Traffic Characteristic Map-based Intrusion Detection Model for Industrial Internet
نویسندگان
چکیده
After the Stuxnet security event in Iran, the security issues on industrial Internet are very serious. Besides, there are many flaws existing in the modern traffic modelling approaches to the industrial field network. Aiming at these problems, the traffic characteristic map-based intrusion detection model for industrial Internet was proposed. Firstly, information entropy method was adopted to select vital traffic characteristics attributes set which is used to form traffic characteristic vectors. Secondly, multiple correlation analysis approach was applied to transform traffic characteristics vector into triangle area mapping matrix and traffic characteristic map can be established. Finally, using discrete cosine transform (DCT) and singular value decomposition (SVD) methods, perceptual hash digest database of normal and abnormal traffic characteristics maps was obtained. Thereafter, the corresponding intrusion detection rule set can be generated, which is essential for the modelling of network traffic periodic characteristics in industrial field network. In particular, the robustness and discrimination of the traffic characteristics map perceptual hash algorithm (TCM-PH) were proved. Experimental results show that the proposed approach has a good performance of intrusion detection in the industrial field network.
منابع مشابه
Mutual Information-based Intrusion Detection Model for Industrial Internet
High dimension, redundancy attributes and high computing cost issues usually exist in the industrial Internet intrusion detection field. For solving these problems, the mutual information-based intrusion detection model for industrial Internet was proposed. Firstly, by using features selection method based on mutual information, the attributes set was reduced and traffic characteristics vector ...
متن کاملAnomaly-based Web Attack Detection: The Application of Deep Neural Network Seq2Seq With Attention Mechanism
Today, the use of the Internet and Internet sites has been an integrated part of the people’s lives, and most activities and important data are in the Internet websites. Thus, attempts to intrude into these websites have grown exponentially. Intrusion detection systems (IDS) of web attacks are an approach to protect users. But, these systems are suffering from such drawbacks as low accuracy in ...
متن کاملBotnet Detection Through Fine Flow Classification
The prevalence of botnets, which is defined as a group of infected machines, have become the predominant factor among all the internet malicious attacks such as DDoS, Spam, and Click fraud. The number of botnets is steadily increasing, and the characteristic C&C channels have evolved from IRC to HTTP, FTP, and DNS, etc., and from the centralized structure to P2P and Fast Flux Network Services. ...
متن کاملA Survey of Anomaly Detection Approaches in Internet of Things
Internet of Things is an ever-growing network of heterogeneous and constraint nodes which are connected to each other and the Internet. Security plays an important role in such networks. Experience has proved that encryption and authentication are not enough for the security of networks and an Intrusion Detection System is required to detect and to prevent attacks from malicious nodes. In this ...
متن کاملتولید خودکار الگوهای نفوذ جدید با استفاده از طبقهبندهای تک کلاسی و روشهای یادگیری استقرایی
In this paper, we propose an approach for automatic generation of novel intrusion signatures. This approach can be used in the signature-based Network Intrusion Detection Systems (NIDSs) and for the automation of the process of intrusion detection in these systems. In the proposed approach, first, by using several one-class classifiers, the profile of the normal network traffic is established. ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- I. J. Network Security
دوره 20 شماره
صفحات -
تاریخ انتشار 2018