{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T05:49:09Z","timestamp":1774590549332,"version":"3.50.1"},"reference-count":25,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2013,9,25]],"date-time":"2013-09-25T00:00:00Z","timestamp":1380067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/3.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The deterministic and restricted nature of industrial control system networks sets them apart from more open networks, such as local area networks in office environments. This improves the usability of network security, monitoring approaches that would be less feasible in more open environments. One of such approaches is machine learning based anomaly detection. Without proper customization for the special requirements of the industrial control system network environment, many existing anomaly or misuse detection systems will perform sub-optimally. A machine learning based approach could reduce the amount of manual customization required for different industrial control system networks. In this paper we analyze a possible set of features to be used in a machine learning based anomaly detection system in the real world industrial control system network environment under investigation. The network under investigation is represented by architectural drawing and results derived from network trace analysis. The network trace is captured from a live running industrial process control network and includes both control data and the data flowing between the control network and the office network. We limit the investigation to the IP traffic in the traces.<\/jats:p>","DOI":"10.3390\/fi5040460","type":"journal-article","created":{"date-parts":[[2013,9,25]],"date-time":"2013-09-25T12:47:40Z","timestamp":1380113260000},"page":"460-473","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":48,"title":["Network Traffic Features for Anomaly Detection in Specific Industrial Control System Network"],"prefix":"10.3390","volume":"5","author":[{"given":"Matti","family":"Mantere","sequence":"first","affiliation":[{"name":"VTT Technical Research Centre of Finland, Kaitovayla 1, Oulu 90571, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mirko","family":"Sailio","sequence":"additional","affiliation":[{"name":"VTT Technical Research Centre of Finland, Kaitovayla 1, Oulu 90571, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sami","family":"Noponen","sequence":"additional","affiliation":[{"name":"VTT Technical Research Centre of Finland, Kaitovayla 1, Oulu 90571, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2013,9,25]]},"reference":[{"key":"ref_1","unstructured":"The U.S. Department of Homeland Security (DHS) and Division\u2019s Control Systems Security Program (CSSP) (2011). Common Cybersecurity Vulnerabilities in Industrial Control Systems."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mantere, M., Uusitalo, I., Sailio, M., and Noponen, S. (2012, January 26\u201329). Challenges of Machine Learning Based Monitoring for Industrial Control System Networks. Proceedings of the 26th International Conference on Advanced Information Networking and Applications Workshops, Fukuoka, Japan.","DOI":"10.1109\/WAINA.2012.135"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Mantere, M., Sailio, M., and Noponen, S. (2012, January 20\u201323). Feature Selection for Machine Learning Based Anomaly Detection in Industrial Control System Networks. Proceedings of the 2nd Workshop on Security of Systems and Software Resiliency, IEEE Computer Society, Besancon, France.","DOI":"10.1109\/GreenCom.2012.127"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"222","DOI":"10.1109\/TSE.1987.232894","article-title":"An intrusion-detection model","volume":"SE-13","author":"Denning","year":"1987","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_5","unstructured":"Heberlein, L., Dias, G., Levitt, K., Mukherjee, B., Wood, J., and Wolber, D. (1990). IEEE Computer Society Symposium on Research in Security and Privacy 1990, IEEE Computer Society."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","article-title":"Anomaly-based network intrusion detection: Techniques, systems and challenges","volume":"28","author":"Vazquez","year":"2009","journal-title":"Comput. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Sommer, R., and Paxson, V. (2010, January 16\u201319). Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. Proceedings of the 2010 IEEE Symposium on Security and Privacy (SP), Oakland, CA, USA.","DOI":"10.1109\/SP.2010.25"},{"key":"ref_8","unstructured":"Cheung, S., Dutertre, B., Fong, M., Lindqvist, U., Skinner, K., and Valdes, A. (2007, January 24\u201325). Using Model-based Intrusion Detection for SCADA Networks. Proceedings of the SCADA Security Scientific Symposium, Miami, FL, USA."