[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123036-en":3,"doc-seo-123036-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123036,8796095461564,"Liam","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Enhanced Anomaly Detection in Industrial Control Systems - Machine Learning Aided Thesis","Industrial environments increasingly rely on digitised, interconnected automation, making robust cybersecurity essential. This thesis develops a nuanced understanding of normal versus anomalous behaviour by integrating machine learning with traditional intrusion detection approaches. The work combines network intrusion detection and host intrusion detection with rich process data from the iTrust labs’ SWaT experiment, using Zeek to structure network traffic logs. Focused feature enrichment for Common Industrial Protocol analysis aims to improve detection of malicious activities and support more resilient IDS for industrial networks.","University of Bergen Department of Informatics  \nEnhanced Anomaly Detection in Industrial Control Systems aided by  \nMachine Learning  \nAuthor: Vegard Berge  \nSupervisors: Chunlei Li, H˚akon Olsen, Haakon Knudsen  \nMay, 2024  \nAbstract  \nAs the world’s critical infrastructure becomes increasingly digitised, the need for robust and adequate security measures is more important than ever. This thesis aims to develop a more nuanced understanding of normal and anomalous behaviours from both a network and an operational perspective. To this end, this thesis investigates the potential of enhancing anomaly detection in Industrial Control Systems (ICS) through the integration of Machine Learning (ML) with traditional Network Intrusion Detection Systems (NIDS) and Host Intrusion Detection Systems (HIDS) . Collaborating with DNV, a leading classification company, and utilising a rich dataset from the iTrust labs’SWaT experiment, this project explores the use of both process data and traditional network traffic to improve the detection of malicious activities within industrial networks. The thesis employs the Zeek network analysis tool to transform raw network traffic into structured logs and focuses on leveraging the Common Industrial Protocol (CIP) for detailed analysis. By examining various types of logs and process data, this study aspires to improve our understanding of the potential benefits by enriching the features injected into anomaly-detecting models. Providing a new perspective on traditional detection techniques can help develop more resilient and adaptive Intrusion Detection Systems (IDS)s tailored to industrial systems.  \nAcknowledgements  \nI would like to express my sincere gratitude to my supervisor, Professor Chunlei Li, for his guidance and support throughout this research project. His insight has been important in shaping the direction and execution of this thesis. Special thanks are due to H˚akon Olsen, whose expertise on industrial security and effort in providing crucial feedback has greatly enriched my understanding and added depth to my work. I am also grateful to Haakon Knudsen for facilitating the collaboration between the University of Bergen and DNV. This partnership has added credibility and relevance to the research. I owe a debt of gratitude to my study friends, who have supported and motivated me. A special mention goes to Sondre for the many ”not-so-productive-but-productive” coffee breaks that have offered much-needed breaks and camaraderie during this intensive study period. Lastly, I must extend my heartfelt thanks to my family, whose unwavering support and confidence in my abilities have empowered me to complete a thesis I am proud to present. Your belief in me has been a constant source of strength and encouragement. Thank you!  \nVegard Berge Tuesday 28th May, 2024  \nContents  \n1 Introduction 2  \n2 Background 4  \n2.1 IDS ....................................... 4  \n2.1.1 NIDS .................................. 7  \n2.1.2 HIDS .................................. 9  \n2.1.3 Intrusion Kill Chain ......................... 10  \n2.2 Industrial Control Systems .......................... 13  \n2.2.1 Overview of ICS ........................... 13  \n2.2.2 Key Components in ICS ....................... 15  \n2.2.3 Security Imperatives for ICS ..................... 17  \n2.2.4 Purdue model ............................. 19  \n2.2.5 MITRE ATT&CK ICS Framework ................. 21  \n2.2.6 Attack Vectors in ICS ........................ 22  \n2.2.7 Common Industrial Protocol ..................... 