Water distribution infrastructures are increasingly incorporating IoT in the form of sensing and computing power to improve control over the system and achieve greater adaptability to the water demand. This evolution, from physical towards cyber-physical systems, comes with an attack perimeter extended from physical infrastructure to the cyberspace. Being able to detect this novel kind of attacks is gaining traction in the scientific community. Machine learning detection algorithms, which are showing encouraging results in cybersecurity applications, are leveraging the increasing amount of datasets published in the water distribution community for better attack detection. These datasets also begin to reflect this novel cyber-physical aspect in two ways: first by conducting cyberattacks against the testbed infrastructures during the data acquisition, and second, by including network traffic data along with the physical data captured during the experimentations.
However, current machine learning models do not fully take into account this cyber-physical component, being only trained either on the physical or on the network data. This paper addresses this problem by providing a multi-layer approach to applying machine learning to cyber-physical systems, by combining physical and network traffic data and assessing its effects on attack detection performances of machine learning algorithms, as well as its cross impact with data enriched with graph metrics.
- Venue: WDSA/CCWI 2024, Ferrara, Italy — Engineering Proceedings, MDPI
- DOI: 10.3390/engproc2024069118
- HAL record: hal-04474132
- PDF: download
- Co-authors: Côme Frappé - Vialatoux