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Hadeli, H., Schierholz, R., Braendle, M., and Tuduce, C. (2009, January 22\u201325). Leveraging Determinism in Industrial Control Systems for Advanced Anomaly Detection and Reliable Security Configuration. Proceedings of the IEEE Conference on Emerging Technologies and Factory Automation (ETFA 2009), Mallorca.","DOI":"10.1109\/ETFA.2009.5347134"},{"key":"ref_10","unstructured":"Yang, D., Usynin, A., and Hines, J.W. (2006, January 12\u201316). Anomaly-Based Intrusion Detection for SCADA Systems. Proceedings of the 5th International Topical Meeting on Nuclear Plant Instrumentation, Control and Human Machine Interface Technologies (NPIC&HMIT 05), Albuquerque, NM, USA."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Linda, O., Vollmer, T., and Manic, M. (2009, January 14\u201319). Neural Network Based Intrusion Detection System for Critical Infrastructures. Proceedings of International Joint Conference on Neural Networks, Atlanta, GA, USA.","DOI":"10.1109\/IJCNN.2009.5178592"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Briesemeister, L., Cheung, S., Lindqvist, U., and Valdes, A. (2010, January 17\u201319). Detection, Correlation, and Visualization of Attacks Against Critical Infrastructure Systems. Proceedings of the 2010 Eighth Annual International Conference on Privacy Security and Trust (PST), Ottawa, Canada.","DOI":"10.1109\/PST.2010.5593242"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Chen, H., Clark, J., Shaikh, S., Chivers, H., and Nobles, P. (2010, January 15\u201318). Optimising IDS Sensor Placement. Proceedings of the ARES 10 International Conference on Availability, Reliability, and Security, Krakow, Poland.","DOI":"10.1109\/ARES.2010.92"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Ramadas, M., Ostermann, S., and Tjaden, B. (2003, January 8\u201310). Detecting Anomalous Network Traffic with Self-Organizing Maps. Proceedings of the Sixth International Symposium on Recent Advances in Intrusion Detection, LNCS, Pittsburgh, PA, USA.","DOI":"10.1007\/978-3-540-45248-5_3"},{"key":"ref_15","unstructured":"Valdes, A., and Cheung, S. (2009, January 5\u20138). Intrusion Monitoring in Process Control Systems. Proceedings of the 42nd Annual Hawaii International Conference on System Sciences HICSS, Big Island, HI, USA."},{"key":"ref_16","unstructured":"Morris, T., Vaughn, R., and Dandass, Y. (2010, January 4\u20137). A Retrofit Intrusion Detection System for MODBUS RTU and ASCII Industrial Control Systems. Proceedings of the 45th Hawaii International Conference on System Sciences, Maui, HI, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Bertoluzzo, M., Buja, G., and Vitturi, S. (2002, January 8\u201311). Ethernet Networks for Factory Automation. Proceedings of the 2002 IEEE International Symposium on Industrial Electronics ISIE 2002, L\u2019Aquila, Italy.","DOI":"10.1109\/ISIE.2002.1026061"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Gaderer, G., Sauter, T., Ring, F., and Nagy, A. (2010, January 1\u20134). A Novel, Wireless Sensor\/actuator Network for the Factory Floor. Proceedings of the 2010 IEEE Sensors, Waikoloa, HI, USA.","DOI":"10.1109\/ICSENS.2010.5690900"},{"key":"ref_19","unstructured":"Wireshark Protocol Analyzer. Available online: http:\/\/www.wireshark.org\/."},{"key":"ref_20","unstructured":"Tcpdump. Available online: http:\/\/www.tcpdump.org\/."},{"key":"ref_21","unstructured":"Bro Network Security Monitor. Available online: http:\/\/www.bro-ids.org\/."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","article-title":"Bro: A system for detecting network intruders in real-time","volume":"31","author":"Paxson","year":"1999","journal-title":"Comput. Netw."},{"key":"ref_23","unstructured":"NetMate-flowcalc. Available online: http:\/\/dan.arndt.ca\/projects\/netmate-flowcalc\/."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kohonen, T. (2001). Self-Organizing Maps, Springer-Verlag Inc.. [3rd ed.].","DOI":"10.1007\/978-3-642-56927-2"},{"key":"ref_25","unstructured":"DIAMONDS Project. Available online: http:\/\/www.itea2-diamonds.org\/index.html."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/5\/4\/460\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T21:49:32Z","timestamp":1760219372000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/5\/4\/460"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,9,25]]},"references-count":25,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2013,12]]}},"alternative-id":["fi5040460"],"URL":"https:\/\/doi.org\/10.3390\/fi5040460","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,9,25]]}}}