SSAD: State Space-Based Anomaly Detection in Industrial Control Systems
Zhiyi Wei, Fei Lv, Lu Xiao, Xin Chen, Shichao Lv, Limin Sun · 2024
Industrial Control Systems (ICS) are increasingly facing the threat of False Data Injection (FDI) attacks. Process-based anomaly detection is an emerging intrusion detection approach for I CS that effectively identifies anomalies induced by FDI attacks. Anomaly detection models are constructed to describe the normal patterns of industrial processes and subsequently perform real-time evaluation of process data. However, this approach suffers from low detection accuracy due to the complex nonlinear spatiotemporal correlations in industrial pro-cess data, which are difficult to explicitly describe using anomaly detection models. Additionally, noise and interference within the process data prevent these models from recognizing genuine anomalous events. This paper proposes a State Space-based Anomaly Detection (SSAD) approach. Specifically, to explicitly describe the spatiotemporal correlations in process data, we introduce a deep learning-based state estimation model that employs Convolutional Neural Networks (CNNs) for temporal modeling and utilizes a Selective State Space (SSS) for spatial modeling. To detect anomalies in the presence of noise and interference, we design a robust anomaly identification model that combines maximum deviation and threshold strategies to analyze the outputs of the state estimation model. Extensive experiments on two benchmark I CS security datasets demonstrate the effectiveness of SSAD.