{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T04:55:26Z","timestamp":1783400126122,"version":"3.54.6"},"reference-count":27,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>This article presents a statistical approach using entropy and classification-based analysis to detect anomalies in industrial control systems traffic. Several statistical techniques have been proposed to create baselines and measure deviation to detect intrusion in enterprise networks with a centralized intrusion detection approach in mind. Looking at traffic volume alone to find anomalous deviation may not be enough\u2014it may result in increased false positives. The near real-time communication requirements, coupled with the lack of centralized infrastructure in operations technology and limited resources of the sensor motes, require an efficient anomaly detection system characterized by these limitations. This paper presents extended results from our previous work by presenting a detailed cluster-based entropy analysis on selected network traffic features. It further extends the analysis using a classification-based approach. Our detailed entropy analysis corroborates with our earlier findings that, although some degree of anomaly may be detected using univariate and bivariate entropy analysis for Denial of Service (DOS) and Man-in-the-Middle (MITM) attacks, not much information may be obtained for the initial reconnaissance, thus preventing early stages of attack detection in the Cyber Kill Chain. Our classification-based analysis shows that, overall, the classification results of the DOS attacks were much higher than the MITM attacks using two Modbus features in addition to the three TCP\/IP features. In terms of classifiers, J48 and random forest had the best classification results and can be considered comparable. For the DOS attack, no resampling with the 60\u201340 (training\/testing split) had the best results (average accuracy of 97.87%), but for the MITM attack, the 80\u201320 non-attack vs. attack data with the 75\u201325 split (average accuracy of 82.81%) had the best results.<\/jats:p>","DOI":"10.3390\/jcp3040041","type":"journal-article","created":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T04:12:56Z","timestamp":1701403976000},"page":"895-913","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["Anomaly Detection for Modbus over TCP in Control Systems Using Entropy and Classification-Based Analysis"],"prefix":"10.3390","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1914-711X","authenticated-orcid":false,"given":"Tirthankar","family":"Ghosh","sequence":"first","affiliation":[{"name":"Department of Electrical & Computer Engineering and Computer Science, University of New Haven, West Haven, CT 06516, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1886-4582","authenticated-orcid":false,"given":"Sikha","family":"Bagui","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of West Florida, Pensacola, FL 32514, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6140-5384","authenticated-orcid":false,"given":"Subhash","family":"Bagui","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Statistics, University of West Florida, Pensacola, FL 32514, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Kadzis","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of West Florida, Pensacola, FL 32514, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jackson","family":"Bare","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of West Florida, Pensacola, FL 32514, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,12,1]]},"reference":[{"key":"ref_1","unstructured":"Cardenas, A., Amin, S., Sinopoli, B., Giani, A., Perrig, A., and Sastry, S. (2009, January 22\u201324). Challenges for Securing Cyber Physical Systems. Proceedings of the Workshop in Cyber Physical Systems, Newark, NJ, USA."},{"key":"ref_2","unstructured":"Angseus, J., and Ekbom, R. (2017). Network-Based Intrusion Detection Systems for Industrial Control Systems. [Master\u2019s Thesis, Computer Science, Chalmers University of Technology]."},{"key":"ref_3","unstructured":"Koucham, O. (2018). Intrusion Detection for Industrial Control Systems. [Ph.D. Dissertation, Universite Grenoble Aples]. Available online: https:\/\/theses.hal.science\/tel-02108208\/file\/KOUCHAM_2018_diffusion.pdf."},{"key":"ref_4","first-page":"441","article-title":"Industrial Control System Traffic Data Sets for Intrusion Detection Research","volume":"Volume 441","author":"Butts","year":"2014","journal-title":"Critical Infrastructure Protection VIII, Proceedings of the ICCIP 2014, IFIP Advances in Information and Communication Technology, Arlington, VA, USA, 17\u201319 March 2014"},{"key":"ref_5","unstructured":"Bouckaert, R. (2004). Bayesian Network Classifiers in Weka, University of Waikato, Department of Computer Science."},{"key":"ref_6","unstructured":"Han, J., Kamber, M., and Pei, J. (2011). Data Mining: Concepts and Techniques, Morgan Kaufmann Publishers. [3rd ed.]."},{"key":"ref_7","unstructured":"Hussain, Y. (2020). Network Intrusion Detection for Distributed Denial of Service (DDoS) Attacks using Machine Learning Classification Techniques. [Master\u2019s Thesis, University of Victoria]."},{"key":"ref_8","first-page":"1459","article-title":"Performance Evaluation By Artificial Neural Network Using WEKA","volume":"3","author":"Sebastian","year":"2016","journal-title":"Int. Res. J. Eng. Technol."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Almseidin, M., Alzubi, M., Kovacs, S., and Alkasassbeh, M. (2017, January 14\u201316). Evaluation of machine learning algorithms for intrusion detection system. Proceedings of the 2017 IEEE 15th International Symposium on Intelligent Systems and Informatics (SISY), Subotica, Serbia.","DOI":"10.1109\/SISY.2017.8080566"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"tyab006","DOI":"10.1093\/cybsec\/tyab006","article-title":"A three-tiered intrusion detection system for industrial control systems","volume":"7","author":"Anthi","year":"2021","journal-title":"J. Cybersecur."