Graph-Based Anomaly Detection in Industrial Control Systems

Sofya Balaba, Yuri Chernyshov, Andrey Skorohodov, Denis Komarov · 2025

In Industrial Control Systems (ICS), the number of targeted cyberattacks (APT) on critical infrastructure, such as Stuxnet and Industroyer, is increasing. Particularly concerning are complex attacks exploiting vulnerabilities in network protocols (e.g., Modbus, OPC UA) and affecting physical infrastructure, highlighting the need for enhanced protection methods and network intrusion detection systems (NIDS). Current research actively employs classical machine learning (ML) techniques for developing NIDS.In our research, we developed a model evaluated on the open CIC Modbus 2023 dataset and compared it to traditional ML models. The results demonstrated that our model effectively detects a wide range of modern attacks, achieving an F1-score of 0.98. Unlike sequence-based methods, our graph-based approach identifies meaningful patterns in flow relationships that traditional methods often miss.We also developed an automated digital forensics module using a Saliency map based on reconstruction error. This map helps identify the most critical elements (edges and nodes) of the graph for decision-making. The automation of forensics accelerates attack investigations, providing operators with efficient tools for incident analysis and interpretation.These results highlight the effectiveness of graph-based machine learning methods for enhancing ICS security and open new avenues for future research.

Read the paper · More papers on PaperTik