{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T08:44:29Z","timestamp":1780044269787,"version":"3.53.1"},"reference-count":46,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2020,9,23]],"date-time":"2020-09-23T00:00:00Z","timestamp":1600819200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Industrial Control Systems (ICSs) are widely used in critical infrastructures to support the essential services of society. Therefore, their protection against terrorist activities, natural disasters, and cyber threats is critical. Diverse cyber attack detection systems have been proposed over the years, in which each proposal has applied different steps and methods. However, there is a significant gap in the literature regarding methodologies to detect cyber attacks in ICS scenarios. The lack of such methodologies prevents researchers from being able to accurately compare proposals and results. In this work, we present a Methodology for Anomaly Detection in Industrial Control Systems (MADICS) to detect cyber attacks in ICS scenarios, which is intended to provide a guideline for future works in the field. MADICS is based on a semi-supervised anomaly detection paradigm and makes use of deep learning algorithms to model ICS behaviors. It consists of five main steps, focused on pre-processing the dataset to be used with the machine learning and deep learning algorithms; performing feature filtering to remove those features that do not meet the requirements; feature extraction processes to obtain higher order features; selecting, fine-tuning, and training the most appropriate model; and validating the model performance. In order to validate MADICS, we used the popular Secure Water Treatment (SWaT) dataset, which was collected from a fully operational water treatment plant. The experiments demonstrate that, using MADICS, we can achieve a state-of-the-art precision of 0.984 (as well as a recall of 0.750 and F1-score of 0.851), which is above the average of other works, proving that the proposed methodology is suitable for use in real ICS scenarios.<\/jats:p>","DOI":"10.3390\/sym12101583","type":"journal-article","created":{"date-parts":[[2020,9,24]],"date-time":"2020-09-24T03:03:39Z","timestamp":1600916619000},"page":"1583","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":64,"title":["MADICS: A Methodology for Anomaly Detection in Industrial Control Systems"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1004-881X","authenticated-orcid":false,"given":"\u00c1ngel Luis","family":"Perales G\u00f3mez","sequence":"first","affiliation":[{"name":"Departamento de Ingenier\u00eda y Tecnolog\u00eda de Computadores, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-4239","authenticated-orcid":false,"given":"Lorenzo","family":"Fern\u00e1ndez Maim\u00f3","sequence":"additional","affiliation":[{"name":"Departamento de Ingenier\u00eda y Tecnolog\u00eda de Computadores, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7125-1710","authenticated-orcid":false,"given":"Alberto","family":"Huertas Celdr\u00e1n","sequence":"additional","affiliation":[{"name":"Telecommunications Software &amp; Systems Group, Waterford Institute of Technology, X91 P20H Waterford, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6181-5033","authenticated-orcid":false,"given":"F\u00e9lix J.","family":"Garc\u00eda Clemente","sequence":"additional","affiliation":[{"name":"Departamento de Ingenier\u00eda y Tecnolog\u00eda de Computadores, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,9,23]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"6472","DOI":"10.1109\/TII.2019.2917693","article-title":"Cyber-physical security design in multimedia data cache resource allocation for industrial networks","volume":"15","author":"Jiang","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Miller, B., and Rowe, D. (2012, January 11\u201313). A survey SCADA of and critical infrastructure incidents. Proceedings of the 1st Annual Conference on Research in Information Technology, Calgary, AB, Canada.","DOI":"10.1145\/2380790.2380805"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"418","DOI":"10.1016\/j.cose.2012.02.009","article-title":"SCADA security in the light of Cyber-Warfare","volume":"31","author":"Nicholson","year":"2012","journal-title":"Comput. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Hemsley, K.E., Fisher, E., and Ronald, D. (2018). History of Industrial Control System Cyber Incidents.","DOI":"10.2172\/1505628"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Karnouskos, S. (2011, January 7\u201310). Stuxnet worm impact on industrial cyber-physical system security. Proceedings of the IECON 2011 37th Annual Conference of the IEEE Industrial Electronics Society, Melbourne, Australia.","DOI":"10.1109\/IECON.2011.6120048"},{"key":"ref_6","unstructured":"Kumar, M. (The Hacker News, 2016). Irongate new stuxnet-like malware targets industrial control systems, The Hacker News."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Fan, X., Fan, K., Wang, Y., and Zhou, R. (2015, January 5\u20137). Overview of cyber-security of industrial control system. Proceedings of the 2015 International Conference on Cyber Security of Smart Cities, Industrial Control System and Communications (SSIC), Shanghai, China.","DOI":"10.1109\/SSIC.2015.7245324"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Jie, P., and Li, L. (2011, January 26\u201327). Industrial Control System Security. Proceedings of the 2011 Third International Conference on Intelligent Human-Machine Systems and Cybernetics, Hangzhou, China.","DOI":"10.1109\/IHMSC.2011.108"},{"key":"ref_9","unstructured":"Pillitteri, V.Y., and Brewer, T.L. (2014). Guidelines for Smart Grid Cybersecurity."