RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 = A Study on Semi-Supervised Anomaly Detection Models Utilizing Time-Series Context to Improve the Performance of Industrial Control System Anomaly Detection

    한글로보기

    https://www.riss.kr/link?id=T17553742

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
      • URL 복사
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)은 발전, 수처리, 제조, 에너지, 교통 등 주요 기반시설과 산업 현장에서 물리 공정을 감시하고 제어하는 핵심 시스템이다. 최근 ICS 환경은 IT/OT 연계와 원격 운영이 확대되면서 운영 효율성이 향상되었으나, 외부 사이버공격에 노출될 가능성 또한 증가하고 있다. ICS 환경을 대상으로 한 사이버공격은 센서 값 조작, 제어 명령 변조, 액추에이터 오동작 등을 통해 물리 공정의 오작동, 설비 손상, 생산 중단, 인명 피해로 이어질 수 있어 효과적인 이상탐지 기술이 요구된다. 그러나 ICS 데이터는 센서 및 액추에이터 값이 시간 순서에 따라 기록되는 다변량 시계열 데이터이다. 그렇기 때문에 단일 시점의 값만으로는 정상 상태와 이상 상태를 구분하기 어렵다. 또한 실제 산업 현장에서는 정상 운전 데이터를 장기간 수집할 수 있는 반면, 공격 데이터와 신뢰 가능한 라벨은 제한적으로만 확보된다. 이로 인해 소량의 라벨에 탐지 경계가 과도하게 의존하면 전체 정상 운전 패턴과 다양한 이상 유형을 충분히 반영하지 못해 탐지 경계가 편향될 수 있다. 따라서 ICS 환경에서는 정상 운전 데이터의 시간적 문맥을 학습하면서 소량의 라벨을 안정적으로 활용하는 이상탐지 방법이 필요하다. 이에 본 논문에서는 ICS 환경에서 발생하는 다변량 시계열 데이터를 대상으로 시계열 문맥 표현 학습 기반 이상탐지 모델을 제안한다. 제안 모델은 원본 센서 및 액추에이터 값으로부터 현재 시점의 운전 상태, 직전 시점 대비 절대 변화량, 단기 운전 문맥 대비 절대 편차, 장기 운전 문맥 대비 절대 편차 등의 시계열 문맥 기반 특징을 구성하고, 정상 운전 데이터만을 이용한 마스킹 복원 및 다음 시점 예측을 통해 정상 운전 상태의 잠재 표현과 복원·예측 오차를 학습한다. 이후 시계열 문맥 특징과 자기지도 학습 기반 특징을 결합하고, 정상 학습 샘플과 소량의 정상·공격 라벨을 함께 활용하여 정상과 이상을 구분하는 탐지 경계를 학습한다. 이를 통해 탐지 경계가 소량 라벨에 과도하게 의존하는 문제를 완화한다. 제안 모델의 성능을 평가하기 위해 SWaT, WADI, HAI 데이터셋을 이용하여 실험을 수행하였다. 공격 라벨 500 개 조건에서 SWaT F1-Score 0.9519, WADI F1-Score 0.9765, HAI F1-Score 0.9113 을 기록하였으며, 특히 WADI 데이터셋에서는 공격 라벨 100 개만으로 F1- Score 0.9282 를 달성하였다. 또한 기존 준지도 이상탐지 모델인 DeepSAD, RoSAS, SFSD 와 지도학습 기반 이상탐지 모델인 STAND, 비지도학습 기반 이상탐지 모델인 TranAD 와 비교하여 다수의 라벨 조건에서 동등하거나 더 높은 성능을 확인하였다. 이를 통해 제안 모델이 라벨 확보가 어려운 실제 ICS 환경에서 사이버공격 및 이상 상태 탐지에 활용될 수 있음을 보였다.
    번역하기

    산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)...

