期刊文献+

基于多新息扩展Kalman粒子群的Modbus协议攻击检测方法 被引量:2

Attack Detection Algorithm of Modbus Protocol Based on Extended Kalman Particle Swarm Optimization with Multi-innovation
下载PDF
导出
摘要 因为工控系统数据有高维度和非线性的特点,所以针对基于Modbus TCP协议的工控系统提出一种融合Fisher分析、核主成分分析法和多新息扩展Kalman粒子群方法的攻击检测模型。利用Fisher分析和核主成分分析法(kernel principal component analysis,KPCA)对初始数据集进行预处理,实现特征提取和降低数据维度的作用;使用多新息扩展Kalman粒子群算法对支持向量机进行参数寻优,使用以前时刻的新息和当前时刻粒子观测值预估粒子位置,避免传统粒子群算法易陷入局部极小和扩展卡尔曼滤波算法在强非线性系统易导致精度降低的问题。在原始数据集上的仿真结果表明,所提算法在检测准确率、精确率和误报率上与传统的检测算法比较有显著的的提高。 Because of the high dimensional and nonlinear characteristics of industrial control system data, an attack detection model is proposed for industrial control system based on Modbus TCP protocol, and by integrating Fisher’s sub-analysis, nuclear main component analysis method and multi-innovation expansion Kalman particle group method. The initial data set is preprocessed by Fisher and KPCA(kernel principal component analysis), to do feature extraction and reduction of data dimensions, and the support vector machine is parameterized by the multi-innovation extended Kalman particle group algorithm, and the particle position is estimated by the innovation of the previous moment and the particle observations of the current moment. It avoids the problem to get caught up in the local extremes, and solves that the extended Kalman filter algorithm can easily lead to the reduction of accuracy in the strong nonlinear system. The simulation results on the original data set show that the proposed algorithm has significantly improved the detection accuracy and false positive rate compared with the traditional detection algorithm.
作者 王敏 王勇 邹春明 田英杰 郭乃网 WANG Min;WANG Yong;ZOU Chunming;TIAN Yingjie;GUO Naiwang(College of Computer Science and Technology,Shanghai University of Electric,Shanghai 200090,China;The Thrid Research Institute of Ministry of Public Security,Shanghai 200031,China;Institute of Electric Power Research,State Grid Shanghai Electric Power Company,Shanghai 200120,China)
出处 《微型电脑应用》 2022年第10期1-5,9,共6页 Microcomputer Applications
基金 国家自然科学基金面上项目(61772327) 上海自然科学基金面上项目(20ZR1455900) 奇安信大数据协同安全国家工程实验室开放课题(QAX-201803) 浙江大学工业控制技术国家重点实验室开放式基金(ICT1800380) 上海市科委科技创新行动计划(18511105700) 上海市科委电力人工智能工程技术研究中心项目(19DZ2252800)。
关键词 MODBUS协议 主成分分析 扩展Kalman粒子群算法 支持向量机 攻击检测 Modbus protocol PCA extended Kalman particle swarm optimization SVM attack detection
  • 相关文献

参考文献11

二级参考文献141

共引文献265

同被引文献9

引证文献2

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部