@inproceedings{c56c660ccf7341408fb85c76667048b0,
title = "Cyber Forensic Analysis for Operational Technology Using Graph-Based Deep Learning",
abstract = "The cyber attacks in Ukraine in 2015 and 2016 demonstrated the vulnerability of electrical power grids to cyber threats. They highlighted the significance of Operational Technology (OT) communication-based anomaly detection. Many anomaly detection methods are based on real-time traffic monitoring, i.e., Intrusion Detection Systems (IDS) that may produce false positives and degrade the OT communication performance. Security Operations Center (SOC) needs intelligent tools to conduct forensic analysis on generated IDS alarms and identify the attack locations. Therefore, in this paper, we propose a novel, graph-based forensic analysis method for anomaly detection in power systems using OT communication network traffic throughput. It employs a hybrid deep learning model involving Graph Convolutional Long Short-Term Memory and a Convolutional Neural Network. The proposed method aids SOC with continuous OT security monitoring and post-mortem investigations. Results indicate that the proposed method is able to pinpoint the locations of cyber attacks on power grid OT networks with an AUC score above 75%.",
keywords = "Anomaly Detection, Attack Graph, CNN, Cyber Security, Digital Forensics, GNN, Graph, LSTM, Operational Technology",
author = "Alfan Presekal and Alexandru Stefanov and Rajkumar, {Vetrivel Subramaniam} and Peter Palensky",
note = "Publisher Copyright: {\textcopyright} 2023 IEEE.; 14th IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids, SmartGridComm 2023 ; Conference date: 31-10-2023 Through 03-11-2023",
year = "2023",
doi = "10.1109/SmartGridComm57358.2023.10333922",
language = "English",
series = "2023 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids, SmartGridComm 2023 - Proceedings",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
booktitle = "2023 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids, SmartGridComm 2023 - Proceedings",
address = "United States",
}