IMG: Deep Representation Graph Learning for Anomaly Detection in Industrial Control System

Binbin Ge,Jingru Bao,Bo Li,Xudong Mou,Jun Zhao,Xudong Liu
DOI: https://doi.org/10.1007/s11265-024-01923-w
2024-01-01
Journal of Signal Processing Systems
Abstract:Network flow anomaly detection plays a critical role in the Industrial Control System (ICS). As industrial informatization advances, ICS encounters numerous cybersecurity challenges. Recent approaches based on machine learning and deep learning have proven successful; however, the complex relationships among ICS nodes and insufficient feature extraction capabilities hinder anomaly detection performance, presenting significant challenges to the process. In this paper, we propose a novel framework IMG (Inter-Intra MultiGraph Anomaly Detection), an unsupervised detection framework for anomalous network flow detection on multigraph. Specifically, IMG first builds a multigraph within each snapshot from network flows. Then, by employing embedding and Fourier transformation to the numerical, discrete, and temporal features of the same edge, IMG simplifies multigraph into a simple directed graph for each snapshot. Next, IMG leverages attention mechanisms combined with Graph Neural Networks (GNN) to learn node relationships within snapshots (intra-snapshot), and uses Gated Recurrent Units (GRU) combined with GNN for temporal learning between snapshots (inter-snapshot). Finally, a stacked autoencoder is employed to perform dimension reduction for anomaly detection. Experiments conducted on industrial protocol traffic datasets and traditional traffic datasets demonstrate that IMG exhibits superior anomaly detection performance compared to baseline methods.
What problem does this paper attempt to address?