Securing Critical Infrastructure: A Robust DNP3 Intrusion Detection System Employing Recurrent Neural Networks

Md. Nazmus Sakib, Afzal Hossain, Ahsan Ullah, Mst. Nishita Aktar, Noshin Un Noor, Kh. Mustafizur Rahman, Shamsun Nahar · 2024

This study explores how different types of attacks are related to various protocols used in industrial control systems (ICSs). A study revealed that timestamps indicating when data are created, shared, modified, or deleted play a crucial role in analysing attack patterns. The focus of this empirical study is on the DNP3 protocol, which facilitates remote communication between the Systems for supervisory control and data acquisition (SCADA) along with industrial control System (ICS). Research incorporates a secondary dataset associated with DNP3 attacks are provided by the University of Western Macedonia. The study excluded outlier data from the analysis and used a dataset with labelled information about attack types. To enhance the results, the dataset is split into a training set (67%), a test set (22%) and a validation set (11%). By combining a randomforest classifier with the proposed model(LSTM-CNN), the study achieved an impressive accuracy of 98.3%. Research findings suggest that this model could be useful in scenarios where a cyber-attacker intercepts and discards communications between a DNP3 superintendent and a DNP3 captive device. This study introduces a novel solution by modifying the link protocol data unit DNP3 to ensure data integrity and authenticate the data origin via a recurrent neural network paired with a classification algorithm.

Read the paper · More papers on PaperTik