Metric Learning with Neural Network for Modbus/TCP Anomaly Detection

Haicheng Qu, Jianzhong Zhou, Jitao Qin
{"title":"Metric Learning with Neural Network for Modbus/TCP Anomaly Detection","authors":"Haicheng Qu, Jianzhong Zhou, Jitao Qin","doi":"10.1145/3411016.3411160","DOIUrl":null,"url":null,"abstract":"In cyber security field, anomaly detection is triggered when detected network data traffic behaves obviously differently from normal data traffic. Traditional approaches typically create or define the normal pattern for the data and compare the normal pattern with the detected object. When a significantly different object appears, it is regarded as abnormal data. This paper proposes a novel neural network structure for anomaly detection, called a metric learning network, which aims to directly learn the differences between abnormal and normal data rather than set up a normal pattern. The network comprises an auto-encoder, which is used to encode the abnormal and normal data, and a metric learning component, which is designed to understand the difference between abnormal and normal data via a comparison approach. A deviation score is produced by the metric learning component to recognize the detected object. Research based on the Modbus/Transmission Control Protocol (TCP) network demonstrates that this approach can not only learn the difference between normal data and outliers, but is suitable for anomaly detection tasks. Our method has greater overall detection rates than a baseline model.","PeriodicalId":251897,"journal":{"name":"Proceedings of the 2nd International Conference on Industrial Control Network And System Engineering Research","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd International Conference on Industrial Control Network And System Engineering Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3411016.3411160","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

In cyber security field, anomaly detection is triggered when detected network data traffic behaves obviously differently from normal data traffic. Traditional approaches typically create or define the normal pattern for the data and compare the normal pattern with the detected object. When a significantly different object appears, it is regarded as abnormal data. This paper proposes a novel neural network structure for anomaly detection, called a metric learning network, which aims to directly learn the differences between abnormal and normal data rather than set up a normal pattern. The network comprises an auto-encoder, which is used to encode the abnormal and normal data, and a metric learning component, which is designed to understand the difference between abnormal and normal data via a comparison approach. A deviation score is produced by the metric learning component to recognize the detected object. Research based on the Modbus/Transmission Control Protocol (TCP) network demonstrates that this approach can not only learn the difference between normal data and outliers, but is suitable for anomaly detection tasks. Our method has greater overall detection rates than a baseline model.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于神经网络度量学习的Modbus/TCP异常检测
在网络安全领域,当检测到的网络数据流量行为与正常数据流量明显不同时,就会触发异常检测。传统方法通常为数据创建或定义正常模式,并将正常模式与检测到的对象进行比较。当出现明显不同的对象时,将其视为异常数据。本文提出了一种新的用于异常检测的神经网络结构,称为度量学习网络,其目的是直接学习异常和正常数据之间的差异,而不是建立正常模式。该网络包括一个自动编码器,用于对异常和正常数据进行编码,以及一个度量学习组件,旨在通过比较方法理解异常和正常数据之间的差异。度量学习组件产生偏差分数以识别检测到的对象。基于TCP (Modbus/Transmission Control Protocol)网络的研究表明,该方法不仅可以学习到正常数据和离群数据之间的区别,而且适用于异常检测任务。我们的方法比基线模型具有更高的总体检出率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Relativity-Driven Optimization for Test Schedule of Spaceflight Products at Launch Site Design and Implementation of Grain Traceability Code Coding Scheme A color image edge detection method based on entropy operator A two-dimensional code security authentication method based on digital watermarking A Performance Analysis of Container Cluster Networking Alternatives
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1