{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:43:40Z","timestamp":1782834220666,"version":"3.54.5"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T00:00:00Z","timestamp":1671580800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T00:00:00Z","timestamp":1671580800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100006359","name":"Blekinge Institute of Technology","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006359","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Energy Inform"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Network anomaly detection for critical infrastructure supervisory control and data acquisition (SCADA) systems is the first line of defense against cyber-attacks. Often hybrid methods, such as machine learning with signature-based intrusion detection methods, are employed to improve the detection results. Here an attempt is made to enhance the support vector-based outlier detection method by leveraging behavioural attribute extension of the network nodes. The network nodes are modeled as graph vertices to construct related attributes that enhance network characterisation and potentially improve unsupervised anomaly detection ability for SCADA network. IEC 104 SCADA protocol communication data with good domain fidelity is utilised for empirical testing. The results demonstrate that the proposed approach achieves significant improvements over the baseline approach (average <jats:inline-formula><jats:alternatives><jats:tex-math>$$F_{1}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msub>\n                    <mml:mi>F<\/mml:mi>\n                    <mml:mn>1<\/mml:mn>\n                  <\/mml:msub>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>\u00a0score increased from 0.6 to 0.9, and Matthews correlation coefficient (MCC) from 0.3 to 0.8). The achieved outcome also surpasses the unsupervised scores of related literature. For critical networks, the identification of attacks is indispensable. The result shows an insignificant missed-alert rate (<jats:inline-formula><jats:alternatives><jats:tex-math>$$0.3\\%$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mn>0.3<\/mml:mn>\n                    <mml:mo>%<\/mml:mo>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula> on average), the lowest among related works. The gathered results show that the proposed approach can expose rouge SCADA nodes reasonably and assist in further pruning the identified unusual instances.<\/jats:p>","DOI":"10.1186\/s42162-022-00252-1","type":"journal-article","created":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T10:02:45Z","timestamp":1671616965000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Improving anomaly detection in SCADA network communication with attribute extension"],"prefix":"10.1186","volume":"5","author":[{"given":"Mahwish","family":"Anwar","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lars","family":"Lundberg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anton","family":"Borg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,12,21]]},"reference":[{"key":"252_CR1","doi-asserted-by":"crossref","unstructured":"Akoglu L, McGlohon M, Faloutsos C (2010) Oddball: Spotting anomalies in weighted graphs. In: Zaki MJ, Yu JX, Ravindran B, Pudi V (eds) Advances in knowledge discovery and data mining. Pacific-Asia conference on knowledge discovery and data mining (PAKDD). Lecture notes in computer science, Vol 6119. Springer, Berlin, Heidelberg, pp. 410\u2013421","DOI":"10.1007\/978-3-642-13672-6_40"},{"key":"252_CR2","doi-asserted-by":"publisher","unstructured":"Anwar M, Borg A, Lundberg L (2021) A comparison of unsupervised learning algorithms for intrusion detection in IEC 104 SCADA protocol. In: 20th International conference on machine learning and cybernetics (ICMLC), IEEE, pp. 1\u20138. https:\/\/doi.org\/10.1109\/ICMLC54886.2021.9737267","DOI":"10.1109\/ICMLC54886.2021.9737267"},{"key":"252_CR3","volume-title":"The