{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/improving-siem-for-critical-scada-water","title":"Improving SIEM for Critical SCADA Water Infrastructures Using Machine Learning","arxiv_id":"1904.05724","date":"2019-03-06","proceeding":null,"authors":["Hanan Hindy","David Brosset","Ethan Bayne","Amar Seeam","Xavier Bellekens"],"abstract":"Network Control Systems (NAC) have been used in many industrial processes.\nThey aim to reduce the human factor burden and efficiently handle the complex\nprocess and communication of those systems. Supervisory control and data\nacquisition (SCADA) systems are used in industrial, infrastructure and facility\nprocesses (e.g. manufacturing, fabrication, oil and water pipelines, building\nventilation, etc.) Like other Internet of Things (IoT) implementations, SCADA\nsystems are vulnerable to cyber-attacks, therefore, a robust anomaly detection\nis a major requirement. However, having an accurate anomaly detection system is\nnot an easy task, due to the difficulty to differentiate between cyber-attacks\nand system internal failures (e.g. hardware failures). In this paper, we\npresent a model that detects anomaly events in a water system controlled by\nSCADA. Six Machine Learning techniques have been used in building and\nevaluating the model. The model classifies different anomaly events including\nhardware failures (e.g. sensor failures), sabotage and cyber-attacks (e.g. DoS\nand Spoofing). Unlike other detection systems, our proposed work focuses on\nnotifying the operator when an anomaly occurs with a probability of the event\noccurring. This additional information helps in accelerating the mitigation\nprocess. The model is trained and tested using a real-world dataset.","url_abs":"http://arxiv.org/abs/1904.05724v1","url_pdf":"http://arxiv.org/pdf/1904.05724v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"improving-siem-for-critical-scada-water","repo_url":"https://github.com/AbertayMachineLearningGroup/machine-learning-SIEM-water-infrastructure","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null}],"tasks":[{"task_slug":"anomaly-detection","task_name":"Anomaly Detection"},{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"cyber-attack-detection","task_name":"Cyber Attack Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}