Qr code
中文
姚羽

Professor
Supervisor of Doctorate Candidates
Supervisor of Master's Candidates


Gender:Male
Alma Mater:东北大学
Education Level:With Certificate of Graduation for Doctorate Study
College: 计算机科学与工程学院
Administrative Position:复杂网络系统安全保障技术教育部工程研究中心主任
Discipline:Computer Applications Technology
Computer Software and Theory
Computer Architecture
Contact Information:
E-Mail:

Academic Honor

2013   Excellent talents of the Ministry of education in the new century

Click:Times

Open Time: ..

The Last Update Time: ..

Current position: Home >> Scientific Research >> Paper Publications
Unknown Attack Traffic Classification in SCADA Network Using Heuristic Clustering Technique

Hits:

Journal:IEEE Transactions on Network and Service Management.

Impact Factor:5.332

Summary:Attack Traffic Classification (ATC) technique is an
essential tool for Industrial Control System (ICS) network security,
which can be widely used in active defense, situational awareness,
attack source traceback and so on. At present, the state-of-the-art
ATC methods are usually based on traffic statistical features and
machine learning techniques, including supervised classification
methods and unsupervised clustering methods. However, it is
difficult for these methods to overcome the problems of lack of
attack samples and high real-time requirement in ATC in
Supervisory Control and Data Acquisition (SCADA) networks. In
order to address the above problems, we propose a self-growing
ATC model based on a new density-based heuristic clustering
method, which can continuously and automatically detect and
distinguish different kinds of unknown attack traffic generated by
various attack tools against SCADA networks in real time. An
effective representation method of SCADA network traffic is
proposed to further improve the performance of ATC. In addition,
a large number of experiments are conducted on a compound
dataset consisting of the SCADA network dataset, the attack tool
dataset and the ICS honeypot dataset, to evaluate the proposed
method. The experimental results show that the proposed method
outperforms existing state-of-the-art ATC methods in the crucial
situation of only normal SCADA network traffic.

Key Words:Attack traffic classification, heuristic clustering, SCADA network, traffic representation.

Note:https://ieeexplore.ieee.org/document/10023526

Discipline:Engineering

Document Type:JCR 一区

First-Level Discipline:Computer Science and Technology

Translation or Not:No