A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures

Critical Infrastructures (CIs) use Supervisory Control and Data Acquisition (SCADA) systems for monitoring and remote control. Sensor networks are being integrated into all areas of the infrastructures of smart cities. The sensor network data stream contains information that can be utilized to model...

Full description

Bibliographic Details
Main Authors: Yakub Kayode Saheed, Oluwadamilare Harazeem Abdulganiyu, Taha Ait Tchakoucht
Format: Article
Language:English
Published: Elsevier 2023-05-01
Series:Journal of King Saud University: Computer and Information Sciences
Subjects:
Online Access:http://www.sciencedirect.com/science/article/pii/S1319157823000782
_version_ 1797817488079060992
author Yakub Kayode Saheed
Oluwadamilare Harazeem Abdulganiyu
Taha Ait Tchakoucht
author_facet Yakub Kayode Saheed
Oluwadamilare Harazeem Abdulganiyu
Taha Ait Tchakoucht
author_sort Yakub Kayode Saheed
collection DOAJ
description Critical Infrastructures (CIs) use Supervisory Control and Data Acquisition (SCADA) systems for monitoring and remote control. Sensor networks are being integrated into all areas of the infrastructures of smart cities. The sensor network data stream contains information that can be utilized to model and control the activity of these infrastructures. However, SCADA systems are constantly exposed to a variety of diverse intrusions, making detection with traditional intrusion detection systems (IDS) extremely difficult. Due to their unique specifications, conventional security solutions, like antivirus and firewall software, are unsuitable for properly securing SCADA systems. In addition, anomaly detection in industrial sensor networks (ISNs) should occur in real time. Therefore, effectively identifying cyberattacks in major SCADA systems is unquestionably essential for enhancing their resilience, ensuring safe operations, and avoiding expensive maintenance. We developed a novel hybrid ensemble model approach to address these issues. This paper's primary objective is to detect hostile intrusions that have already circumvented firewalls and typical IDS. In this paper, we propose a hybrid Ensemble Learning Model (ELM) for intrusion detection in SCADA systems with ISNs utilizing a tangible data gathered from a gas pipeline system given by Mississippi State University (MSU), the water system, and the high-dimensional University of New South Wales-NB 2015 (UNSW-NB15) data that reflects a typical attack in the Internet of Things (IoT) environment. The unity normalization method was adopted for data preprocessing, and the Principal Component Analysis (PCA) was utilized for feature extraction of the high-dimensional datasets. Grey Wolf Optimizer (GWO) was used for optimizing the bagging, stacking, Adaboost, and an ensemble of classifiers Naive Bayes and Support Vector Machine with a majority voting technique. Then, we utilized the proposed approach founded on the bijective soft-set approach for efficient ELM selection. The experiment was conducted in two phases: Initially, without PCA + GWO for feature extraction and selection on the ELM, and subsequently, with PCA + GWO for feature extraction and selection on the ELM. PCA + GWO on the ensemble of classifiers NB + SVM provided an accuracy of 99%, precision of 100%, recall of 100%, and detection rate of 99.90%, outpacing the ensemble of classifiers without PCA feature extraction and GWO optimization approaches.
first_indexed 2024-03-13T08:54:10Z
format Article
id doaj.art-43baaf75c9664955b28b61b995116f2d
institution Directory Open Access Journal
issn 1319-1578
language English
last_indexed 2024-03-13T08:54:10Z
publishDate 2023-05-01
publisher Elsevier
record_format Article
series Journal of King Saud University: Computer and Information Sciences
spelling doaj.art-43baaf75c9664955b28b61b995116f2d2023-05-29T04:03:44ZengElsevierJournal of King Saud University: Computer and Information Sciences1319-15782023-05-01355101532A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructuresYakub Kayode Saheed0Oluwadamilare Harazeem Abdulganiyu1Taha Ait Tchakoucht2School of IT and Computing, American University of Nigeria, Nigeria; Corresponding author.School of Digital Engineering and Artificial Intelligence, EuroMed University of Fes, MoroccoSchool of Digital Engineering and Artificial Intelligence, EuroMed University of Fes, MoroccoCritical Infrastructures (CIs) use Supervisory Control and Data Acquisition (SCADA) systems for monitoring and remote control. Sensor networks are being integrated into all areas of the infrastructures of smart cities. The sensor network data stream contains information that can be utilized to model and control the activity of these infrastructures. However, SCADA systems are constantly exposed to a variety of diverse intrusions, making detection with traditional intrusion detection systems (IDS) extremely difficult. Due to their unique specifications, conventional security solutions, like antivirus and firewall software, are unsuitable for properly securing SCADA systems. In addition, anomaly detection in industrial sensor networks (ISNs) should occur in real time. Therefore, effectively identifying cyberattacks in major SCADA systems is unquestionably essential for enhancing their resilience, ensuring safe operations, and avoiding expensive maintenance. We developed a novel hybrid ensemble model approach to address these issues. This paper's primary objective is to detect hostile intrusions that have already circumvented firewalls and typical IDS. In this paper, we propose a hybrid Ensemble Learning Model (ELM) for intrusion detection in SCADA systems with ISNs utilizing a tangible data gathered from a gas pipeline system given by Mississippi State University (MSU), the water system, and the high-dimensional University of New South Wales-NB 2015 (UNSW-NB15) data that reflects a typical attack in the Internet of Things (IoT) environment. The unity normalization method was adopted for data preprocessing, and the Principal Component Analysis (PCA) was utilized for feature extraction of the high-dimensional datasets. Grey Wolf Optimizer (GWO) was used for optimizing the bagging, stacking, Adaboost, and an ensemble of classifiers Naive Bayes and Support Vector Machine with a majority voting technique. Then, we utilized the proposed approach founded on the bijective soft-set approach for efficient ELM selection. The experiment was conducted in two phases: Initially, without PCA + GWO for feature extraction and selection on the ELM, and subsequently, with PCA + GWO for feature extraction and selection on the ELM. PCA + GWO on the ensemble of classifiers NB + SVM provided an accuracy of 99%, precision of 100%, recall of 100%, and detection rate of 99.90%, outpacing the ensemble of classifiers without PCA feature extraction and GWO optimization approaches.http://www.sciencedirect.com/science/article/pii/S1319157823000782Intrusion detection systemSCADAIndustrial control networksCritical infrastructureSmart GridSmart City
spellingShingle Yakub Kayode Saheed
Oluwadamilare Harazeem Abdulganiyu
Taha Ait Tchakoucht
A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
Journal of King Saud University: Computer and Information Sciences
Intrusion detection system
SCADA
Industrial control networks
Critical infrastructure
Smart Grid
Smart City
title A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
title_full A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
title_fullStr A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
title_full_unstemmed A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
title_short A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures
title_sort novel hybrid ensemble learning for anomaly detection in industrial sensor networks and scada systems for smart city infrastructures
topic Intrusion detection system
SCADA
Industrial control networks
Critical infrastructure
Smart Grid
Smart City
url http://www.sciencedirect.com/science/article/pii/S1319157823000782
work_keys_str_mv AT yakubkayodesaheed anovelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures
AT oluwadamilareharazeemabdulganiyu anovelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures
AT tahaaittchakoucht anovelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures
AT yakubkayodesaheed novelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures
AT oluwadamilareharazeemabdulganiyu novelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures
AT tahaaittchakoucht novelhybridensemblelearningforanomalydetectioninindustrialsensornetworksandscadasystemsforsmartcityinfrastructures