[Paper Review] Revisiting Anomaly Detection in ICS: Aimed at Segregation of Attacks and Faults
This paper proposes a framework to distinguish between cyberattacks and system faults in Industrial Control Systems (ICS) using multi-layered data analysis, digital twins, attack signatures, and behavioral modeling. By leveraging differences in detection latency, fault time constants, mode shifts, and correlation asymmetry, the approach enables accurate segregation of anomalies, reducing false alarms and improving response precision in critical infrastructure.
In an Industrial Control System (ICS), its complex network of sensors, actuators and controllers have raised security concerns for critical infrastructures and industrial production units. This opinion paper strives to initiate discussion on the design algorithms which can segregate attacks from faults. Most of the proposed anomaly detection mechanisms are not able to differentiate between an attack and an anomaly due to a fault. We argue on the need of solving this important problem form our experiences in CPS security research. First, we motivate using analysis of studies and interviews though economical and psychological aspects. Then main challenges are highlighted. Further, we propose multiple directions of approach with suitable reasoning and examples from ICS systems.
Motivation & Objective
- Address the critical gap in ICS anomaly detection where attacks and faults are not differentiated, leading to inappropriate responses.
- Highlight the economic and psychological consequences of misclassifying faults as attacks or vice versa.
- Motivate the need for a robust differentiator to enable targeted, efficient, and safe incident response in industrial control systems.
- Propose multiple technical directions to segregate attacks from faults based on system behavior, timing, and data consistency.
- Stimulate research collaboration to develop practical, deployable solutions for real-world ICS environments.
Proposed method
- Integrate data from both network-layer traffic and process-layer physical variables to detect anomalies with contextual awareness.
- Utilize digital twins or virtual sensors as reference models to detect manipulation, since virtual systems cannot fail physically.
- Apply signature-based detection to identify known attack patterns, though acknowledging limitations in detecting zero-day attacks.
- Analyze mode transitions across devices: attacks often cause coordinated mode shifts, while faults are typically random and isolated.
- Model fault behavior using simulated or historical fault data to create distinguishable profiles from attack patterns.
- Exploit asymmetries in causation vs. correlation—e.g., a failed sensor affects downstream devices, but a failed actuator does not affect upstream sensors—enabling detection of manipulation.
Experimental results
Research questions
- RQ1How can anomaly detection systems in ICS reliably differentiate between cyberattacks and system faults?
- RQ2What behavioral, temporal, and structural differences exist between attacks and faults that can be exploited for segregation?
- RQ3How do detection latency and time-to-damage vary between attack and fault scenarios, and can these be used as discriminative features?
- RQ4To what extent can digital twins or virtual sensors serve as a reference to detect malicious manipulation in real-time?
- RQ5Can fault time constants and mode transition patterns be used to distinguish between random failures and coordinated cyberattacks?
Key findings
- Most existing anomaly detection techniques fail to distinguish between attacks and faults, leading to incorrect system responses such as unnecessary shutdowns.
- Interviews with 19 ICS experts and operators confirm that current systems lack robust differentiation, and misclassification leads to economic losses and psychological stress.
- Faults typically exhibit abrupt, random changes with short time constants, while attacks often involve longer persistence and coordinated behavior across devices.
- Detection latency differences suggest that attacks may be detected later than fault-like injections, especially in persistent attack scenarios.
- Correlation asymmetry—where a sensor failure affects downstream devices but not vice versa—can be used to detect manipulation in sensor data.
- Redundant sensors can improve fault and attack isolation, provided not all are compromised simultaneously, offering a practical detection layer.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.