Systems and Computer Engineering Department, School of Engineering, University of the Andes, Bogotá 111711, Colombia.
Colombian Defense Ministry's CSIRT, Bogotá 111321, Colombia.
Sensors (Basel). 2023 Feb 22;23(5):2415. doi: 10.3390/s23052415.
Industrial control systems (ICSs), supervisory control and data acquisition (SCADA) systems, and distributed control systems (DCSs) are fundamental components of critical infrastructure (CI). CI supports the operation of transportation and health systems, electric and thermal plants, and water treatment facilities, among others. These infrastructures are not insulated anymore, and their connection to fourth industrial revolution technologies has expanded the attack surface. Thus, their protection has become a priority for national security. Cyber-attacks have become more sophisticated and criminals are able to surpass conventional security systems; therefore, attack detection has become a challenging area. Defensive technologies such as intrusion detection systems (IDSs) are a fundamental part of security systems to protect CI. IDSs have incorporated machine learning (ML) techniques that can deal with broader kinds of threats. Nevertheless, the detection of zero-day attacks and having technological resources to implement purposed solutions in the real world are concerns for CI operators. This survey aims to provide a compilation of the state of the art of IDSs that have used ML algorithms to protect CI. It also analyzes the security dataset used to train ML models. Finally, it presents some of the most relevant pieces of research on these topics that have been developed in the last five years.
工业控制系统 (ICSs)、监控和数据采集 (SCADA) 系统以及分布式控制系统 (DCSs) 是关键基础设施 (CI) 的基本组成部分。CI 支持交通和医疗系统、电力和热力厂以及水处理设施等的运行。这些基础设施不再孤立,它们与第四次工业革命技术的连接扩大了攻击面。因此,保护它们已成为国家安全的优先事项。网络攻击变得更加复杂,犯罪分子能够超越传统的安全系统;因此,攻击检测已成为一个具有挑战性的领域。入侵检测系统 (IDSs) 等防御技术是保护 CI 的安全系统的基本组成部分。IDSs 已经采用了机器学习 (ML) 技术,可以应对更广泛的威胁。然而,检测零日攻击以及拥有在现实世界中实施有针对性解决方案的技术资源是 CI 运营商关注的问题。本调查旨在提供一个使用 ML 算法来保护 CI 的 IDS 最新技术的汇编。它还分析了用于训练 ML 模型的安全数据集。最后,它介绍了过去五年中在这些主题上开发的一些最相关的研究。