    산업제어시스템 이상탐지 성능 향상을 위한 시계열 Context 활용 준지도 이상탐지 모델에 관한 연구 서정규 정보보호학과 가천대학교 일반대학원 산업제어시스템(Industrial Control System, ICS)은 발전, 수처리, 제조, 에너지, 교통 등 주요 기반시설과 산업 현장에서 물리 공정을 감시하고 제어하는 핵심 시스템이다. 최근 ICS 환경은 IT/OT 연계와 원격 운영이 확대되면서 운영 효율성이 향상되었으나, 외부 사이버공격에 노출될 가능성 또한 증가하고 있다. ICS 환경을 대상으로 한 사이버공격은 센서 값 조작, 제어 명령 변조, 액추에이터 오동작 등을 통해 물리 공정의 오작동, 설비 손상, 생산 중단, 인명 피해로 이어질 수 있어 효과적인 이상탐지 기술이 요구된다. 그러나 ICS 데이터는 센서 및 액추에이터 값이 시간 순서에 따라 기록되는 다변량 시계열 데이터이다. 그렇기 때문에 단일 시점의 값만으로는 정상 상태와 이상 상태를 구분하기 어렵다. 또한 실제 산업 현장에서는 정상 운전 데이터를 장기간 수집할 수 있는 반면, 공격 데이터와 신뢰 가능한 라벨은 제한적으로만 확보된다. 이로 인해 소량의 라벨에 탐지 경계가 과도하게 의존하면 전체 정상 운전 패턴과 다양한 이상 유형을 충분히 반영하지 못해 탐지 경계가 편향될 수 있다. 따라서 ICS 환경에서는 정상 운전 데이터의 시간적 문맥을 학습하면서 소량의 라벨을 안정적으로 활용하는 이상탐지 방법이 필요하다. 이에 본 논문에서는 ICS 환경에서 발생하는 다변량 시계열 데이터를 대상으로 시계열 문맥 표현 학습 기반 이상탐지 모델을 제안한다. 제안 모델은 원본 센서 및 액추에이터 값으로부터 현재 시점의 운전 상태, 직전 시점 대비 절대 변화량, 단기 운전 문맥 대비 절대 편차, 장기 운전 문맥 대비 절대 편차 등의 시계열 문맥 기반 특징을 구성하고, 정상 운전 데이터만을 이용한 마스킹 복원 및 다음 시점 예측을 통해 정상 운전 상태의 잠재 표현과 복원·예측 오차를 학습한다. 이후 시계열 문맥 특징과 자기지도 학습 기반 특징을 결합하고, 정상 학습 샘플과 소량의 정상·공격 라벨을 함께 활용하여 정상과 이상을 구분하는 탐지 경계를 학습한다. 이를 통해 탐지 경계가 소량 라벨에 과도하게 의존하는 문제를 완화한다. 제안 모델의 성능을 평가하기 위해 SWaT, WADI, HAI 데이터셋을 이용하여 실험을 수행하였다. 공격 라벨 500 개 조건에서 SWaT F1-Score 0.9519, WADI F1-Score 0.9765, HAI F1-Score 0.9113 을 기록하였으며, 특히 WADI 데이터셋에서는 공격 라벨 100 개만으로 F1- Score 0.9282 를 달성하였다. 또한 기존 준지도 이상탐지 모델인 DeepSAD, RoSAS, SFSD 와 지도학습 기반 이상탐지 모델인 STAND, 비지도학습 기반 이상탐지 모델인 TranAD 와 비교하여 다수의 라벨 조건에서 동등하거나 더 높은 성능을 확인하였다. 이를 통해 제안 모델이 라벨 확보가 어려운 실제 ICS 환경에서 사이버공격 및 이상 상태 탐지에 활용될 수 있음을 보였다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Industrial Control Systems(ICS) are core systems that monitor and control physical processes in key infrastructure and industrial sites, such as power generation, water treatment, manufacturing, energy, and transportation. Recently, while operational efficiency in ICS environments has improved due to the expansion of IT/OT integration and remote operations, the risk of exposure to external cyberattacks has also increased. Cyberattacks targeting ICS environments can lead to physical process malfunctions, equipment damage, production shutdowns, and loss of life through the manipulation of sensor values, tampering with control commands, and actuator malfunctions, thereby necessitating effective anomaly detection technologies. However, ICS data consists of multivariate time-series data in which sensor and actuator values are recorded in chronological order. Consequently, it is difficult to distinguish between normal and anomaly states based solely on values at a single point in time. Furthermore, while normal operation data can be collected over long periods in actual industrial settings, attack data and reliable labels are available only in limited quantities. Consequently, if detection thresholds rely too heavily on a small number of labels, they may fail to adequately reflect the overall normal operation patterns and various anomaly types, leading to biased detection thresholds. Therefore, ICS environments require an anomaly detection method that reliably utilizes a small number of labels while learning the temporal context of normal operation data. Accordingly, this paper proposes an anomaly detection model based on the learning of time-series contextual representations, targeting multivariate time-series data generated in ICS environments. The proposed model constructs time-series context-based features from raw sensor and actuator values, such as the current operating state, absolute change relative to the previous time step, absolute deviation relative to the short-term operating context, and absolute deviation relative to the long-term operating context. It then learns the latent representation of the normal operating state and the restoration and prediction errors through masking restoration and next-time-step prediction using only normal operating data. Subsequently, the model combines time-series context features with self-supervised learning-based features and utilizes both normal training samples and a small number of normal and attack labels to learn a detection boundary that distinguishes between normal and anomaly states. This mitigates the issue of the detection boundary becoming overly dependent on the small number of labels. To evaluate the performance of the proposed model, experiments were conducted using the SWaT, WADI, and HAI datasets. With 500 attack labels, the model achieved an F1-score of 0.9519 on SWaT, 0.9765 on WADI, and 0.9113 on HAI; notably, on the WADI dataset, it achieved an F1-score of 0.9282 using only 100 attack labels. Furthermore, when compared to existing semi-supervised anomaly detection models such as DeepSAD, RoSAS, and SFSD; the supervised anomaly detection model STAND; and the unsupervised anomaly detection model TranAD, the proposed model demonstrated equivalent or higher performance across a wide range of label conditions. This demonstrates that the proposed model can be utilized for detecting cyberattacks and anomaly states in real-world ICS environments where obtaining labels is challenging.
    번역하기

    Industrial Control Systems(ICS) are core systems that monitor and control physical processes in key infrastructure and industrial sites, such as power generation, water treatment, manufacturing, energy, and transportation. Recently, while operatio...