},{"key":"ref_10","unstructured":"Van, N.T., Thinh, T.N., and Sach, L.T. (2017, January 21\u201323). An anomaly-based network intrusion detection system using Deep learning. Proceedings of the 2017 International Conference on System Science and Engineering (ICSSE), Ho Chi Minh City, Vietnam."},{"key":"ref_11","unstructured":"Zitta, T., Neruda, M., Vojtech, L., Matejkova, M., Jehlicka, M., Hach, L., and Moravec, J. (2018, January 5\u20137). Penetration Testing of Intrusion Detection and Prevention System in Low-Performance Embedded IoT Device. Proceedings of the 2018 18th International Conference on Mechatronics-Mechatronika (ME), Brno, Czech Republic."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"7700","DOI":"10.1109\/ACCESS.2018.2803446","article-title":"A Self-Adaptive Deep Learning-Based System for Anomaly Detection in 5G Networks","volume":"6","year":"2018","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"3083","DOI":"10.1007\/s12652-018-0813-4","article-title":"Dynamic management of a deep learning-based anomaly detection system for 5G networks","volume":"10","year":"2019","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Fern\u00e1ndez Maim\u00f3, L., Huertas Celdr\u00e1n, A., Perales G\u00f3mez, A.L., Garc\u00eda Clemente, F.J., Weimer, J., and Lee, I. (2019). Intelligent and dynamic ransomware spread detection and mitigation in integrated clinical environments. Sensors, 19.","DOI":"10.3390\/s19051114"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Havarneanu, G., Setola, R., Nassopoulos, H., and Wolthusen, S. (2017). A Dataset to Support Research in the Design of Secure Water Treatment Systems. Critical Information Infrastructures Security, Springer International Publishing.","DOI":"10.1007\/978-3-319-71368-7"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Silhavy, R., Senkerik, R., Oplatkova, Z.K., Silhavy, P., and Prokopova, Z. (2016). Comparison of the Intrusion Detection System Rules in Relation with the SCADA Systems. Software Engineering Perspectives and Application in Intelligent Systems, Springer International Publishing.","DOI":"10.1007\/978-3-319-33622-0"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Yang, Y., McLaughlin, K., Littler, T., Sezer, S., and Wang, H. (2013). Rule-based intrusion detection system for SCADA networks. IET Conf. Proc., 1\u20134.","DOI":"10.1049\/cp.2013.1729"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1254","DOI":"10.1109\/TSG.2013.2258948","article-title":"Behavior-Rule Based Intrusion Detection Systems for Safety Critical Smart Grid Applications","volume":"4","author":"Mitchell","year":"2013","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_19","unstructured":"Rome, E., Theocharidou, M., and Wolthusen, S. (2016). A Statechart-Based Anomaly Detection Model for Multi-Threaded SCADA Systems. Critical Information Infrastructures Security, Springer International Publishing."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"103177","DOI":"10.1016\/j.compind.2019.103177","article-title":"Model-based vehicular prognostics framework using Big Data architecture","volume":"115","author":"Petrillo","year":"2020","journal-title":"Comput. Ind."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"83842","DOI":"10.1109\/ACCESS.2020.2976745","article-title":"Machine Learning Methods for Industrial Protocol Security Analysis: Issues, Taxonomy, and Directions","volume":"8","author":"Men","year":"2020","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Kravchik, M., and Shabtai, A. Detecting Cyber Attacks in Industrial Control Systems Using Convolutional Neural Networks. Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy.","DOI":"10.1145\/3264888.3264896"},{"key":"ref_23","unstructured":"Shalyga, D., Filonov, P., and Lavrentyev, A. (2018). Anomaly detection for water treatment system based on neural network with automatic architecture optimization. arXiv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Lavin, A., and Ahmad, S. (2015, January 9\u201311). Evaluating Real-Time Anomaly Detection Algorithms\u2014The Numenta Anomaly Benchmark. Proceedings of the 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA), Miami, FL, USA.","DOI":"10.1109\/ICMLA.2015.141"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Zizzo, G., Hankin, C., Maffeis, S., and Jones, K. (2019). Intrusion Detection for Industrial Control Systems: Evaluation Analysis and Adversarial Attacks. arXiv.","DOI":"10.1109\/TrustCom50675.2020.00121"},{"key":"ref_26","unstructured":"Tetko, I.V., K\u016frkov\u00e1, V., Karpov, P., and Theis, F. (2019). MAD-GAN: Multivariate Anomaly Detection for Time Series Data with Generative Adversarial Networks. Artificial Neural Networks and Machine Learning\u2014ICANN 2019: Text and Time Series, Springer International Publishing."