Improving SCADA Cyber security: A Deep Learning Technique for Anomaly Detection

G.C Madhu, S. Sivakumar, S. Sree Hari Raju, M. Sweetline Sonia, Kotha Chakradhar, Sandeep Gupta · 2025

As the number of hacks on some countries’ vital assets grows, new methods are needed that use how AI and defence work together. This study looks at how these areas come together, using machine learning methods to improve the SCADA (supervisory control and data acquisition) systems of important assets. Sensitive data is collected and processed by these networks, which are key for managing and keeping an eye on important assets. The method combines the forecast power of machine learning with the need for safety. This creates a strong model that can find and stop cyber risks before they happen, which is something that many current models lack. One complete method for doing this is to simulate hacking on a Kali Linux computer that is connected to a fake SCADA network. Using Wireshark, data on network activity is gathered for use in machine learning. By finding the answer in a supervised machine learning model with two tasks: it uses the strength specifically for an MLP neural network and XGBoostbased optimization. This combination makes it possible for the model to figure out small trends and strange things happening in network data. With an average precision of $99.61 \%$ as well as a discovery success rate of $99.49 \%$, the technique does a good job of telling the difference between normal as well as suspicious states and stopping harmful packets from getting in. The model applies firewall rules through PowerShell, which is an example of AI’s adaptable governing. This gives it two roles: one as an Intrusion Detection Model and one as an Intrusion Prevention Model. The model works well it has a $99.19 \%$ accuracy rate and a $98.95 \%$ recognition rate as shown by rigorous testing on data that had never been seen before. When compared to other models, the suggested answer does much better in terms of precision, and accuracy, along alongside detection and recall rates. Networks that rely on computers and data have a solid defense under this security paradigm. For the purpose of securing SCADA networks and critical infrastructure, it demonstrates the significance of AI and ML.

Read the paper · More papers on PaperTik