industrial control system cyber kill chain","author":"MJ Assante","year":"2015","unstructured":"Assante MJ, Lee RM (2015) The industrial control system cyber kill chain. Technical report, SANS Institute InfoSec Reading Room"},{"issue":"1","key":"252_CR4","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1186\/s12864-019-6413-7","volume":"21","author":"D Chicco","year":"2020","unstructured":"Chicco D, Jurman G (2020) The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation. BMC Genomics 21(1):6. https:\/\/doi.org\/10.1186\/s12864-019-6413-7","journal-title":"BMC Genomics"},{"key":"252_CR5","unstructured":"CISA (2016) ICS Alert (IR-ALERT-H-16-056-01). Cyber-attack against Ukrainian critical infrastructure; Cybersecurity and Infrastructure Security Agency. Cybersecurity and Infrastructure Security Agency (CISA).&nbsp;&nbsp;https:\/\/www.cisa.gov\/uscert\/ics\/alerts\/IR-ALERT-H-16-056-01. Accessed 9 May&nbsp;2022"},{"key":"252_CR6","doi-asserted-by":"crossref","unstructured":"Corizzo R, Ceci M, Pio G, Mignone P, Japkowicz N (2021) Spatially-aware autoencoders for detecting contextual anomalies in geo-distributed data. In: International conference on discovery science, pp. 461\u2013471. Springer","DOI":"10.1007\/978-3-030-88942-5_36"},{"issue":"S1","key":"252_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42162-020-00118-4","volume":"3","author":"M Egger","year":"2020","unstructured":"Egger M, Eibl G, Engel D (2020) Comparison of approaches for intrusion detection in substations using the IEC 60870\u20135-104 protocol. Energy Inform 3(S1):1\u201317. https:\/\/doi.org\/10.1186\/s42162-020-00118-4","journal-title":"Energy Inform"},{"key":"252_CR8","doi-asserted-by":"publisher","unstructured":"ENISA (2017) Communication Network Dependencies for ICS\/SCADA Systems. European Network and Information Security Agency, Athens. https:\/\/doi.org\/10.2824\/397676","DOI":"10.2824\/397676"},{"key":"252_CR9","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511973000","volume-title":"Machine Learning: The Art and Science of Algorithms That Make Sense of Data","author":"P Flach","year":"2012","unstructured":"Flach P (2012) Machine learning: the art and science of algorithms that make sense of data. Cambridge University Press, Cambridge"},{"key":"252_CR10","doi-asserted-by":"crossref","unstructured":"Ferling B, Chromik J, Caselli M, Remke A (2018) Intrusion detection for sequence-based attacks with reduced traffic models. In: International conference on measurement, modelling and evaluation of computing systems, pp. 53\u201367. Springer","DOI":"10.1007\/978-3-319-74947-1_4"},{"issue":"2","key":"252_CR11","doi-asserted-by":"publisher","first-page":"20","DOI":"10.3390\/jsan9020020","volume":"9","author":"GB Gaggero","year":"2020","unstructured":"Gaggero GB, Rossi M, Girdinio P, Marchese M (2020) Detecting system fault\/cyberattack within a photovoltaic system connected to the grid: a neural network-based solution. J Sens Actuator Netw 9(2):20. https:\/\/doi.org\/10.3390\/jsan9020020","journal-title":"J Sens Actuator Netw"},{"key":"252_CR12","doi-asserted-by":"publisher","unstructured":"Grammatikis PR, Sarigiannidis P, Sarigiannidis A, Margounakis D, Tsiakalos A, Efstathopoulos G (2020) An anomaly detection mechanism for iec 60870-5-104. In: 9th International conference on modern circuits and systems technologies (MOCAST), IEEE, pp. 1\u20134. https:\/\/doi.org\/10.1109\/MOCAST49295.2020.9200285","DOI":"10.1109\/MOCAST49295.2020.9200285"},{"key":"252_CR13","unstructured":"Gy\u00f6rgy P, Holczer T (2020) Attacking iec 60870-5-104 protocol. In: 1st Conference on Information Technology and Data Science (CITDS), pp. 140\u2013150. http:\/\/ceur-ws.org\/Vol-2874\/paper13.pdf"},{"key":"252_CR14","doi-asserted-by":"publisher","unstructured":"Henderson K, Gallagher B, Eliassi-Rad T, Tong H, Basu S, Akoglu L, Koutra