Skip to main content
QUICK REVIEW

[论文解读] Deep transfer learning for intrusion detection in industrial control networks: A comprehensive review

Hamza Kheddar, Yassine Himeur|arXiv (Cornell University)|Apr 19, 2023
Network Security and Intrusion Detection参考文献 185被引用 14
一句话总结

本论文综述深度迁移学习如何提升工业控制网络的入侵检测,提供分类法、数据集、方法和未来方向。

ABSTRACT

Globally, the external internet is increasingly being connected to industrial control systems. As a result, there is an immediate need to protect these networks from a variety of threats. The key infrastructure of industrial activity can be protected from harm using an intrusion detection system (IDS), a preventive mechanism that seeks to recognize new kinds of dangerous threats and hostile activities. This review examines the most recent artificial-intelligence techniques that are used to create IDSs in many kinds of industrial control networks, with a particular emphasis on IDS-based deep transfer learning (DTL). DTL can be seen as a type of information-fusion approach that merges and/or adapts knowledge from multiple domains to enhance the performance of a target task, particularly when labeled data in the target domain is scarce. Publications issued after 2015 were considered. These selected publications were divided into three categories: DTL-only and IDS-only works are examined in the introduction and background section, and DTL-based IDS papers are considered in the core section of this review. By reading this review paper, researchers will be able to gain a better grasp of the current state of DTL approaches used in IDSs in many different types of network. Other useful information, such as the datasets used, the type of DTL employed, the pre-trained network, IDS techniques, the evaluation metrics including accuracy/F-score and false-alarm rate, and the improvements gained, are also covered. The algorithms and methods used in several studies are presented, and the principles of DTL-based IDS subcategories are presented to the reader and illustrated deeply and clearly

研究动机与目标

  • 在物联网及更广泛的5G context 下,推动工业控制系统(ICS)安全的入侵检测系统(IDS)的应用。
  • 提供深度迁移学习(DTL)模型及其 IDS 应用的全面分类。
  • 综述用于 IDS 的数据集、预训练模型、IDS 技术、评估指标及报告的改进。
  • 识别挑战并为基于 DTL 的 ICS/ICN 环境中的 IDS 研究勾勒未来方向。

提出的方法

  • 通过主要数据库(IEEE Xplore、ACM DL、ScienceDirect、SpringerLink)使用迁移学习和 IDS 关键词进行文献筛选。
  • 三段式框架:DTL-only 背景、IDS-only 背景,以及 DTL 基础的 IDS 核心研究。
  • 为 DTL 模型(归纳、传导、对抗)和 IDS 技术(基于签名、基于异常、基于规范、基于滥用、混合)的分类体系构建。
  • 讨论在 ICS/ICN 情境下用于 IDS 评估的数据集及相关评估指标(如准确率、F-score、误警率)。
  • 综合设计决策、优缺点及未解决挑战,以绘制未来方向。
Figure 1 : Mind map showing the main sections and highlighting the key concepts covered in this review.
Figure 1 : Mind map showing the main sections and highlighting the key concepts covered in this review.

实验结果

研究问题

  • RQ1当前工业控制网络与 ICS 安全中的基于 DTL 的 IDS 的现状如何?
  • RQ2DTL 模型如何在 ICS/ICN 环境中用于 IDS 的应用进行分类?
  • RQ3用于基准 DTL 基于 IDS 的数据集和评估指标有哪些?
  • RQ4在 ICS/ICN 中基于 IDS 的 DTL 研究的主要挑战和未来方向是什么?
  • RQ5DTL 方法在适应新威胁和数据稀缺方面相较于传统 IDS 方法有何优势/劣势?

主要发现

  • 综述整合了现有在各类 ICS/ICN 场景中用于 IDS 的 DTL 应用,阐明它们的设计决策和局限性。
  • 提供用于 IDS 的 DTL 模型分类体系,包括归纳、传导和对抗 DTL。
  • 总结广泛使用的 IDS 技术(基于签名、基于异常、基于规范、基于滥用及混合型)及其与 DTL 的整合方式。
  • 整理用于 ICS 场景下 IDS 评估的数据集(如 SWaT、WADI、ADFA-LD,以及论文中引用的其他数据集)。
  • 本文强调尚待解决的挑战并提出推进 ICS/ICN 网络中基于 IDS 的 DTL 的未来研究方向。
Figure 2 : Bibliometric analysis in terms of statistics on: (a) Number of articles involved in this review in each year, (b) Top fifteen most cited papers with their authors and publication year, (c) Top fifteen most relevant papers’ sources, (d) Top fifteen most active authors, (e) Percentage of pa
Figure 2 : Bibliometric analysis in terms of statistics on: (a) Number of articles involved in this review in each year, (b) Top fifteen most cited papers with their authors and publication year, (c) Top fifteen most relevant papers’ sources, (d) Top fifteen most active authors, (e) Percentage of pa

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。