Anomaly Detection in Industrial Networks using Distributed Observation of Statistical Behavior
Paolo Ferrari, Paolo Bellagente, Alessandra Flammini, Massimiliano Gaffurini, Stefano Rinaldi, Emiliano Sisinni, Dennis Brandão · 2024
Industrial network infrastructures are often exposed to possible issues related to accidental anomalous traffic or intentional cyber-attacks. Alteration and disruption of the real-time characteristics of the network may lead to loss of production or, worse, to danger situations. The prompt identification and mitigation of anomalies on the network traffic by means of early detection and classification is of main importance. However, cost and topology constrains of industrial network do not easy the deployment of devices for inspection of live traffic. Moreover, complex anomaly detection systems require personnel skills that are not common in industrial facilities. This paper presents an expert system relying only the collection of statistical data obtained in from industrial devices with standard protocol SNMP (Simple Network Management Protocol), realizing a de-facto distributed measurement system. The solution does not require addition hardware or excessive computation power. The proposed approach includes the definition of suitable performance indicators and the related clustering/classification methods. The use case of a real assembly machine is taken into account for the feasibility demonstration. With sampling time of ten minutes and after an initial training phase, the proposed system is able to highlight small modification of traffic behavior and guide the operator to identify the sources of the problem. Finally, current limitations and future works are discussed.