A method referred to as PbNN is proposed to detect cyber-physical attacks through the identification of resulting anomalies in the process dynamics of the underlying ICS. Unlike existing anomaly detectors… Click to show full abstract
A method referred to as PbNN is proposed to detect cyber-physical attacks through the identification of resulting anomalies in the process dynamics of the underlying ICS. Unlike existing anomaly detectors based on an abstract knowledge acquired from operational data, PbNN utilizes the design knowledge of ICS to learn the complex relationships among the correlated components. Such relationships are accurately modeled using operational data through the application of the deep convolution neural network. The proposed detector was implemented and evaluated in an operational secure water treatment plant by launching several real-time stealthy and coordinated attacks. The results indicate that PbNN outperforms the existing state-of-the-art machine learning anomaly detectors when compared using detection accuracy and the rate of false alarms.
               
Click one of the above tabs to view related content.