Threat Detection Framework Based on Industrial Internet of Things Logs
Shuqin Zhang, Yong Wang, Xinyu Su · IEEE Access · 2024
The Industrial Internet of Things logs capture the status and events of industrial Internet of Things systems and provide a valuable source for identifying potential threats. However, most existing anomaly detection methods consider quantitative or sequential relationships between log events. These methods often neglect the contextual information embedded in these events and fail to analyze the underlying attack techniques. This paper proposes a novel framework for detecting threats in industrial Internet of Things logs to address these limitations. Specifically, the framework introduces a log field extraction module that uses a log ontology and a prompt-based few-shot learning technique to identify and extract key fields from the logs. It then employs an anomaly detection method based on a temporal graph neural network, which considers events’ structural and temporal characteristics for a thorough analysis of logs. Finally, the framework applies Sigma rules to map low-level anomalous events to high-level attack techniques and create a summary graph that links anomalous paths to their corresponding attack techniques to alleviate the burden on security analysts. We evaluated the framework using four datasets from the United States Department of Defense Advanced Research Projects Agency. The results demonstrate an average recall of 94.38% and an average precision of 83.78%.