23  \n3 Machine Learning-aided Intrusion Detection 25  \n3.1 Machine Learning Models for IDS ...................... 26  \n3.1.1 Neural Networks ........................... 27  \n3.1.2 Decision Tree ............................. 31  \n3.1.3 K-Nearest Neighbours ........................ 32  \n3.1.4 Support Vector Machine ....................... 32  \n3.1.5 Random Forest ............................ 33  \n3.2 Performance Metrics ................","cbCaitxxGB1fEWVH","https://ap.wps.com/l/cbCaitxxGB1fEWVH","pdf",4516803,1,108,"English","en",105,"# 1 Introduction\n# 2 Background\n## 2.1 IDS\n## 2.2 Industrial Control Systems\n# 3 Machine Learning-aided Intrusion Detection\n## 3.1 Machine Learning Models for IDS\n## 3.2 Performance Metrics\n# 4 Overview of the SWaT Dataset\n## 4.1 SWaT Testbed\n## 4.2 The A6 Experiment\n# 5 Investigating the Dataset\n## 5.1 Zeek Network Security Monitor\n## 5.4 Summary\n# 6 Experiment\n## 6.1 Data Processing\n## 6.4 Results\n# 7 Conclusion and Future Direction\n## 7.2 Limitations","[{\"question\":\"What is the main goal of the thesis on anomaly detection?\",\"answer\":\"To enhance anomaly detection in Industrial Control Systems by learning from both network and operational/process perspectives and improving the detection of malicious activities.\"},{\"question\":\"Which datasets and tooling are used for the experiments?\",\"answer\":\"The thesis uses the iTrust labs’ SWaT experiment dataset and employs Zeek to transform raw network traffic into structured logs for analysis.\"},{\"question\":\"How are machine learning techniques integrated into intrusion detection?\",\"answer\":\"Machine learning models are applied to intrusion detection using enriched features derived from process data and traditional network traffic logs, targeting improved performance for malicious activity detection.\"},{\"question\":\"What types of intrusion detection systems are combined in this work?\",\"answer\":\"Traditional Network Intrusion Detection Systems (NIDS) and Host Intrusion Detection Systems (HIDS) are integrated with machine learning and ICS process data.\"}]","Enhanced Anomaly Detection in Industrial Control Systems - Machine Learning Aided Thesis | PDF",1785814315,272,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"enhanced-anomaly-detection-in-industrial-control-systems-machine-learning-aided-thesis","",{"@graph":36,"@context":89},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/enhanced-anomaly-detection-in-industrial-control-systems-machine-learning-aided-thesis/123036/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"What is the main goal of the thesis on anomaly detection?","Question",{"text":75,"@type":76},"To enhance anomaly detection in Industrial Control Systems by learning from both network and operational/process perspectives and improving the detection of malicious activities.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which datasets and tooling are used for the experiments?",{"text":80,"@type":76},"The thesis uses the iTrust labs’ SWaT experiment dataset and employs Zeek to transform raw network traffic into structured logs for analysis.",{"name":82,"@type":73,"acceptedAnswer":83},"How are machine learning techniques integrated into intrusion detection?",{"text":84,"@type":76},"Machine learning models are applied to intrusion detection using enriched features derived from process data and traditional network traffic logs, targeting improved performance for malicious activity detection.",{"name":86,"@type":73,"acceptedAnswer":87},"What types of intrusion detection systems are combined in this work?",{"text":88,"@type":76},"Traditional Network Intrusion Detection Systems (NIDS) and Host Intrusion Detection Systems (HIDS) are integrated with machine learning and ICS process data.","https://schema.org",{"og:url":52,"og:type":91,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":93,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":96},[97,101,105,109,114,119,124,127,132,135,139],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},6,"Technology",50,"technology",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":125,"slug":126},30,"research-report",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},9,"Religion & Spirituality",20,"religion-spirituality",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":130,"slug":134},"World Cup","world-cup",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":136,"slug":138},10,"Lifestyle","lifestyle",{"id":140,"doc_module":4,"doc_module_name":46,"category_name":141,"show_sort_weight":110,"slug":142},19,"General","general"]