|
| Prior-Knowledge? | Statistical distribution | Labelled training data |
| Environment? | Static | Dynamic |
| Detection speed? | fast | Moderate/slow |
| Detection generality? | No | Yes |
Comparison of anomaly detection training methods.
| Supervised | Semi-Supervised | Unsupervised | |
|---|---|---|---|
| Prior-Knowledge? | Yes | Yes | No |
| Environment? | Static | Dynamic | Dynamic |
| Detection speed? | Fast | Fast/moderate | Moderate/slow |
| Detection generality? | No | Yes | Yes |
Figure 2Anomaly Detection Summary.
Figure 3FACIES Testbed.
Figure 4SWaT Industrial Control Network.
A comparison of the discussed anomaly detection schemes.
| Scheme | Technique | Prior Knowledge | Complexity | Practical Consideration | Accuracy | Data Prediction | Anomaly | Drawback |
|---|---|---|---|---|---|---|---|---|
| Xie et al. [ | Multivariate | Yes | Low | No | High | No | DOS | Dimensionality/PK |
| Magan-Carrion et al. [ | Multivariate | Yes | Low | Yes | High | Yes | Data Loss/Modification | Affected by Routing/PK |
| Magan-Carrion et al. [ | Multivariate | Yes | Low | No | High | Yes | Tampered Data | Traffic Imbalance/PK |
| Xie et al. [ | kNN | No | Moderate | No | High | No | Generic | No Regression |
| Liu et al. [ | kNN | Yes | High | No | High | No | Generic | Dimensionality |
| Zhu et al. [ | kNN | No | High | No | High | No | Misbehaving Nodes | Complexity |
| Martins et al. [ | SVM | No | High | No | High | No | Generic | Complexity |
| Salem et al. [ | SVM | Yes | High | No | High | Yes | Data Integrity | Complexity/PK |
| Shilton et al. [ | SVM | Yes | High | No | High | No | Generic | Complexity/PK |
| Cannady [ | ANN | No | High | No | N/A | No | DOS | Complexity |
| Bosman et al. [ | ANN | No | Moderate | Yes | High | No | Generic | Detection Bias |
| Yusuf et al. [ | ANN | Yes | High | Yes | High | Yes | Data Integrity | Complexity/PK |
| Radhika et al. [ | GA | Yes | High | No | Average | No | Misbehaving Nodes | Complexity/PK |
| Bankovic et al. [ | GA | No | High | Yes | High | No | Misbehaving Nodes | Complexity |
| Rizwan et al. [ | GA | Yes | High | No | High | No | Generic | Complexity/PK |
| Maleh et al. [ | Hybrid | Yes | Moderate | Yes | High | No | DOS | PK |
| Ma et al. [ | Hybrid | Yes | High | No | High | No | Generic | Complexity/PK |