산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17553742
성남: 가천대학교 일반대학원, 2026
학위논문(석사) -- 가천대학교 일반대학원 , 정보보호학과 정보보호학 전공 , 2026. 8
2026
한국어
005.8 판사항(23)
경기도
vii, 112 p.: 천연색삽화, 도표; 26 cm.
지도교수: 서정택
참고문헌 수록
I804:41005-200001011099
0
상세조회0
다운로드산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)...
산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)은 발전, 수처리, 제조, 에너지, 교통 등 주요 기반시설과 산업 현장에서 물리 공정을 감시하고 제어하는 핵심 시스템이다. 최근 ICS 환경은 IT/OT 연계와 원격 운영이 확대되면서 운영 효율성이 향상되었으나, 외부 사이버공격에 노출될 가능성 또한 증가하고 있다. ICS 환경을 대상으로 한 사이버공격은 센서 값 조작, 제어 명령 변조, 액추에이터 오동작 등을 통해 물리 공정의 오작동, 설비 손상, 생산 중단, 인명 피해로 이어질 수 있어 효과적인 이상탐지 기술이 요구된다. 그러나 ICS 데이터는 센서 및 액추에이터 값이 시간 순서에 따라 기록되는 다변량 시계열 데이터이다. 그렇기 때문에 단일 시점의 값만으로는 정상 상태와 이상 상태를 구분하기 어렵다. 또한 실제 산업 현장에서는 정상 운전 데이터를 장기간 수집할 수 있는 반면, 공격 데이터와 신뢰 가능한 라벨은 제한적으로만 확보된다. 이로 인해 소량의 라벨에 탐지 경계가 과도하게 의존하면 전체 정상 운전 패턴과 다양한 이상 유형을 충분히 반영하지 못해 탐지 경계가 편향될 수 있다. 따라서 ICS 환경에서는 정상 운전 데이터의 시간적 문맥을 학습하면서 소량의 라벨을 안정적으로 활용하는 이상탐지 방법이 필요하다. 이에 본 논문에서는 ICS 환경에서 발생하는 다변량 시계열 데이터를 대상으로 시계열 문맥 표현 학습 기반 이상탐지 모델을 제안한다. 제안 모델은 원본 센서 및 액추에이터 값으로부터 현재 시점의 운전 상태, 직전 시점 대비 절대 변화량, 단기 운전 문맥 대비 절대 편차, 장기 운전 문맥 대비 절대 편차 등의 시계열 문맥 기반 특징을 구성하고, 정상 운전 데이터만을 이용한 마스킹 복원 및 다음 시점 예측을 통해 정상 운전 상태의 잠재 표현과 복원·예측 오차를 학습한다. 이후 시계열 문맥 특징과 자기지도 학습 기반 특징을 결합하고, 정상 학습 샘플과 소량의 정상·공격 라벨을 함께 활용하여 정상과 이상을 구분하는 탐지 경계를 학습한다. 이를 통해 탐지 경계가 소량 라벨에 과도하게 의존하는 문제를 완화한다. 제안 모델의 성능을 평가하기 위해 SWaT, WADI, HAI 데이터셋을 이용하여 실험을 수행하였다. 공격 라벨 500 개 조건에서 SWaT F1-Score 0.9519, WADI F1-Score 0.9765, HAI F1-Score 0.9113 을 기록하였으며, 특히 WADI 데이터셋에서는 공격 라벨 100 개만으로 F1- Score 0.9282 를 달성하였다. 또한 기존 준지도 이상탐지 모델인 DeepSAD, RoSAS, SFSD 와 지도학습 기반 이상탐지 모델인 STAND, 비지도학습 기반 이상탐지 모델인 TranAD 와 비교하여 다수의 라벨 조건에서 동등하거나 더 높은 성능을 확인하였다. 이를 통해 제안 모델이 라벨 확보가 어려운 실제 ICS 환경에서 사이버공격 및 이상 상태 탐지에 활용될 수 있음을 보였다.
다국어 초록 (Multilingual Abstract)
Industrial Control Systems(ICS) are core systems that monitor and control physical processes in key infrastructure and industrial sites, such as power generation, water treatment, manufacturing, energy, and transportation. Recently, while operatio...
Industrial Control Systems(ICS) are core systems that monitor and control physical processes in key infrastructure and industrial sites, such as power generation, water treatment, manufacturing, energy, and transportation. Recently, while operational efficiency in ICS environments has improved due to the expansion of IT/OT integration and remote operations, the risk of exposure to external cyberattacks has also increased. Cyberattacks targeting ICS environments can lead to physical process malfunctions, equipment damage, production shutdowns, and loss of life through the manipulation of sensor values, tampering with control commands, and actuator malfunctions, thereby necessitating effective anomaly detection technologies. However, ICS data consists of multivariate time-series data in which sensor and actuator values are recorded in chronological order. Consequently, it is difficult to distinguish between normal and anomaly states based solely on values at a single point in time. Furthermore, while normal operation data can be collected over long periods in actual industrial settings, attack data and reliable labels are available only in limited quantities. Consequently, if detection thresholds rely too heavily on a small number of labels, they may fail to adequately reflect the overall normal operation patterns and various anomaly types, leading to biased detection thresholds. Therefore, ICS environments require an anomaly detection method that reliably utilizes a small number of labels while learning the temporal context of normal operation data. Accordingly, this paper proposes an anomaly detection model based on the learning of time-series contextual representations, targeting multivariate time-series data generated in ICS environments. The proposed model constructs time-series context-based features from raw sensor and actuator values, such as the current operating state, absolute change relative to the previous time step, absolute deviation relative to the short-term operating context, and absolute deviation relative to the long-term operating context. It then learns the latent representation of the normal operating state and the restoration and prediction errors through masking restoration and next-time-step prediction using only normal operating data. Subsequently, the model combines time-series context features with self-supervised learning-based features and utilizes both normal training samples and a small number of normal and attack labels to learn a detection boundary that distinguishes between normal and anomaly states. This mitigates the issue of the detection boundary becoming overly dependent on the small number of labels. To evaluate the performance of the proposed model, experiments were conducted using the SWaT, WADI, and HAI datasets. With 500 attack labels, the model achieved an F1-score of 0.9519 on SWaT, 0.9765 on WADI, and 0.9113 on HAI; notably, on the WADI dataset, it achieved an F1-score of 0.9282 using only 100 attack labels. Furthermore, when compared to existing semi-supervised anomaly detection models such as DeepSAD, RoSAS, and SFSD; the supervised anomaly detection model STAND; and the unsupervised anomaly detection model TranAD, the proposed model demonstrated equivalent or higher performance across a wide range of label conditions. This demonstrates that the proposed model can be utilized for detecting cyberattacks and anomaly states in real-world ICS environments where obtaining labels is challenging.
목차 (Table of Contents)