IET Cyber-Physical Systems (Sep 2021)

Flow‐based intrusion detection algorithm for supervisory control and data acquisition systems: A real‐time approach

  • Marcio Andrey Teixeira,
  • Maede Zolanvari,
  • Khaled M. Khan,
  • Raj Jain,
  • Nader Meskin

DOI
https://doi.org/10.1049/cps2.12016
Journal volume & issue
Vol. 6, no. 3
pp. 178 – 191

Abstract

Read online

Abstract Intrusion detection in supervisory control and data acquisition (SCADA) systems is integral because of the critical roles of these systems in industries. However, available approaches in the literature lack representative flow‐based datasets and reliable real‐time adaption and evaluation. A publicly available labelled dataset to support flow‐based intrusion detection research specific to SCADA systems is presented. Cyberattacks were carried out against our SCADA system test bed to generate this flow‐based dataset. Moreover, a flow‐based intrusion detection system (IDS) is developed for SCADA systems using a deep learning algorithm. We used the dataset to develop this IDS model for real‐time operations of SCADA systems to detect attacks momentarily after they happen. The results show empirical proof of the model’s adequacy when deployed online to detect cyberattacks in real time.