Enhancing Industrial Control System Security: An Isolation Forest-based Anomaly Detection Model for Mitigating Cyber Threats
Md. Saif Mahmud, Md. Ashikul Islam, Md. Maruf Rahman, Debashon Chakraborty, Shaharier Kabir, Abu Shufian, Protik Parvez Sheikh
Journal of Engineering Research and Reports · pp. 161–173 · Published 6 Mar 2024
10.9734/jerr/2024/v26i31102Abstract
In the evolving landscape of industrial control systems (ICS), the sophistication of cyber threats has necessitated the development of advanced anomaly detection mechanisms to safeguard critical infrastructure. This study introduces a novel anomaly detection model based on the Isolation Forest algorithm, tailored for the complex environment of ICS. Unlike traditional detection methods that often rely on predefined thresholds or patterns, our model capitalizes on the Isolation Forest's ability to efficiently isolate anomalies in high-dimensional datasets, making it particularly suited for the dynamic and intricate data generated by ICS. Leveraging the HAI dataset, which encompasses operational data from a realistic ICS testbed augmented with a Hardware-In-the-Loop (HIL) simulator, this research demonstrates the model's effectiveness in identifying both known and novel cyber threats across various ICS components. Our findings reveal that the Isolation Forest-based model outperforms traditional anomaly detection techniques in terms of detection accuracy, false positive rate, and computational efficiency. Furthermore, the model exhibits a remarkable ability to adapt to the evolving nature of cyber threats, underscoring its potential as a robust tool for enhancing the security posture of ICS. Through a detailed analysis of its application in detecting sophisticated attacks represented in the HAI dataset, this study contributes to the ongoing discourse on improving ICS security and presents a compelling case for the adoption of machine learning-based anomaly detection solutions in industrial settings.
Cited by 14
M. T. Yilmaz, Ferdi Doğan, Esra Söğüt · International Journal of Information Security · 2026
Recep Akkan, Osman Can Çetlenbik · Journal of Information Assurance and Security · 2026
Sijin Yeom, Jae-Hun Jung · Machine Learning: Science and Technology · 2026
Iman Masoumi, S. Esmaeiloghli, Ali Moradi Afrapoli · Stochastic environmental research and risk assessment (Print) · 2026
Betul Karaoglan, M. Guneser, Ufuk Akbulut · 2025 9th International Conference on Electronics, Communication and Aerospace Technology (ICECA) · 2025
Amna Zahoor, Waseem Abbasi, Muhammad Zeeshan Babar · Scientific Reports · 2025
Velizar Varbanov, Tatiana V. Atanasova · SGEM International Multidisciplinary Scientific GeoConference� EXPO Proceedings · 2025
Kiren Roopraj, N. Pillay, Navin Singh · Conference on Information Communications Technology and Society · 2025
Velizar Varbanov, Tatiana V. Atanasova · ITISE 2025 · 2025
K. Nugroho · Jurnal Pendidikan dan Teknologi Indonesia · 2025
Related research
- Comparative Analysis of Fully Convolutional Networks (FCN), SegNet, and U-Net for Semantic Segmentation of Synthetic Wafer Map Defect Patterns — shares topic coverage
- Attack and Anomaly Detection in IoT Networks using Machine Learning Techniques: A Review — shares topic coverage
- State-of-the-Art Violence Detection Techniques: A review — shares topic coverage
- Combating the Challenges of False Positives in AI-Driven Anomaly Detection Systems and Enhancing Data Security in the Cloud — shares topic coverage
- A Machine Learning Algorithm Based on Inverse Problems for Cyber Anomaly Detection — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
14
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.