طراحی یک سیستم تشخیص نفوذ ترکیبی LSTM-DT در شبکه‌های SCADA

نوع مقاله : علمی-پژوهشی

نویسندگان

1 گروه مهندسی کنترل، دانشکده مهندسی برق و کامپیوتر دانشگاه کاشان

2 استادیار دانشکده مهندسی برق دانشگاه کاشان

چکیده

این مقاله یک سیستم تشخیص نفوذ ترکیبی برای سیستم‌های کنترل صنعتی ارائه می‌دهد که از داده‌های دنیای واقعی برای شناسایی حملات سایبری شناخته شده با دقت بسیار بالا استفاده می‌کند. این تحقیق با طراحی یک بستر آزمایشی آزمایشگاهی واقع‌گرایانه شامل یک PLC زیمنس S7-1200، یک HMI و نرم‌افزار WinCC آغاز می‌شود. سه نوع حمله سایبری DDoS، Start/Stop و Port Scan با استفاده از Metasploit شبیه‌سازی می‌شوند و ترافیک شبکه مربوطه از طریق Wireshark با فعال بودن Port Mirroring ثبت می‌شود. در طول پیش‌پردازش، داده‌ها فیلتر و برچسب‌گذاری می‌شوند و ویژگی‌های رفتاری - مانند زمان بین ورود بسته‌ها، فرکانس فرمان کنترل و تنوع پورت مقصد - استخراج می‌شوند. یک مدل ترکیبی LSTM-DT در سه پیکربندی توسعه داده شده و آموزش داده می‌شود. پیکربندی موازی (Config 3)، که خروجی‌های هر دو مؤلفه LSTM و Decision Tree را با هم ترکیب می‌کند، عملکرد برتر را نشان می‌دهد. ارزیابی با استفاده از اعتبارسنجی متقابل 10-fold بر روی داده‌های آزمایشی برچسب‌گذاری شده نشان می‌دهد که مدل پیشنهادی به دقت 99.45٪، دقت 99.23٪ و فراخوانی 99.49٪ دست می‌یابد. با تمرکز بر الگوهای رفتاری مبتنی بر جریان به جای بازرسی بار مفید، این سیستم سربار محاسباتی کمی را تضمین می‌کند و آن را برای محیط‌های صنعتی با محدودیت منابع مناسب می‌سازد.

کلیدواژه‌ها

موضوعات


عنوان مقاله [English]

Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks

نویسندگان [English]

  • Majid Naghibian 1
  • Alireza Faraji 2
1 Electrical and computer Faulty, University of Kashan
2 Assistant professor of electrical engineering faculty of university of kashanu
چکیده [English]

This paper presents a hybrid intrusion detection system for Industrial Control Systems that leverages real-world data to detect known cyberattacks with very high accuracy. The research begins by designing a realistic laboratory testbed comprising a Siemens S7-1200 PLC, an HMI, and WinCC software. Three types of cyberattacks DDoS, Start/Stop, and Port Scan are simulated using Metasploit, and the corresponding network traffic is captured via Wireshark with Port Mirroring enabled. During preprocessing, the data are filtered, labeled, and behavioral features—such as packet inter-arrival time, control command frequency, and destination port diversity are extracted. A hybrid LSTM-DT model is developed and trained in three configurations; the parallel configuration (Config 3), which fuses the outputs of both LSTM and Decision Tree components, demonstrates superior performance. Evaluation using 10-fold cross-validation on labeled testbed data shows that the proposed model achieves 99.45% accuracy, 99.23% precision, and 99.49% recall. By focusing on flow-based behavioral patterns rather than payload inspection, the system ensures low computational overhead, making it well-suited for resource-constrained industrial environments.

کلیدواژه‌ها [English]

  • Industrial Control Systems (ICS)
  • Cyberattacks
  • Long Short-Term Memory
  • Decision Tree
  • Intrusion Detection System
[1] Amanoul, S.V., et al., Intrusion Detection Systems Based on Machine Learning Algorithms, in 2021 IEEE International Conference on Automatic Control & Intelligent Systems (I2CACIS). 2021. p. 282-287.
[2] Mohamad Kaouk, J.-M.F., Marie-Laure Potet, Roland Groz, A Review of Intrusion Detection Systems for Industrial Control Systems. 2019.
[3] Mubarak, S., et al., Anomaly Detection in ICS Datasets with Machine Learning Algorithms. Computer Systems Science and Engineering, 2021. 37(1): p. 33-46.
[4] Rocio Lopez Perez, F.A., Ridha Soua,Thomas Engel, Machine Learning for Reliable Network Attack Detection in SCADA Systems. 2018.
[5] Marcio Andrey Teixeira, T.S., , Maede Zolanvari, Raj Jain, Nader Meskin, Mohammed Samaka, SCADA System Testbed for Cybersecurity Research  Using Machine Learning Approach. Future Internet, 2018.
[6] Manish Kumar, D.M.H., Dr. T. V. Suresh Kumar, Intrusion Detection System Using Decision Tree Algorithm. 2012.
[7] Teixeira, M., et al., SCADA System Testbed for Cybersecurity Research Using Machine Learning Approach. Future Internet, 2018. 10(8).
[8] Wang, W., et al., A stacked deep learning approach to cyber-attacks detection in industrial systems: application to power system and gas pipeline systems. Cluster Comput, 2022. 25(1): p. 561-578.
[9] Wei Wang, Y.X., Lu Ren, Xiaodong Zhu, Rui Chang, Qing Yin, Detection of Data Injection Attack in Industrial Control System Using Long Short Term Memory Recurrent Neural Network. 2018.
[10] Jihyun Kim, J.K., Huong Le Thi Thu, and Howon Kim, Long Short Term Memory Recurrent Neural Network Classifier for Intrusion Detection. 2016.
[11] Sagarika Ghosh1, S.S., A Survey of Security in SCADA Networks: Current Issues and Future Challenges. IEEE Aerospace and Electronic Systems Magazine, 2019: p. 23.
[12] Terai, A., et al., Cyber-Attack Detection for Industrial Control System Monitoring with Support Vector Machine Based on Communication Profile, in 2017 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). 2017. p. 132-138.
[13] نجار, م. and س. معطر, تشخیص نفوذ شبکه با استفاده از رویکرد ترکیبی مدل مخفی مارکوف و یادگیری ماشین مفرط. مجله مهندسی برق دانشگاه تبریز, 2019. 48(4): p. 1807-1817.
[14] قصابی, م. and م. دی‌پیر, تشخیص و کاهش اثر حملات DDOS در شبکه‌های نرم‌افزار محور با استفاده از تکنیک فاصله جفری. مجله مهندسی برق دانشگاه تبریز, 2018. 48(3): p. 1287-1300.
[15] Ahmad, Z., et al., Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 2020. 32(1).
[16] Alzahrani, A. and T.H.H. Aldhyani, Design of Efficient Based Artificial Intelligence Approaches for Sustainable of Cyber Security in Smart Industrial Control System. Sustainability, 2023. 15(10).
[17] Arifin, M.A.S., et al., Oversampling and undersampling for intrusion detection system in the supervisory control and data acquisition IEC 60870‐5‐104. IET Cyber-Physical Systems: Theory & Applications, 2024. 9(3): p. 282-292.
[18] Ferrag, M.A., M. Babaghayou, and M.A. Yazici, Cyber security for fog-based smart grid SCADA systems: Solutions and challenges. Journal of Information Security and Applications, 2020. 52.
[19] Xin, Y., et al., Machine Learning and Deep Learning Methods for Cybersecurity. IEEE Access, 2018. 6: p. 35365-35381.