Performance Comparison For Multi Class Classification Intrusion Detection In SCADA Systems Using Apache Spark - Archive ouverte HAL Accéder directement au contenu
Poster De Conférence Année : 2018

Performance Comparison For Multi Class Classification Intrusion Detection In SCADA Systems Using Apache Spark

Résumé

SCADA (Supervisory Control And Data Acquisition).are industrial control systems, that allow the monitoring and control of large indutrial systems. Those systems are more and more subject to cyber attacks due to their interconnexion with corporate networks and the Internet. We are comparing in this work the performances of a SCADA-specific Intrusion Detection system built with apache Spark, using Decision Tree, Naïve Bayes, Random Forest and Multilayer Perceptron approaches. Our Comparison criterias are the recall, specificity, precision, training time and detection time. The dataset used is obtained from a Modbus control system that monitors a water storage tank system. The dataset contains normal as well as different caregories of attack tuples. Our Intrusion Detection framework is a Hadoop cluster using Hive and the Spark ML library. The experimentation results show that the Decision Tree classifier has a very good detection rate (recall of 100 %) for all tuples categories except the Denial-of-Service (recall of 0). Decision Tree has also a fairly good training and detection time (7.84 s and 0.23 s respectively). The Random Forest also has a good detection rate for all classes apart DoS. But it has only 60% detection rate for the DoS class and longer training and detection. Naïve Bayes and Multilayer Perceptron have an overall poor classification results, but Naïve Bayes is very fast at training (2.96 s) and detecting (0.14 s) . Multilayer Perceptron on the other hand, while taking time to train (155.51 s) is very fast in the prediction phase (0.16 s).
Fichier non déposé

Dates et versions

hal-01876894 , version 1 (19-09-2018)

Identifiants

  • HAL Id : hal-01876894 , version 1

Citer

Raogo Kabore, Yvon Kermarrec, Philippe Lenca. Performance Comparison For Multi Class Classification Intrusion Detection In SCADA Systems Using Apache Spark. 8th Global Techmining Conference, Sep 2018, Leiden, Netherlands. ⟨hal-01876894⟩
101 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More