An Enhanced EWMA for Alert Reduction and Situation Awareness in Industrial Control Networks*

2022 IEEE 18th International Conference on Automation Science and Engineering (CASE)(2022)

引用 1|浏览3
暂无评分
摘要
Intrusion detection systems (IDSs) are widely deployed in the industrial control systems to protect network security. IDSs typically generate a huge number of alerts, which are time-consuming for system operators to process. Most of the alerts are individually insignificant false alarms. However, it is not the best solution to discard these alerts, as they can still provide useful information about network situation. Based on the study of characteristics of alerts in the industrial control systems, we adopt an enhanced method of exponentially weighted moving average (EWMA) control charts to help operators in processing alerts. We classify all detection signatures as regular and irregular according to their frequencies, set multiple control limits to detect anomalies, and monitor regular signatures for network security situational awareness. Extensive experiments have been performed using real-world alert data. Simulation results demonstrate that the proposed enhanced EWMA method can greatly reduce the volume of alerts to be processed while reserving significant abnormal information.
更多
查看译文
关键词
enhanced EWMA method,alert reduction,situation awareness,industrial control networks,intrusion detection systems,IDSs,industrial control systems,system operators,individually insignificant false alarms,network situation,enhanced method,exponentially weighted moving average control charts,processing alerts,detection signatures,set multiple control limits,network security situational awareness,real-world alert data
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要