A Deep Learning Approach for Understanding Device Behavior in Smart Building Networks
Maroun Touma, Isabelle Crawford-Eng · 2021
Securing critical infrastructure networks requires a detailed understanding of the devices that are connected to the network and how networking resources are being used. In this paper, we present a novel technique that focuses on describing device behavior by analyzing and classifying the observed network traffic patterns, and demonstrate how this technique augments existing Machine Learning (ML) models for the detection and classification of networked devices. In our research, we primarily focus on techniques for the classifying of Supervisory Control and Data Acquisition (SCADA) networks that often run as an overlay on top of the Internet Protocol (IP). The prevalence of IP networks within manufacturing and industrial sites adds a layer of vulnerability and makes it a primary target for attacks by malicious actors. By design, the IP network often carries critical SCADA traffic as well as other Information Technology (IT) traffic with different security constraints. We will share our initial results obtained using an optimized implementation of a Bayesian Neural Network (BNN) used to classify SCADA devices and alternatively, to characterize networked devices behaviors for unknown protocols. We will present two scenarios and discuss the performance of BNN: In one scenario, we use an application protocol parser for Building Automation Control Network over IP (BACnet/IP) and show how the specific protocol features can be used for classifying devices. In a second scenario we assume that we cannot parse the application protocol messages and use features derived from the underlying User Datagram Protocol (UDP) for our classification. We will discuss the benefits and shortcomings of each method and discuss how the method for analyzing UDP can be used to quickly formulate an initial point of view on the network being studied by classifying devices based on their pattern of behavior independent of what application protocol they use. This approach presents a significant advantage when the messages between the devices cannot be decoded.