1Viewes
Rancang Bangun Sistem Deteksi Intrusi Berbasis Machine Learning dan Akuisisi Bukti Digital Menggunakan Framework PLC-SEIFF untuk Mitigasi Serangan Stealth Injection pada Lingkungan OpenPLC
Repository Analytics
Statistic Details
0Downloaded
1Accessed per month
1Countries
Loading...
Date
Authors
Rhomadhon, Fuad Restu
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
Industrial Control Systems (ICS), particularly Programmable Logic Controllers (PLCs), are increasingly vulnerable to stealth program injection attacks that manipulate internal logic without altering physical outputs. Traditional networkbased intrusion detection systems often fail to identify these host-level anomalies, while reactive forensic approaches risk losing volatile memory evidence. This study proposes a novel cyber-physical defense mechanism integrating a Deep Isolation Forest (DIF) machine learning model with the PLC-SEIFF (Security Incident Forensics Framework) for automated digital evidence acquisition. Implemented on an OpenPLC v3 environment simulating a cyber-physical water tank, the DIF model analyzes raw execution time (scan cycle) and physical state correlations to detect logic hijacking via GDB hot-patching. During the internal evaluation phase, the proposed DIF model achieved an accuracy of 99.05% and an F1-Score of 0.9077. Furthermore, during the testing phase with unseen data, the model maintained a robust overall accuracy of 95.00% and a Macro Average F1-Score of 87.43%, successfully capturing all malicious intrusions (100% Recall for the anomaly class) with zero false negatives.Upon anomaly detection, the automated SEIFF integration rapidly acquired volatile memory dumps and network logs, revealing the injected hex payload (b0 01 90) and state inconsistencies as definitive forensic evidence. This research demonstrates a highly resilient, real-time intrusion detection and automated forensic solution for mitigating advanced cyber threats in modern ICS environments.
Description
Citation
IEEE