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kim, J., Yun, J.H., and Kim, H.C. (2019). Anomaly detection for industrial control systems using sequence-to-sequence neural networks. arXiv.","DOI":"10.1007\/978-3-030-42048-2_1"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Inoue, J., Yamagata, Y., Chen, Y., Poskitt, C.M., and Sun, J. (2017, January 18\u201321). Anomaly Detection for a Water Treatment System Using Unsupervised Machine Learning. Proceedings of the 2017 IEEE International Conference on Data Mining Workshops (ICDMW), New Orleans, LA, USA.","DOI":"10.1109\/ICDMW.2017.149"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kravchik, M., and Shabtai, A. (2019). Efficient cyber attacks detection in industrial control systems using lightweight neural networks. arXiv.","DOI":"10.1145\/3264888.3264896"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Liu, L., Hu, M., Kang, C., and Li, X. (2020). Unsupervised Anomaly Detection for Network Data Streams in Industrial Control Systems. Information, 11.","DOI":"10.3390\/info11020105"},{"key":"ref_31","unstructured":"Tomlin, L., Farnam, M.R., and Pan, S. (2016, January 30). A clustering approach to industrial network intrusion detection. Proceedings of the 2016 Information Security Research and Education (INSuRE) Conference (INSuRECon-16), University of Alabama in Huntsville, Huntsville, AL, USA."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Schneider, P., and B\u00f6ttinger, K. (2018, January 19). High-performance unsupervised anomaly detection for cyber-physical system networks. Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy, Toronto, ON, Canada.","DOI":"10.1145\/3264888.3264890"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"36639","DOI":"10.1109\/ACCESS.2020.2975066","article-title":"A Dual-Isolation-Forests-Based Attack Detection Framework for Industrial Control Systems","volume":"8","author":"Elnour","year":"2020","journal-title":"IEEE Access"},{"key":"ref_34","unstructured":"Khan, A.A.Z. (August, January 29). Misuse Intrusion Detection Using Machine Learning for Gas Pipeline SCADA Networks. Proceedings of the International Conference on Security and Management (SAM), Las Vegas, NV, USA."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Alhaidari, F.A., and AL-Dahasi, E.M. (2019, January 3\u20134). New Approach to Determine DDoS Attack Patterns on SCADA System Using Machine Learning. Proceedings of the 2019 International Conference on Computer and Information Sciences (ICCIS), Sakaka, Saudi Arabia.","DOI":"10.1109\/ICCISci.2019.8716432"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"177460","DOI":"10.1109\/ACCESS.2019.2958284","article-title":"On the Generation of Anomaly Detection Datasets in Industrial Control Systems","volume":"7","year":"2019","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1080\/17538947.2016.1209583","article-title":"A domain-independent methodology to analyze IoT data streams in real-time. A proof of concept implementation for anomaly detection from environmental data","volume":"10","author":"Trilles","year":"2017","journal-title":"Int. J. Digit. Earth"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"e2012","DOI":"10.1002\/stc.2012","article-title":"Early detection of anomalies in dam performance: A methodology based on boosted regression trees","volume":"24","author":"Salazar","year":"2017","journal-title":"Struct. Control Health Monit."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Pinelli, M., Venturini, M., and Burgio, M. (2003). Statistical methodologies for reliability assessment of gas turbine measurements. ASME Turbo Expo 2003, Collocated with the 2003 International Joint Power Generation Conference, American Society of Mechanical Engineers Digital Collection.","DOI":"10.1115\/GT2003-38407"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Fabio Ceschini, G., Gatta, N., Venturini, M., Hubauer, T., and Murarasu, A. (2017). Optimization of Statistical Methodologies for Anomaly Detection in Gas Turbine Dynamic Time Series. J. Eng. Gas Turbines Power, 140.","DOI":"10.1115\/1.4037963"},{"key":"ref_41","first-page":"73","article-title":"A case study on partitioning data for classification","volume":"8","author":"Sarkar","year":"2016","journal-title":"Int. J. Inf. Decis. Sci."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Russac, Y., Caelen, O., and He-Guelton, L. (2018). Embeddings of categorical variables for sequential data in fraud context. International Conference on Advanced Machine Learning Technologies and Applications, Springer.","DOI":"10.1007\/978-3-319-74690-6_53"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1109\/MCSE.2007.55","article-title":"Matplotlib: A 2D graphics environment","volume":"9","author":"Hunter","year":"2007","journal-title":"Comput. Sci. Eng."},{"key":"ref_44","unstructured":"Waskom, M., Botvinnik, O., Ostblom, J., Lukauskas, S., Hobson, P., Gelbart, M., Gemperline, D.C., Augspurger, T., Halchenko, Y., and Cole, J.B. (2020, September 15). mwaskom\/seaborn: V0.8.1 (September 2017). Available online: https:\/\/github.com\/mwaskom\/seaborn."},{"key":"ref_45","unstructured":"Abadi, M., Agarwal, A., Barham, P., Brevdo, E., Chen, Z., Citro, C., Corrado, G.S., Davis, A., Dean, J., and Devin, M. (2016). Tensorflow: Large-scale machine learning on heterogeneous distributed systems. arXiv."},{"key":"ref_46","unstructured":"Chollet, F. (2020, September 15). Keras. Available online: https:\/\/keras.io."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/12\/10\/1583\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:12:52Z","timestamp":1760177572000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/12\/10\/1583"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,23]]},"references-count":46,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2020,10]]}},"alternative-id":["sym12101583"],"URL":"https:\/\/doi.org\/10.3390\/sym12101583","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,23]]}}}