Real-time intrusion detection method for industrial network traffic
LIAN Lian
WANG Wencheng
ZONG Xuejun
HE Kan
Abstract:[Objective]Industrial Internet is an important part of the national key infrastructure,and its security is directly related to national security,economic stability,and social order.In recent years,with the widespread application of industrial Internet,network attacks targeting industrial control systems have occurred frequently,causing serious economic losses and social impact.Therefore,it is particularly important to develop efficient real-time intrusion detection systems.Traditional intrusion detection systems often fail to effectively distinguish between normal traffic and abnormal traffic when processing high-dimensional network traffic data,especially in the absence of abnormal traffic samples.[Methods]To solve this problem,this study proposed a real-time anomaly detection method for industrial networks which combined Suricata and density clustering based on a sliding window through analyzing the real network traffic characteristics of an oil and gas pipeline industrial control system.This method utilized the open-source and extensible nature of Suricata and the dynamic detection capability of the density clustering algorithm based on a sliding window to establish a full-process intrusion detection model from traffic collection and analysis to real-time intrusion detection.Through analyzing the network traffic characteristics in the real industrial control system environment,this study finds that industrial network traffic has a certain periodicity.By using the GINI coefficient to select features that can reflect the heterogeneity of industrial network traffic characteristics,the present study realizes dimensionality reduction of industrial network traffic.The reduced-dimensional data were grouped using a sliding window to construct the threshold of normal traffic characteristics in industrial networks.By rewriting Suricata to realize real-time traffic collection and analysis and inputting the real-time analysis results into the constructed density clustering intrusion detection algorithm based on a sliding window,this study quickly screened absolute normal traffic groups and absolute abnormal traffic groups through comparison using the threshold of normal traffic characteristics in industrial networks.Abnormal traffic was separated by the density clustering algorithm for groups encompassing normal and abnormal traffic,through which abnormal traffic detection was completed.[Results]The above intrusion detection method was applied in the attack and defense range of the entire process of oil and gas gathering and transportation in an industrial scenario,and a large number of experiments were carried out.This method can effectively identify abnormal traffic with a detection rate exceeding 96%and a false positive rate below 3%.This proves that the proposed method can meet the needs of high-efficiency,reliable,and real-time detection of abnormal traffic in industrial networks.[Conclusion]The innovation of this study lies in providing a new method for detecting abnormal traffic in industrial networks,which combines Suricata and the density clustering algorithm based on a sliding window to establish a full-process intrusion detection model from traffic collection and analysis to real-time intrusion detection.The method has important practical value for the security protection of industrial Internet and provides a new research idea for real-time intrusion detection of industrial networks.
Keywords:industrial networknetwork securitytraffic analysischaracteristic analysisGINI coefficientmachine learningdensity clustering algorithmintrusion detection
Publication Date:2025-01-24
Online Publishing Date:2025-08-15(First online date of this platform, not the publication date of the document)
Pages:8( 98-105 )
