A Method for Anomaly Detection of Encrypted Traffic in Power IoT Base on Security Baseline Learning
Zhou Peng, Qiang Xu, Hu Lizhi, Menglin Li · 2024
As numerous power IoT terminals require secure access to the power grid, how to detect the encrypted malicious traffic in power IoT becomes a challenge. Following an in-depth investigation of potential security risks in power, IoT encrypted traffic, an unsupervised learning method is designed to establish a security baseline for normal business encrypted traffic and to identify the anomaly encrypted traffic. Firstly, a partially seeded K-means clustering algorithm is proposed for security baseline learning to construct a set of clusters for normal encrypted traffic. Secondly, an algorithm tailored for comparing similarity within a cluster is introduced to minimize the costs associated with anomaly detection. At last, experiments are performed to evaluate the effectiveness and performance of this method on real-power IoT encrypted traffic and open VPN encrypted traffic. The results demonstrate that this method has the ability not only to detect the anomaly in business encrypted traffic caused by terminal device error or manual wrong operation but also to identify unknown cyberattacks targeting internal applications to penetrate the secure access gateway by encrypted traffic