Enhancing Industrial Control System Security: An Isolation Forest-based Anomaly Detection Model for Mitigating Cyber Threats
Md. Saif Mahmud, Md. Ashikul Islam, Md. Maruf Rahman, Debashon Chakraborty, Shaharier Kabir, Abu Shufian, Protik Parvez Sheikh
Journal of Engineering Research and Reports · pp. 161–173 · Published 6 Mar 2024
10.9734/jerr/2024/v26i31102Abstract
In the evolving landscape of industrial control systems (ICS), the sophistication of cyber threats has necessitated the development of advanced anomaly detection mechanisms to safeguard critical infrastructure. This study introduces a novel anomaly detection model based on the Isolation Forest algorithm, tailored for the complex environment of ICS. Unlike traditional detection methods that often rely on predefined thresholds or patterns, our model capitalizes on the Isolation Forest's ability to efficiently isolate anomalies in high-dimensional datasets, making it particularly suited for the dynamic and intricate data generated by ICS. Leveraging the HAI dataset, which encompasses operational data from a realistic ICS testbed augmented with a Hardware-In-the-Loop (HIL) simulator, this research demonstrates the model's effectiveness in identifying both known and novel cyber threats across various ICS components. Our findings reveal that the Isolation Forest-based model outperforms traditional anomaly detection techniques in terms of detection accuracy, false positive rate, and computational efficiency. Furthermore, the model exhibits a remarkable ability to adapt to the evolving nature of cyber threats, underscoring its potential as a robust tool for enhancing the security posture of ICS. Through a detailed analysis of its application in detecting sophisticated attacks represented in the HAI dataset, this study contributes to the ongoing discourse on improving ICS security and presents a compelling case for the adoption of machine learning-based anomaly detection solutions in industrial settings.
Cited by 14
Muhammad Muzamil Aslam, Ali Tufail, M. N. Irshad · Cyber Security and Applications · 2025
F. K, S. R, Owais Farooqui · 2024 8th International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud) (I-SMAC) · 2024
Ermiyas Birihanu, Souad Asroubi, Imre Lendák · Symposium on Intelligent Systems and Informatics · 2024
Mustafa Tahsin Yilmaz, Ferdi Doğan, Esra Söğüt · 2025
Related research
- Comparative Analysis of Fully Convolutional Networks (FCN), SegNet, and U-Net for Semantic Segmentation of Synthetic Wafer Map Defect Patterns — shares topic coverage
- Attack and Anomaly Detection in IoT Networks using Machine Learning Techniques: A Review — shares topic coverage
- State-of-the-Art Violence Detection Techniques: A review — shares topic coverage
- Combating the Challenges of False Positives in AI-Driven Anomaly Detection Systems and Enhancing Data Security in the Cloud — shares topic coverage
- A Machine Learning Algorithm Based on Inverse Problems for Cyber Anomaly Detection — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
14
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.