详细信息

基于深度学习的工控系统网络攻击多分类检测    

Multi-Class Detection of Cyber Attacks in Industrial Control Systems Based on Deep Learning

文献类型:期刊文献

中文题名:基于深度学习的工控系统网络攻击多分类检测

英文题名:Multi-Class Detection of Cyber Attacks in Industrial Control Systems Based on Deep Learning

作者:王庚辰[1];姜庆超[1];颜学峰[1]

机构:[1]华东理工大学信息科学与工程学院,上海200237

年份:2026

卷号:52

期号:2

起止页码:247

中文期刊名:华东理工大学学报(自然科学版)

外文期刊名:Journal of East China University of Science and Technology

收录:;北大核心:【北大核心2023】;

基金:国家自然科学基金(62433004)。

语种:中文

中文关键词:工业控制系统;异常检测;网络攻击;攻击分类;深度学习

外文关键词:industrial control system;anomaly detection;cyber attack;attack classification;deep learning

摘要:近年来,针对工业控制系统(Industrial Control System,ICS)的网络物理攻击事件频发,工控系统的异常检测成为安全防护的关键技术。传统的异常检测方法通常将问题简化为二元分类,难以满足实际需求。为了更精确地定位攻击源头并实现系统状态的快速恢复,需要对ICS异常状态进行更细致的划分。本文提出了一种基于深度学习的新型工控异常检测及攻击分类模型,结合卷积神经网络(CNN)、双向长短期记忆网络(BiLSTM)以及注意力(Attention)机制的优势,通过CNN提取数据包的空间特征,利用BiLSTM捕捉数据包间的时间依赖性,并引入注意力机制进一步聚焦关键的时间步信息,从而实现对工控系统网络攻击的高精度检测。实验结果表明,该模型在检测准确率等评价指标上优于现有的工业入侵检测系统,并且在处理不平衡数据集时表现出色,为工控系统的安全防护提供了新的解决方案。
As a core component of national critical infrastructure,the security of Industrial Control Systems(ICS)is of paramount importance.With the widespread application of information technology,the efficiency of ICS operations has significantly improved,but new security risks have also emerged.In recent years,the frequent occurrence of cyber-physical attacks targeting ICS has made anomaly detection a key technology in safeguarding such systems.Traditional anomaly detection methods often reduce the problem to binary classification,which is insufficient for practical needs.To more precisely locate attack sources and facilitate rapid system recovery,a finer-grained classification of ICS anomalies is required.This paper proposes a novel deep learning-based model for ICS anomaly detection and attack classification.The model leverages the strengths of Convolutional Neural Networks(CNN),Bidirectional Long Short-Term Memory(BiLSTM)networks,and the Attention mechanism.CNN is used to extract spatial features of data packets,BiLSTM captures temporal dependencies between packets,and the Attention mechanism focuses on critical time-step information to achieve high-precision detection of ICS network attacks.Experimental results demonstrate that the proposed model outperforms existing industrial intrusion detection systems in terms of detection accuracy and performs well on imbalanced datasets,offering a new solution for ICS security protection.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心