    Industrial Control Systems(ICS) are core systems that monitor and control physical processes in key infrastructure and industrial sites, such as power generation, water treatment, manufacturing, energy, and transportation. Recently, while operational efficiency in ICS environments has improved due to the expansion of IT/OT integration and remote operations, the risk of exposure to external cyberattacks has also increased. Cyberattacks targeting ICS environments can lead to physical process malfunctions, equipment damage, production shutdowns, and loss of life through the manipulation of sensor values, tampering with control commands, and actuator malfunctions, thereby necessitating effective anomaly detection technologies. However, ICS data consists of multivariate time-series data in which sensor and actuator values are recorded in chronological order. Consequently, it is difficult to distinguish between normal and anomaly states based solely on values at a single point in time. Furthermore, while normal operation data can be collected over long periods in actual industrial settings, attack data and reliable labels are available only in limited quantities. Consequently, if detection thresholds rely too heavily on a small number of labels, they may fail to adequately reflect the overall normal operation patterns and various anomaly types, leading to biased detection thresholds. Therefore, ICS environments require an anomaly detection method that reliably utilizes a small number of labels while learning the temporal context of normal operation data. Accordingly, this paper proposes an anomaly detection model based on the learning of time-series contextual representations, targeting multivariate time-series data generated in ICS environments. The proposed model constructs time-series context-based features from raw sensor and actuator values, such as the current operating state, absolute change relative to the previous time step, absolute deviation relative to the short-term operating context, and absolute deviation relative to the long-term operating context. It then learns the latent representation of the normal operating state and the restoration and prediction errors through masking restoration and next-time-step prediction using only normal operating data. Subsequently, the model combines time-series context features with self-supervised learning-based features and utilizes both normal training samples and a small number of normal and attack labels to learn a detection boundary that distinguishes between normal and anomaly states. This mitigates the issue of the detection boundary becoming overly dependent on the small number of labels. To evaluate the performance of the proposed model, experiments were conducted using the SWaT, WADI, and HAI datasets. With 500 attack labels, the model achieved an F1-score of 0.9519 on SWaT, 0.9765 on WADI, and 0.9113 on HAI; notably, on the WADI dataset, it achieved an F1-score of 0.9282 using only 100 attack labels. Furthermore, when compared to existing semi-supervised anomaly detection models such as DeepSAD, RoSAS, and SFSD; the supervised anomaly detection model STAND; and the unsupervised anomaly detection model TranAD, the proposed model demonstrated equivalent or higher performance across a wide range of label conditions. This demonstrates that the proposed model can be utilized for detecting cyberattacks and anomaly states in real-world ICS environments where obtaining labels is challenging.

    더보기

    목차 (Table of Contents)

    • 제 1 장. 서론 1
    • 제 2 장. 배경지식 및 관련연구 8
    • 2.1 배경지식 8
    • 2.1.1 ICS 개요 8
    • 2.1.2 ICS 대상 사이버공격 분석 12
    • 제 1 장. 서론 1
    • 제 2 장. 배경지식 및 관련연구 8
    • 2.1 배경지식 8
    • 2.1.1 ICS 개요 8
    • 2.1.2 ICS 대상 사이버공격 분석 12
    • 2.1.3 이상탐지 14
    • 2.2 관련 연구 17
    • 2.2.1 지도·비지도학습 AI 기반 이상탐지 연구 17
    • 2.2.2 준지도학습 AI 기반 이상탐지 연구 24
    • 제 3 장. 산업제어시스템 환경 대상 시계열 문맥 표현 학습 기반 이상탐지 모델 제안 30
    • 3.1 이상탐지 모델 개요 31
    • 3.2 데이터 전처리기 36
    • 3.3 시계열 문맥 정보 기반 특징 추출 39
    • 3.4 자기지도 표현 기반 학습기 47
    • 3.5 라벨 데이터 활용 기반 준지도 경계 학습 55
    • 3.6 준지도 이상탐지기 60
    • 제 4 장. 산업제어시스템 환경 대상 시계열 문맥 표현 학습 기반 이상탐지 모델 실험 및 검증 64
    • 4.1 실험환경 65
    • 4.2 데이터셋 69
    • 4.2.1 SWaT 데이터셋 69
    • 4.2.2 WADI 데이터셋 70
    • 4.2.3 HAI 데이터셋 73
    • 4.3 이상탐지 모델 성능 평가 77
    • 4.4 이상탐지 모델 성능 비교 검증 83
    • 4.5 자기지도 표현 기반 특징 제거 실험 98
    • 제 5 장. 결론 및 향후 연구방향 101
    • 참고문헌 104
    • ABSTRACT 109
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