An Enhanced EWMA for Alert Reduction and Situation Awareness in Industrial Control Networks

  • Baoxiang Jiang
  • , Yang Liu
  • , Huixiang Liu
  • , Zehua Ren
  • , Yun Wang
  • , Yuanyi Bao
  • , Wenqing Wang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Intrusion detection systems (IDSs) are widely deployed in the industrial control systems to protect network security. IDSs typically generate a huge number of alerts, which are time-consuming for system operators to process. Most of the alerts are individually insignificant false alarms. However, it is not the best solution to discard these alerts, as they can still provide useful information about network situation. Based on the study of characteristics of alerts in the industrial control systems, we adopt an enhanced method of exponentially weighted moving average (EWMA) control charts to help operators in processing alerts. We classify all detection signatures as regular and irregular according to their frequencies, set multiple control limits to detect anomalies, and monitor regular signatures for network security situational awareness. Extensive experiments have been performed using real-world alert data. Simulation results demonstrate that the proposed enhanced EWMA method can greatly reduce the volume of alerts to be processed while reserving significant abnormal information.

Original languageEnglish
Title of host publication2022 IEEE 18th International Conference on Automation Science and Engineering, CASE 2022
PublisherIEEE Computer Society
Pages888-894
Number of pages7
ISBN (Electronic)9781665490429
DOIs
StatePublished - 2022
Event18th IEEE International Conference on Automation Science and Engineering, CASE 2022 - Mexico City, Mexico
Duration: 20 Aug 202224 Aug 2022

Publication series

NameIEEE International Conference on Automation Science and Engineering
Volume2022-August
ISSN (Print)2161-8070
ISSN (Electronic)2161-8089

Conference

Conference18th IEEE International Conference on Automation Science and Engineering, CASE 2022
Country/TerritoryMexico
CityMexico City
Period20/08/2224/08/22

Fingerprint

Dive into the research topics of 'An Enhanced EWMA for Alert Reduction and Situation Awareness in Industrial Control Networks'. Together they form a unique fingerprint.

Cite this