Research on Industrial Control Network Security Based on Automatic Machine Learning
Ruijun Yang, Lijun He, Hu Xueqi, Bin Zhang · 2021
Aiming at the problem of complex parameter configuration and slow effective model construction in industrial control system attack identification, starting from the study of the whole process of machine learning, an automatic machine learning (AUTOML) attack behavior identification method is proposed, which takes KDD99 industrial control network data as the detection object. The tree structure based pipeline optimization (TPOT) method, which automatically selects machine learning algorithm and parameter optimization through genetic programming to construct the optimal model pipeline, is used to predict the attack behavior of industrial control network. The empirical study shows that, compared with support vector machine, Naive Bayes, KNN and Logistic Regression, Compared with this method, traditional machine learning methods such as Adaboost reduce the human participation and save a lot of manpower, material resources and time. At the same time, the average accuracy of 10 tests reaches 92.62 % and the average F3_score index reaches 92.17%.