D, Faloutsos C, Li L (2012) Rolx: structural role extraction & mining in large graphs. In: 18th ACM SIGKDD International conference on knowledge discovery and data mining, pp. 1231\u20131239. https:\/\/doi.org\/10.1145\/2339530.2339723","DOI":"10.1145\/2339530.2339723"},{"key":"252_CR15","doi-asserted-by":"publisher","unstructured":"Henderson K, Eliassi-Rad T, Faloutsos C, Akoglu L, Li L, Maruhashi K, Prakash BA, Tong H (2010) Metric forensics: a multi-level approach for mining volatile graphs. In: 16th ACM SIGKDD international conference on knowledge discovery and data mining, pp. 163\u2013172. ACM, NY. https:\/\/doi.org\/10.1145\/1835804.1835828","DOI":"10.1145\/1835804.1835828"},{"key":"252_CR16","doi-asserted-by":"publisher","unstructured":"Hodo E, Grebeniuk S, Ruotsalainen H, Tavolato P (2017) Anomaly detection for simulated IEC-60870-5-104 Trafiic. In: 12th International conference on availability, reliability and security, pp. 1\u20137. ACM, Reggio Calabria. https:\/\/doi.org\/10.1145\/3098954.3103166. Accessed 1 Jul&nbsp;2021","DOI":"10.1145\/3098954.3103166"},{"key":"252_CR17","unstructured":"Lin C-Y, Nadjm-Tehrani S (2019) Timing patterns and correlations in spontaneous scada traffic for anomaly detection. In: 22nd International symposium on research in attacks, intrusions and defenses (RAID), pp. 73\u201388"},{"key":"252_CR18","doi-asserted-by":"crossref","unstructured":"Linda O, Vollmer T, Manic M (2009) Neural network based intrusion detection system for critical infrastructures. In: 2009 International joint conference on neural networks, IEEE,&nbsp; pp. 1827\u20131834","DOI":"10.1109\/IJCNN.2009.5178592"},{"key":"252_CR19","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1007\/978-3-642-04117-4","volume-title":"Handbook of Information and Communication Security","author":"AN Mahmood","year":"2010","unstructured":"Mahmood AN, Leckie C, Hu J, Tari Z, Atiquzzaman M (2010) Network traffic analysis and scada security. Handbook of Information and Communication Security. Springer, Berlin, pp 383\u2013405. https:\/\/doi.org\/10.1007\/978-3-642-04117-4"},{"key":"252_CR20","unstructured":"Matousek P (2017) Description and analysis of IEC 104 Protocol. Technical Report FIT-TR-2017-1, Faculty of Information Technology, Brno University of Technology, Brno, Czech Republic. https:\/\/www.fit.vut.cz\/research\/publication-file\/11570\/TR-IEC104.pdf"},{"key":"252_CR21","doi-asserted-by":"publisher","unstructured":"Matousek P, Ry\u0161av\u1ef3 O, Gr\u00e9gr M (2019) Increasing visibility of iec 104 communication in the smart grid. In: 6th International Symposium for ICS & SCADA Cyber Security Research, pp. 21\u201330. https:\/\/doi.org\/10.14236\/ewic\/icscsr19.3","DOI":"10.14236\/ewic\/icscsr19.3"},{"issue":"4","key":"252_CR22","doi-asserted-by":"publisher","first-page":"460","DOI":"10.3390\/fi5040460","volume":"5","author":"M Mantere","year":"2013","unstructured":"Mantere M, Sailio M, Noponen S (2013) Network traffic features for anomaly detection in specific industrial control system network. Future Internet 5(4):460\u2013473. https:\/\/doi.org\/10.3390\/fi5040460","journal-title":"Future Internet"},{"key":"252_CR23","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jisa.2020.102535","volume":"54","author":"P Matou\u0161ek","year":"2020","unstructured":"Matousek P, Ry\u0161av\u1ef3 O, Gr\u00e9gr M, Havlena V (2020) Flow based monitoring of ics communication in the smart grid. J Inf Secur Appl 54:1\u201316. https:\/\/doi.org\/10.1016\/j.jisa.2020.102535","journal-title":"J Inf Secur Appl"},{"key":"252_CR24","doi-asserted-by":"publisher","unstructured":"Maynard P, McLaughlin K, Sezer S (2018) An open framework for deploying experimental scada testbed networks. In: 5th International symposium for ICS & SCADA cyber security research 2018, pp. 