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Caselli, M., Zambon, E., and Kargl, F. (2015, January 14). Sequence-aware intrusion detection in industrial control systems. Proceedings of the 1st ACM Workshop on Cyber-Physical System Security, Singapore.","DOI":"10.1145\/2732198.2732200"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Eigner, O., Kreimel, P., and Tavolato, P. (2018, January 22\u201324). Attacks on Industrial Control Systems\u2014Modeling and Anomaly Detection. Proceedings of the 4th International Conference on Information Systems Security and Privacy, Madeira, Portugal.","DOI":"10.5220\/0006755405810588"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Feng, C., Li, T., and Chana, D. (2017, January 26\u201329). Multi-level anomaly detection in industrial control systems via package signatures and LSTM networks. Proceedings of the 2017 47th IEEE International Conference on Dependable Systems and Networks, Denver, CO, USA.","DOI":"10.1109\/DSN.2017.34"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Goh, J., Adepu, S., Tan, M., and Lee, Z.S. (2017, January 12\u201314). Anomaly Detection in Cyber Physical Systems Using Recurrent Neural Networks. Proceedings of the 2017 IEEE 18th International Symposium on High Assurance Systems Engineering (HASE), Singapore.","DOI":"10.1109\/HASE.2017.36"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Valdes, A., and Cheung, S. (2009, January 11\u201312). Communication pattern anomaly detection in process control systems. Proceedings of the 2009 IEEE Conference on Technologies for Homeland Security, Waltham, MA, USA.","DOI":"10.1109\/THS.2009.5168010"},{"key":"ref_16","unstructured":"Yang, D., Usynin, A., and Hines, J. (2006, January 12\u201316). Anomaly-Based Intrusion Detection for SCADA Systems. Proceedings of the 5th International Topical Meeting on Nuclear Plant Instrumentation Controls and Human Machine Interface Technology, Albuquerque, NM, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Almalawi, A., Fahad, A., Tari, Z., Khan, A.I., Alzahrani, N., Bakhsh, S.T., Alassafi, M.O., Alshdadi, A., and Qaiyum, S. (2020). Add-On Anomaly Threshold Technique for Improving Unsupervised Intrusion Detection on SCADA Data. Electronics, 9.","DOI":"10.3390\/electronics9061017"},{"key":"ref_18","unstructured":"Lee, W., and Xiang, D. (2001, January 14\u201316). Information-Theoretic Measures for Anomaly Detection. Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, USA."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ping, D., and Abe, S. (2007, January 10\u201313). Detecting DoS attacks using packet size distribution. Proceedings of the Bio-Inspired Models of Networks, Information and Computing Systems (Bionetics \u201907), Budapest, Hungary.","DOI":"10.1109\/BIMNICS.2007.4610090"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Nychis, G., Sekar, V., Anderson, D.G., Kim, H., and Zhang, H. (2008, January 20\u201322). An Empirical Evaluation of Entropy-based Traffic Anomaly Detection. Proceedings of the 8th ACM SIGCOMM Conference on Internet Measurement, Vouliagmeni, Greece.","DOI":"10.1145\/1452520.1452539"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Al-Haidari, F., Sqalli, M., Salah, K., and Hamodi, J. (2009, January 20\u201322). An Entropy-based Countermeasure against Intelligent DoS Attacks Targeting Firewalls. In Proceeding of the 10th IEEE International conference on Policies for Distributed Systems and Networks, London, UK.","DOI":"10.1109\/POLICY.2009.14"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"2367","DOI":"10.3390\/e17042367","article-title":"An Entropy-Based Network Anomaly Detection Method","volume":"17","author":"Jasiul","year":"2015","journal-title":"Entropy"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"567","DOI":"10.1002\/sec.575","article-title":"Classifying malicious activities in Honeynets using entropy and volume-based thresholds","volume":"6","author":"Squali","year":"2012","journal-title":"Secur. Commun. Netw."},{"key":"ref_24","first-page":"173","article-title":"Univariate and Bivariate Entropy Analysis for Modbus Traffic over TCP\/IP in Industrial Control Systems","volume":"29","author":"Ghosh","year":"2022","journal-title":"Int. J. Comput. Appl."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Drias, Z., Serhrouchni, A., and Vogel, O. (2015, January 22\u201324). Taxonomy of attacks on industrial control protocols. Proceedings of the 2015 International Conference on Protocol Engineering (ICPE) and International Conference on New Technologies of Distributed Systems (NTDS), Paris, France.","DOI":"10.1109\/NOTERE.2015.7293513"},{"key":"ref_26","first-page":"16","article-title":"Guide to industrial control systems (ICS) security","volume":"800","author":"Stouffer","year":"2011","journal-title":"NIST Spec. Publ."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1007\/s41664-018-0068-2","article-title":"On Splitting Training and Validation Set: A Comparative Study of Cross-Validation, Bootstrap and Systematic Sampling for Estimating the Generalization Performance of Supervised Learning","volume":"2","author":"Xu","year":"2018","journal-title":"J. Anal. Test."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/4\/41\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:35:49Z","timestamp":1760132149000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/3\/4\/41"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,1]]},"references-count":27,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["jcp3040041"],"URL":"https:\/\/doi.org\/10.3390\/jcp3040041","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,1]]}}}