An Approach to Attack Detection on Graph-Based Modeling of States in Critical Infrastructures
Vasily Alekseevich Desnitsky, Diana Levshun, Igor Vitalievich Kotenko · 2023
The paper proposes an approach to detecting attacks in critical infrastructures by using graph-based modeling and machine learning. The approach includes the following two main stages. In design-time, an intelligent analysis of logs is performed – initial data on the functioning of an industrial system is analyzed by using clustering of possible system states, as well as the a graph of its states and transitions is constructed. At the runtime stage, the graph is traversed to sequentially detect states that determine attacks of certain classes inherent in the system. During the operation, abnormal transitions between normal system states are also detected, and they can be regarded as extra features of attacks as well. Experiments performed on data from datasets describing the functioning of two industrial systems confirmed the correctness of the developed attack detection algorithm, and also showed the high stability of the algorithm to possible losses of some of the events coming to the attack detection mechanism.