The effect of dataset imbalance on the performance of SCADA intrusion detection systems

Integrating IoT devices in SCADA systems has provided efficient and improved data collection and transmission technologies. This enhancement comes with significant security challenges, exposing traditionally isolated systems to the public internet. Effective and highly reliable security devices, su...

Full description

Saved in:
Bibliographic Details
Main Authors: Balla, Asaad, Habaebi, Mohamed Hadi, Elsheikh, Elfatih A. A., Islam, Md. Rafiqul, Suliman, F.M.
Format: Article
Language:English
English
English
Published: Multidisciplinary Digital Publishing Institute (MDPI) 2023
Subjects:
Online Access:http://irep.iium.edu.my/103118/2/103118_The%20effect%20of%20dataset%20imbalance.pdf
http://irep.iium.edu.my/103118/3/103118_The%20effect%20of%20dataset%20imbalance_WOS.pdf
http://irep.iium.edu.my/103118/14/103118_The%20effect%20of%20dataset%20imbalance%20_Scopus.pdf
http://irep.iium.edu.my/103118/
https://www.mdpi.com/1424-8220/23/2/758/pdf?version=1673268094
https://doi.org/10.3390/s23020758
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Islam Antarabangsa Malaysia
Language: English
English
English
Description
Summary:Integrating IoT devices in SCADA systems has provided efficient and improved data collection and transmission technologies. This enhancement comes with significant security challenges, exposing traditionally isolated systems to the public internet. Effective and highly reliable security devices, such as intrusion detection system (IDSs) and intrusion prevention systems (IPS), are critical. Countless studies used deep learning algorithms to design an efficient IDS; however, the fundamental issue of imbalanced datasets was not fully addressed. In our research, we examined the impact of data imbalance on developing an effective SCADA-based IDS. To investigate the impact of various data balancing techniques, we chose two unbalanced datasets, the Morris power dataset, and CICIDS2017 dataset, including random sampling, one-sided selection (OSS), near-miss, SMOTE, and ADASYN. For binary classification, convolutional neural networks were coupled with long short-term memory (CNN-LSTM). The system’s effectiveness was determined by the confusion matrix, which includes evaluation metrics, such as accuracy, precision, detection rate, and F1-score. Four experiments on the two datasets demonstrate the impact of the data imbalance. This research aims to help security researchers in understanding imbalanced datasets and their impact on DL SCADA-IDS.