{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T01:07:02Z","timestamp":1767488822199,"version":"3.48.0"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030935108"},{"type":"electronic","value":"9783030935115"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-93511-5_5","type":"book-chapter","created":{"date-parts":[[2022,1,4]],"date-time":"2022-01-04T07:02:42Z","timestamp":1641279762000},"page":"97-118","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Anomaly Detection in Automation Controllers"],"prefix":"10.1007","author":[{"given":"Robert","family":"Mellish","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Scott","family":"Graham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stephen","family":"Dunlap","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Patrick","family":"Sweeney","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,1,4]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"T. Alves, R. Das and T. Morris, Embedding encryption and machine learning intrusion prevention systems in programmable logic controllers, IEEE Embedded Systems Letters, vol. 10(3), pp. 99\u2013102, 2018.","DOI":"10.1109\/LES.2018.2823906"},{"key":"5_CR2","doi-asserted-by":"crossref","unstructured":"J. Bernacki and G. Kolaczek, Anomaly detection in network traffic using selected methods of time series analysis, International Journal of Computer Network and Information Security, vol. 7(9), pp. 10\u201318, 2015.","DOI":"10.5815\/ijcnis.2015.09.02"},{"key":"5_CR3","unstructured":"Y. Dodge, The Concise Encyclopedia of Statistics, Springer, New York, 2008."},{"key":"5_CR4","doi-asserted-by":"crossref","unstructured":"S. Dunlap, J. Butts, J. Lopez, M. Rice and B. Mullins, Using timing-based side channels for anomaly detection in industrial control systems, International Journal of Critical Infrastructure Protection, vol. 15, pp. 12\u201326, 2016.","DOI":"10.1016\/j.ijcip.2016.07.003"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"S. East, J. Butts, M. Papa and S. Shenoi, A taxonomy of attacks on the DNP3 protocol, in Critical Infrastructure Protection III, C. Palmer and S. Shenoi (Eds.), Springer, Berlin Heidelberg, Germany, pp. 67\u201381, 2009.","DOI":"10.1007\/978-3-642-04798-5_5"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"D. Formby and R. Beyah, Temporal execution behavior for host anomaly detection in programmable logic controllers, IEEE Transactions on Information Forensics and Security, vol. 15, pp. 1455\u20131469, 2020.","DOI":"10.1109\/TIFS.2019.2940890"},{"key":"5_CR7","doi-asserted-by":"crossref","unstructured":"A. Keliris and M. Maniatakos, ICSREF: A framework for automated reverse engineering of industrial control system binaries, Proceedings of the Twenty-Sixth Annual Network and Distributed System Security Symposium, 2019.","DOI":"10.14722\/ndss.2019.23271"},{"key":"5_CR8","unstructured":"D. Kite, Leveraging Security-Using the SEL RTAC\u2019s Built-In Security Features, SEL White Paper LWP0018-01, Schweitzer Engineering Laboratories, Pullman, Washington, 2016."},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"H. Mann and D. Whitney, On a test of whether one of two random variables is stochastically larger than the other, The Annals of Mathematical Statistics, vol. 18(1), pp. 50\u201360, 1947.","DOI":"10.1214\/aoms\/1177730491"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"L. Martin-Liras, M. Prada, J. Fuertes, A. Moran, S. Alonso and M. Dominguez, Comparative analysis of the security of configuration protocols for industrial control devices, International Journal of Critical Infrastructure Protection, vol. 19, pp. 4\u201315, 2017.","DOI":"10.1016\/j.ijcip.2017.10.001"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"R. Mitchell and I. Chen, A survey of intrusion detection techniques for cyber-physical systems, ACM Computing Surveys, vol. 46(4), article no. 55, 2014.","DOI":"10.1145\/2542049"},{"key":"5_CR12","doi-asserted-by":"crossref","unstructured":"N. Nachar, The Mann-Whitney U: A test for assessing whether two independent samples come from the same distribution, Tutorials in Quantitative Methods for Psychology, vol. 4(1), pp. 13\u201320, 2008.","DOI":"10.20982\/tqmp.04.1.p013"},{"key":"5_CR13","unstructured":"M. Niedermaier, J. Malchow, F. Fischer, D. Marzin, D. Merli, V. Roth and A. von Bodisco, You snooze, you lose: Measuring PLC cycle times under attacks, Proceedings of the Twelfth USENIX Workshop on Offensive Technologies, 2018."