November 2012

ORNL Report

Machine Learning for Malicious Transaction Detection in Critical Infrastructure Communications

By:
Beaver, Justin M
Publication Date:
November 6, 2012

Abstract

Recent world events have brought to light the vulnerabilities associated with national power systems. The advent of smart grid technologies and the movement of many systems from proprietary networks to open systems with open standards has improved automation but also increased the risk of cyber-physical attack. Systems that were once made secure by physical isolation are struggling with the realities of the cyber security challenges of traditional information technology networks. However, critical infrastructure systems also stand to benefit from the significant investment in research and development of advanced technologies for detection of attacks levied against computer networks. This report describes an investigation into the viability of applying an existing high-performance machine-learning-based network intrusion detection system to critical infrastructure systems in order to detect malicious control system communications. The machine learning system was designed and developed at Oak Ridge National Laboratory and has been experimentally verified to accurately identify malicious traffic as part of a computer network defense enclave. The system uses prior examples of network-based cyber attacks and normal traffic in an enterprise network to generalize attack patterns by analyzing dozens of metrics simultaneously. In this work, the approach is extended in order to train a model that reliably classifies industrial control system transactions and identifies those that are probable attacks. This investigation leveraged a dataset of remote terminal unit transactions, provided by the Mississippi State University’s Critical Infrastructure Protection Center, which included both normal operations and instances of attack scenarios. The focus was on data injection attacks, where an intruder manipulates the measurement data reported by the controller in order to deceive a human operator monitoring system status, or manipulate automated control loops attempting to regulate the physical state of the device being controlled. The data from both the injection attack examples and the normal operation examples were used to train various machine learning models, and cross-validated to evaluate their ability to identify malicious control system transactions. Of the evaluated models, the adaptive boosting approach was found to be the most accurate with error rates on the order of 5% for attack transactions and 10% for normal transactions. Adaptive boosting is an ensemble method that combines several weak classifiers to create a strong overall classifier without over fitting the training data. While these results are promising, further investigation is required, particularly in the selection of discriminating features for this problem, in order to produce an operationally viable detector.