92\u2013101. https:\/\/doi.org\/10.14236\/ewic\/ICS2018.11","DOI":"10.14236\/ewic\/ICS2018.11"},{"issue":"3","key":"252_CR25","doi-asserted-by":"publisher","first-page":"1146","DOI":"10.3390\/smartcities4030061","volume":"4","author":"F Panagiotis","year":"2021","unstructured":"Panagiotis F, Taxiarxchis K, Georgios K, Maglaras L, Ferrag MA (2021) Intrusion detection in critical infrastructures: a literature review. Smart Cities 4(3):1146\u20131157. https:\/\/doi.org\/10.3390\/smartcities4030061","journal-title":"Smart Cities"},{"issue":"3","key":"252_CR26","doi-asserted-by":"publisher","first-page":"1942","DOI":"10.1109\/COMST.2020.2987688","volume":"22","author":"D Pliatsios","year":"2020","unstructured":"Pliatsios D, Sarigiannidis P, Lagkas T, Sarigiannidis AG (2020) A survey on SCADA systems: secure protocols, incidents, threats and tactics. IEEE Commun Surv Tutor 22(3):1942\u20131976. https:\/\/doi.org\/10.1109\/COMST.2020.2987688","journal-title":"IEEE Commun Surv Tutor"},{"key":"252_CR27","doi-asserted-by":"publisher","first-page":"113303","DOI":"10.1016\/j.dss.2020.113303","volume":"133","author":"T Pourhabibi","year":"2020","unstructured":"Pourhabibi T, Ong K-L, Kam BH, Boo YL (2020) Fraud detection: a systematic literature review of graph-based anomaly detection approaches. Decis Support Syst 133:113303. https:\/\/doi.org\/10.1016\/j.dss.2020.113303","journal-title":"Decis Support Syst"},{"key":"252_CR28","doi-asserted-by":"publisher","unstructured":"Radoglou-Grammatikis P, Sarigiannidis P, Giannoulakis I, Kafetzakis E, Panaousis E (2019) Attacking iec-60870-5-104 SCADA systems. In: IEEE World Congress on Services (SERVICES), IEEE, pp. 41\u201346. https:\/\/doi.org\/10.1109\/SERVICES.2019.00022","DOI":"10.1109\/SERVICES.2019.00022"},{"key":"252_CR29","doi-asserted-by":"publisher","first-page":"93083","DOI":"10.1109\/ACCESS.2020.2994961","volume":"8","author":"SVB Rakas","year":"2020","unstructured":"Rakas SVB, Stojanovi\u0107 MD, Markovi\u0107-Petrovi\u0107 JD (2020) A review of research work on network-based scada intrusion detection systems. IEEE Access 8:93083\u201393108. https:\/\/doi.org\/10.1109\/ACCESS.2020.2994961","journal-title":"IEEE Access"},{"key":"252_CR30","doi-asserted-by":"publisher","unstructured":"Robles-Durazno A, Moradpoor N, McWhinnie J, Russell G (2018) A supervised energy monitoring-based machine learning approach for anomaly detection in a clean water supply system. In: 2018 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), IEEE, pp. 1\u20138. https:\/\/doi.org\/10.1109\/CyberSecPODS.2018.8560683","DOI":"10.1109\/CyberSecPODS.2018.8560683"},{"key":"252_CR31","doi-asserted-by":"publisher","unstructured":"Sch\u00f6lkopf B, Williamson RC, Smola A, Shawe-Taylor J, Platt J (1999) Support vector method for novelty detection. In: 12th International conference on neural information processing systems (NIPS), pp. 582\u2013588. MIT Press, Colorado. https:\/\/doi.org\/10.5555\/3009657.3009740. https:\/\/proceedings.neurips.cc\/paper\/1999\/file\/8725fb777f25776ffa9076e44fcfd776-Paper.pdf","DOI":"10.5555\/3009657.3009740"},{"issue":"3","key":"252_CR32","doi-asserted-by":"publisher","first-page":"279","DOI":"10.4300\/JGME-D-12-00156.1","volume":"4","author":"GM Sullivan","year":"2012","unstructured":"Sullivan GM, Feinn R (2012) Using effect size-or why the p value is not enough. J Grad Med Educ 4(3):279\u2013282. https:\/\/doi.org\/10.4300\/JGME-D-12-00156.1","journal-title":"J Grad Med Educ"},{"key":"252_CR33","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1016\/j.procs.2019.08.086","volume":"155","author":"N Tariq","year":"2019","unstructured":"Tariq N, Asim M, Khan FA (2019) Securing scada-based critical infrastructures: challenges and open issues. Proc Comput Sci 155:612\u2013617. https:\/\/doi.org\/10.1016\/j.procs.2019.08.086","journal-title":"Proc Comput Sci"},{"key":"252_CR34","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-021-10037-9","author":"A Thakkar","year":"2021","unstructured":"Thakkar A, Lohiya