conference-paper

DeepICS: Deep Causal Relationship Modeling for Multi-Source Log-Based Anomaly Detection in Industrial Control Systems

Research footprint

At a glance

Citations
1
References
7
Comments
0
Paper overview

Öz

Industrial Control Systems (ICS) are increasingly targeted by sophisticated cyber attacks, while traditional methods—relying on network analysis and signature-based detection—struggle to detect advanced persistent threats (APTs) and zero-day attacks. We present DeepICS, a novel anomaly detection approach leveraging multi-source log data and deep causal modeling. By integrating system, network, and provenance data, and using a Transformer-based framework, DeepICS captures complex temporal and causal relationships. It achieves a 92% true positive rate (TPR) with low false positives, outperforming traditional ML models and enhancing ICS security against evolving threats.

Record transparency

Publication details

DOI
10.1109/dsn-s65789.2025.00069
OpenAlex
W4412130025
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.