},{"key":"5_CR14","unstructured":"A. Nochvay, Security Research: CODESYS Runtime, A PLC Control Framework, Version 1.0, Kaspersky, Woburn, Massachusetts (ics-cert.kaspersky.com\/media\/KICS-CERT-Codesys-En.pdf), 2019."},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"C. Parian, T. Guldimann and S. Bhatia, Fooling the master: Exploiting weaknesses in the Modbus protocol, Procedia Computer Science, vol. 171, pp. 2453\u20132458, 2020.","DOI":"10.1016\/j.procs.2020.04.265"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"D. Pliatsios, P. Sarigiannidis, T. Lagkas and A. Sarigiannidis, A survey of SCADA systems: Secure protocols, incidents, threats and tactics, IEEE Communications Surveys and Tutorials, vol. 22(3), pp. 1942\u20131976, 2020.","DOI":"10.1109\/COMST.2020.2987688"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"S. Raschka, MLxtend: Providing machine learning and data science utilities and extensions to Python\u2019s scientific computing stack, Journal of Open Source Software, vol. 3(24), pp. 638\u2013639, 2018.","DOI":"10.21105\/joss.00638"},{"key":"5_CR18","unstructured":"Schweitzer Engineering Laboratories, SEL ranked top protective relay manufacturer in industry survey, Pullman, Washington (www.selinc.com\/company\/news\/126347), June 12, 2019."},{"key":"5_CR19","unstructured":"Schweitzer Engineering Laboratories, Customer Highlights, Pullman, Washington (www.selinc.com\/solutions\/success-stories), 2020."},{"key":"5_CR20","unstructured":"Schweitzer Engineering Laboratories, SEL-3505 SEL-3505-3 Real-Time Automation Controller Instruction Manual, Pullman, Washington, 2020."},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"S. Senthivel, S. Dhungana, H. Yoo, I. Ahmed and V. Roussev, Denial of engineering operations attacks on industrial control systems, Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, pp. 319\u2013329, 2018.","DOI":"10.1145\/3176258.3176319"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"J. Staggs, D. Ferlemann and S. Shenoi, Wind farm security: Attack surface, targets, scenarios and mitigation, International Journal of Critical Infrastructure Protection, vol. 17, pp. 3\u201314, 2017.","DOI":"10.1016\/j.ijcip.2017.03.001"},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"C. Vargas Martinez and B. Vogel-Heuser, A host intrusion detection system architecture for embedded industrial devices, Journal of the Franklin Institute, vol. 358(1), pp. 210\u2013236, 2021.","DOI":"10.1016\/j.jfranklin.2019.03.037"},{"key":"5_CR24","doi-asserted-by":"crossref","unstructured":"P. Virtanen, R. Gommers, T. Oliphant, M. Haberland, T. Reddy, D. Cournapeau, E. Burovski, P. Peterson, W. Weckesser, J. Bright, S. van der Walt, M. Brett, J. Wilson, K. Millman, N. Mayorov, A. Nelson, E. Jones, R. Kern, E. Larson, C. Carey, I. Polat, Y. Feng, E. Moore, J. VanderPlas, D. Laxalde, J. Perktold, R. Cimrman, I. Henriksen, E. Quintero, C. Harris, A. Archibald, A. Ribeiro, F. Pedregosa, P. van Mulbregt and SciPy 1.0 Contributors, SciPy 1.0: Fundamental algorithms for scientific computing in Python, Nature Methods, vol. 17, pp. 261\u2013272, 2020.","DOI":"10.1038\/s41592-020-0772-5"},{"key":"5_CR25","unstructured":"R. Wilcox, Applying Contemporary Statistical Techniques, Academic Press, Burlington, Massachusetts, 2003."},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"D. Zhu and Y. Cui, Understanding the random guessing line in a ROC curve, Proceedings of the Second International Conference on Image, Vision and Computing, pp. 1156\u20131159, 2017.","DOI":"10.1109\/ICIVC.2017.7984735"}],"container-title":["IFIP Advances in Information and Communication Technology","Critical Infrastructure Protection XV"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-93511-5_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T01:02:18Z","timestamp":1767488538000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-93511-5_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030935108","9783030935115"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-93511-5_5","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"4 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICCIP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Critical Infrastructure Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 March 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 March 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iccip2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip1110.org\/Conferences\/2021conferenceinformation.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}