ICS Network Anomaly Classification Using SARIMA and LSTM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial control system (ICS) anomaly detection algorithms have high false positive rates, are complex, and lack interpretability, making them ineffective for real-time anomaly classification and source tracing in industrial control system communication networks.
Innovation Solution
A method combining statistical learning using short-cycle SARIMA models and deep learning with LSTM models for real-time anomaly classification, which generates dynamic traffic thresholds and performs integrated computation to classify and trace anomalies in ICS communication networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional machine learning algorithms are used for offline analysis and modeling of anomaly events, then anomaly detection can be performed, but the false positive rate is high and real-time anomaly location accuracy is low
Solution Approach 1:
The patent combines traditional machine learning algorithms (SARIMA) for statistical analysis with deep learning algorithms (LSTM) for sequence modeling to create a hybrid anomaly detection system. The SARIMA model captures linear trends and seasonal patterns in ICS communication traffic, while the LSTM model learns complex non-linear temporal dependencies. This merging of different algorithmic approaches enables both high reliability in anomaly detection and precise real-time anomaly location by leveraging the complementary strengths of each algorithm.
Solution Approach 2:
The patent creates a composite anomaly detection model that integrates multiple algorithmic components: SARIMA for statistical forecasting, LSTM for deep learning-based sequence prediction, and a fusion mechanism that combines their outputs. This composite structure allows the system to achieve both high detection reliability through diverse algorithmic perspectives and high measurement precision through the coordinated analysis of multiple model predictions, effectively resolving the contradiction between these two performance metrics.
2Measurement precision
If existing ICS anomaly event classification models are used, then classification can be performed, but the algorithm complexity is high, interpretability is poor, and classification accuracy is low
Solution Approach 1:
The patent segments the anomaly classification process into distinct stages: traffic data collection and preprocessing, anomaly detection using SARIMA and LSTM models, anomaly classification based on detected patterns, and source tracing. Each segment handles a specific aspect of the classification task with appropriate algorithmic complexity. This segmentation allows the system to achieve high classification accuracy through specialized processing at each stage while managing overall algorithm complexity by breaking down the problem into manageable components with clear interfaces.
Solution Approach 2:
The patent applies different algorithmic approaches with appropriate complexity levels to different aspects of the classification task. Simple statistical methods are used for basic traffic pattern recognition, while more complex deep learning methods are applied only where necessary for capturing temporal dependencies. The system optimizes the local quality of each algorithmic component according to its specific function, thereby achieving high overall classification accuracy without uniformly high complexity across all processing stages.
3Ease of operation
If priori knowledge is heavily relied upon for anomaly classification, then classification can be performed, but the system cannot be deployed without prior knowledge and adaptability is reduced
Solution Approach 1:
The patent performs preliminary training of the SARIMA and LSTM models using historical ICS communication traffic data during an offline phase. This preliminary action pre-lloads the models with learned patterns and characteristics of normal and anomalous traffic. During online deployment, the pre-trained models can automatically detect and classify anomalies without requiring manual prior knowledge input, thereby easing deployment while maintaining adaptability to new attack patterns through the models' inherent learning capabilities.
Solution Approach 2:
The hybrid anomaly detection system enables the ICS communication network to perform self-service anomaly detection and classification. The SARIMA and LSTM models automatically learn traffic patterns and identify anomalies without continuous human intervention or manual rule updates. The system adapts to new attack patterns by continuously analyzing incoming traffic data, reducing dependency on priori knowledge while maintaining high adaptability through its self-learning mechanisms.
Data Source
AI summary
The present disclosure provides a method for anomaly classification for an industrial control system (ICS) communication network based on statistical learning and deep learning. This method designs LSTM deep learning structure parameters and performs modeling analysis based on a large amount of traffic data during normal operation of the ICS communication network; based on real-time communication traffic data thresholds generated by a SARIMA online statistical learning model, designs correlated algorithms to analyze a numerical relationship between background traffic and real-time traffic; and classifies ICS communication network anomalies according to an ICS network anomaly classification algorithm. In the present disclosure, an ICS test network range involving virtual and physical devices and a test platform in Zhejiang Province are used for experimental analysis, a physical simulation platform is built in a laboratory environment for validation, and detailed examples are provided to verify the reliability and accuracy of the algorithm.