R (2021) A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artif Intell Rev. https:\/\/doi.org\/10.1007\/s10462-021-10037-9","journal-title":"Artif Intell Rev"},{"issue":"10","key":"252_CR35","doi-asserted-by":"publisher","first-page":"11994","DOI":"10.1016\/j.eswa.2009.05.029","volume":"36","author":"C-F Tsai","year":"2009","unstructured":"Tsai C-F, Hsu Y-F, Lin C-Y, Lin W-Y (2009) Review: intrusion detection by machine learning: a review. Expert Syst Appl 36(10):11994\u201312000. https:\/\/doi.org\/10.1016\/j.eswa.2009.05.029","journal-title":"Expert Syst Appl"},{"key":"252_CR36","doi-asserted-by":"publisher","unstructured":"Udd R, Asplund M, Nadjm-Tehrani S, Kazemtabrizi M, Ekstedt M (2016) Exploiting bro for intrusion detection in a scada system. In: 2nd ACM international workshop on cyber-physical system security, pp. 44\u201351. ACM, Xian. https:\/\/doi.org\/10.1145\/2899015.2899028","DOI":"10.1145\/2899015.2899028"},{"key":"252_CR37","doi-asserted-by":"publisher","unstructured":"Wong K, Dillabaugh C, Seddigh N, Nandy B (2017) Enhancing suricata intrusion detection system for cyber security in SCADA networks. In: 2017 IEEE 30th Canadian Conference on Electrical and Computer Engineering (CCECE), IEEE, pp. 1\u20135. https:\/\/doi.org\/10.1109\/CCECE.2017.7946818","DOI":"10.1109\/CCECE.2017.7946818"},{"key":"252_CR38","doi-asserted-by":"publisher","unstructured":"Yang Y, McLaughlin K, Littler T, Sezer S, Pranggono B, Wang H (2013) Intrusion detection system for iec 60870-5-104 based scada networks. In: 2013 IEEE power & energy society general meeting, IEEE, pp. 1\u20135. https:\/\/doi.org\/10.1109\/PESMG.2013.6672100","DOI":"10.1109\/PESMG.2013.6672100"},{"issue":"2","key":"252_CR39","doi-asserted-by":"publisher","first-page":"1068","DOI":"10.1109\/TPWRD.2016.2603339","volume":"32","author":"Y Yang","year":"2016","unstructured":"Yang Y, Xu H-Q, Gao L, Yuan Y-B, McLaughlin K, Sezer S (2016) Multidimensional intrusion detection system for iec 61850-based scada networks. IEEE Trans Power Deliv 32(2):1068\u20131078. https:\/\/doi.org\/10.1109\/TPWRD.2016.2603339","journal-title":"IEEE Trans Power Deliv"},{"issue":"96","key":"252_CR40","first-page":"1","volume":"20","author":"Y Zhao","year":"2019","unstructured":"Zhao Y, Nasrullah Z, Li Z (2019) Pyod: a python toolbox for scalable outlier detection. J Mach Learn Res 20(96):1\u20137","journal-title":"J Mach Learn Res"},{"key":"252_CR41","doi-asserted-by":"publisher","unstructured":"Zhu B, Joseph A, Sastry S (2011) A taxonomy of cyber attacks on scada systems. In: 2011 International Conference on Internet of Things and 4th International Conference on Cyber, Physical and Social Computing, IEEE, pp. 380\u2013388. https:\/\/doi.org\/10.1109\/iThings\/CPSCom.2011.34","DOI":"10.1109\/iThings\/CPSCom.2011.34"}],"container-title":["Energy Informatics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42162-022-00252-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42162-022-00252-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42162-022-00252-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T10:04:36Z","timestamp":1671617076000},"score":1,"resource":{"primary":{"URL":"https:\/\/energyinformatics.springeropen.com\/articles\/10.1186\/s42162-022-00252-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,21]]},"references-count":41,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["252"],"URL":"https:\/\/doi.org\/10.1186\/s42162-022-00252-1","relation":{},"ISSN":["2520-8942"],"issn-type":[{"value":"2520-8942","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,21]]},"assertion":[{"value":"13 October 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 December 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 December 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"The authors declare that they have no competing interests.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"69"}}