[SoK] Evaluations in Industrial Intrusion Detection Research

IF 1 Q3 SOCIOLOGY Journal of World-Systems Research Pub Date : 2023-02-01 DOI:10.5070/sr33162445
Olav Lamberts, Konrad Wolsing, Eric Wagner, Jan Pennekamp, Jan Bauer, Klaus Wehrle, Martin Henze
{"title":"[SoK] Evaluations in Industrial Intrusion Detection Research","authors":"Olav Lamberts, Konrad Wolsing, Eric Wagner, Jan Pennekamp, Jan Bauer, Klaus Wehrle, Martin Henze","doi":"10.5070/sr33162445","DOIUrl":null,"url":null,"abstract":"Industrial systems are increasingly threatened by cyberattacks with potentially disastrous consequences. To counter such attacks, industrial intrusion detection systems strive to timely uncover even the most sophisticated breaches. Due to its criticality for society, this fast-growing field attracts researchers from diverse backgrounds, resulting in 130 new detection approaches in 2021 alone. This huge momentum facilitates the exploration of diverse promising paths but likewise risks fragmenting the research landscape and burying promising progress. Consequently, it needs sound and comprehensible evaluations to mitigate this risk and catalyze efforts into sustainable scientific progress with real-world applicability. In this paper, we therefore systematically analyze the evaluation methodologies of this field to understand the current state of industrial intrusion detection research. Our analysis of 609 publications shows that the rapid growth of this research field has positive and negative consequences. While we observe an increased use of public datasets, publications still only evaluate 1.3 datasets on average, and frequently used benchmarking metrics are ambiguous. At the same time, the adoption of newly developed benchmarking metrics sees little advancement. Finally, our systematic analysis enables us to provide actionable recommendations for all actors involved and thus bring the entire research field forward.","PeriodicalId":36882,"journal":{"name":"Journal of World-Systems Research","volume":"3 1","pages":"0"},"PeriodicalIF":1.0000,"publicationDate":"2023-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of World-Systems Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5070/sr33162445","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"SOCIOLOGY","Score":null,"Total":0}
引用次数: 0

Abstract

Industrial systems are increasingly threatened by cyberattacks with potentially disastrous consequences. To counter such attacks, industrial intrusion detection systems strive to timely uncover even the most sophisticated breaches. Due to its criticality for society, this fast-growing field attracts researchers from diverse backgrounds, resulting in 130 new detection approaches in 2021 alone. This huge momentum facilitates the exploration of diverse promising paths but likewise risks fragmenting the research landscape and burying promising progress. Consequently, it needs sound and comprehensible evaluations to mitigate this risk and catalyze efforts into sustainable scientific progress with real-world applicability. In this paper, we therefore systematically analyze the evaluation methodologies of this field to understand the current state of industrial intrusion detection research. Our analysis of 609 publications shows that the rapid growth of this research field has positive and negative consequences. While we observe an increased use of public datasets, publications still only evaluate 1.3 datasets on average, and frequently used benchmarking metrics are ambiguous. At the same time, the adoption of newly developed benchmarking metrics sees little advancement. Finally, our systematic analysis enables us to provide actionable recommendations for all actors involved and thus bring the entire research field forward.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
[j]工业入侵检测评价研究
工业系统日益受到网络攻击的威胁,可能带来灾难性后果。为了对抗这种攻击,工业入侵检测系统努力及时发现即使是最复杂的入侵。由于其对社会的重要性,这一快速发展的领域吸引了来自不同背景的研究人员,仅在2021年就产生了130种新的检测方法。这种巨大的势头促进了对各种有希望的途径的探索,但同样也有可能使研究前景支离破碎,掩埋有希望的进展。因此,它需要可靠和可理解的评估来减轻这种风险,并催化努力实现具有现实适用性的可持续科学进步。因此,本文系统地分析了该领域的评估方法,以了解工业入侵检测的研究现状。我们对609份出版物的分析表明,这一研究领域的快速增长既有积极的影响,也有消极的影响。虽然我们观察到公共数据集的使用越来越多,但出版物平均只评估1.3个数据集,而且经常使用的基准指标是模糊的。与此同时,新开发的基准度量标准的采用进展甚微。最后,我们的系统分析使我们能够为所有参与者提供可操作的建议,从而推动整个研究领域向前发展。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Journal of World-Systems Research
Journal of World-Systems Research Social Sciences-Political Science and International Relations
CiteScore
1.80
自引率
0.00%
发文量
24
审稿时长
30 weeks
期刊最新文献
Cancelling Apocalypse by Risking to Envision Analyzing Global Commodity Chains and Social Reproduction Weathering the Crisis Europe in a State of Denial Travesty of “Anti-Imperialism"
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1