This paper presents a hybrid intrusion detection system for Industrial Control Systems that leverages real-world data to detect known cyberattacks with very high accuracy. The research begins by designing a realistic laboratory testbed comprising a Siemens S7-1200 PLC, an HMI, and WinCC software. Three types of cyberattacks DDoS, Start/Stop, and Port Scan are simulated using Metasploit, and the corresponding network traffic is captured via Wireshark with Port Mirroring enabled. During preprocessing, the data are filtered, labeled, and behavioral features—such as packet inter-arrival time, control command frequency, and destination port diversity are extracted. A hybrid LSTM-DT model is developed and trained in three configurations; the parallel configuration (Config 3), which fuses the outputs of both LSTM and Decision Tree components, demonstrates superior performance. Evaluation using 10-fold cross-validation on labeled testbed data shows that the proposed model achieves 99.45% accuracy, 99.23% precision, and 99.49% recall. By focusing on flow-based behavioral patterns rather than payload inspection, the system ensures low computational overhead, making it well-suited for resource-constrained industrial environments.
Naghibian, M. and Faraji, A. (2026). Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks. Tabriz Journal of Electrical Engineering, 56(1), 35-40. doi: 10.22034/tjee.2026.67140.5017
MLA
Naghibian, M. , and Faraji, A. . "Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks", Tabriz Journal of Electrical Engineering, 56, 1, 2026, 35-40. doi: 10.22034/tjee.2026.67140.5017
HARVARD
Naghibian, M., Faraji, A. (2026). 'Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks', Tabriz Journal of Electrical Engineering, 56(1), pp. 35-40. doi: 10.22034/tjee.2026.67140.5017
CHICAGO
M. Naghibian and A. Faraji, "Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks," Tabriz Journal of Electrical Engineering, 56 1 (2026): 35-40, doi: 10.22034/tjee.2026.67140.5017
VANCOUVER
Naghibian, M., Faraji, A. Design of a Hybrid LSTM-DT Intrusion Detection System in SCADA Networks. Tabriz Journal of Electrical Engineering, 2026; 56(1): 35-40. doi: 10.22034/tjee.2026.67140.5017