Analysis of Historical Data Usage in Ensemble of Classification Methods within a Two-Stage Hybrid Model of ICS Subjected to Cyberattacks
Dmitriy A. Bukharev, Alexander N. Sokolov · 2024
The study proposes a two-stage hybrid method for anomaly detection in the information processes of automated control systems under cyberattacks. In the first stage, the initial signal data from industrial equipment is processed using hierarchical clustering, which reduces data dimensionality without losing information about anomalous events. In the second stage, an ensemble of classification methods analyzes the clusters formed in the first stage to determine the final class of each data point. An analysis was conducted on the applicability of adding various numbers of historical data points during the first stage of data processing. Computational experiments revealed that adding three historical points increases the accuracy of correctly identifying anomalous and normal data by 2.12%. However, this also leads to increased computational resource requirements. Additionally, three methods for determining the final class of a data point as anomalous in a classification ensemble were compared: single vote, unanimous vote, and majority vote (more than 50%). Method requiring more than 50% of votes was found to be optimal for accurately distinguishing between normal and anomalous data points.