Analyzing Changes in the Self-similarity of Industrial Control System Network Traffic Caused by Bursty Sources

dc.contributor.authorMartin, Bryan
dc.contributor.authorMccurdy, William
dc.contributor.authorBollmann, Chad
dc.date.accessioned2024-12-26T21:10:52Z
dc.date.available2024-12-26T21:10:52Z
dc.date.issued2025-01-07
dc.description.abstractIt is well documented that bursty sources on a network, such as those derived from human-type communications (HTC), result in the traffic exhibiting self-similar behavior. However, limited research has been conducted into the self-similarity of networks consisting of machine-type communications (MTC), such as the Internet of Things (IoT) or industrial control system (ICS) devices. Furthermore, it has not been shown how MTC traffic patterns change when aggregated with bursty, human traffic. This research uses publicly available ICS datasets to investigate the effects of adding bursty traffic to MTC networks as characterized by the self-similarity of the traffic. As MTC networks exhibit a lower degree of self-similarity when compared to networks containing HTC, we demonstrate that even a small percentage of bursty traffic introduced to the MTC network will cause an increase in self-similarity. We present these findings as a foundation for utilizing changes in self-similarity, as measured by the Hurst parameter, for anomaly detection of human activity in traditionally non-bursty networks.
dc.format.extent10
dc.identifier.doi10.24251/HICSS.2025.835
dc.identifier.isbn978-0-9981331-8-8
dc.identifier.other79c7e5f6-7730-4f60-a0d4-14a26a76fca3
dc.identifier.urihttps://hdl.handle.net/10125/109686
dc.relation.ispartofProceedings of the 58th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectApplied Security Through Cyber Innovation and Implementation
dc.subjectindustrial control system, machine-type communications, network anomaly detection, self-similarity
dc.titleAnalyzing Changes in the Self-similarity of Industrial Control System Network Traffic Caused by Bursty Sources
dc.typeConference Paper
dc.type.dcmiText
prism.startingpage6986

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0681.pdf
Size:
677.87 KB
Format:
Adobe Portable Document Format