Enhanced CNN-LSTM Deep Learning for SCADA IDS Featuring Hurst Parameter Self-Similarity

Усовершенствованная глубокая модель CNN-LSTM для IDS SCADA с само-похожестью по параметру Херста
Mohamed Hadi Habaebi, Md. Rafiqul Islam, Asaad Balla, Elfatih A. A. Elsheikh, Fakher Eldin M. Suliman, Sinil Mubarak
2024-01-01

CICIDS2017 datasetCNN-LSTMHurst parameterPCA dimensionality reductionSCADA intrusion detection
Supervisory Control and Data Acquisition (SCADA) systems are crucial for modern industrial processes and securing them against increasing cyber threats is a significant challenge. This study presents an advanced method for bolstering SCADA security by employing a modified hybrid deep learning model. A key innovation in this work is integrating the Self-similarity Hurst parameter into the dataset alongside a CNN-LSTM model, significantly boosting the Intrusion Detection System’s (IDS) capabilities. The Hurst parameter, which quantifies the self-similarity in a dataset, is instrumental in detecting anomalies. Our in-depth analysis of the CICIDS2017 dataset sheds light on contemporary attack patterns and network traffic behaviors. The CNN-LSTM architecture was substantially altered by adding multiple convolutional layers with progressively increasing filters, batch normalization for stable training, and dropout layers for regularization. Principal Component Analysis (PCA) was applied for dimensionality reduction, thereby optimizing the dataset. Test results demonstrate the superior performance of the model incorporating the Hurst parameter, achieving 95.21% accuracy and 82.59% recall, significantly surpassing the standard model. The inclusion of the Hurst parameter marks a substantial advancement in identifying emerging threats, while architectural improvements to the CNN-LSTM model led to more robust and accurate intrusion detection in industrial control settings.
1
Applying PCA for dimensionality reduction optimized the dataset for the IDS pipeline.
2
Incorporating the Hurst parameter enhances detection of emerging threats by capturing dataset self-similarity and anomaly-related patterns.
3
Integrating the Self-similarity Hurst parameter into the dataset significantly improves SCADA IDS performance.
4
Modified CNN-LSTM architecture with multiple convolutional layers, increasing filters, batch normalization, and dropout yields more robust and accurate intrusion detection.
5
The model including the Hurst parameter achieved 95.21% accuracy and 82.59% recall on the CICIDS2017 dataset, significantly surpassing the standard model.

SCADA Intrusion Detection System based on a hybrid CNN-LSTM model augmented with the Hurst self-similarity parameter (evaluated on the CICIDS2017 dataset)

Impact of integrating the Hurst self-similarity parameter and architectural enhancements to the CNN-LSTM (multiple convolutional layers, batch normalization, dropout) plus PCA dimensionality reduction on intrusion-detection performance (accuracy, recall) for SCADA network traffic

Publication Details
Publication Date
2024-01-01
Journal
Publisher
ISSN
Cited by
24
Access Type
Author Information
Authors
Mohamed Hadi Habaebi
Md. Rafiqul Islam
Asaad Balla
Elfatih A. A. Elsheikh
Fakher Eldin M. Suliman
Sinil Mubarak
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%