Rancang Bangun Sistem Deteksi Intrusi Berbasis Machine Learning dan Akuisisi Bukti Digital Menggunakan Framework PLC-SEIFF untuk Mitigasi Serangan Stealth Injection pada Lingkungan OpenPLC

dc.contributor.advisorArif, Hamdani
dc.contributor.authorRhomadhon, Fuad Restu
dc.date.accessioned2026-08-14T07:31:19Z
dc.date.issued2026-07-20
dc.description.abstractIndustrial Control Systems (ICS), particularly Programmable Logic Controllers (PLCs), are increasingly vulnerable to stealth program injection attacks that manipulate internal logic without altering physical outputs. Traditional networkbased intrusion detection systems often fail to identify these host-level anomalies, while reactive forensic approaches risk losing volatile memory evidence. This study proposes a novel cyber-physical defense mechanism integrating a Deep Isolation Forest (DIF) machine learning model with the PLC-SEIFF (Security Incident Forensics Framework) for automated digital evidence acquisition. Implemented on an OpenPLC v3 environment simulating a cyber-physical water tank, the DIF model analyzes raw execution time (scan cycle) and physical state correlations to detect logic hijacking via GDB hot-patching. During the internal evaluation phase, the proposed DIF model achieved an accuracy of 99.05% and an F1-Score of 0.9077. Furthermore, during the testing phase with unseen data, the model maintained a robust overall accuracy of 95.00% and a Macro Average F1-Score of 87.43%, successfully capturing all malicious intrusions (100% Recall for the anomaly class) with zero false negatives.Upon anomaly detection, the automated SEIFF integration rapidly acquired volatile memory dumps and network logs, revealing the injected hex payload (b0 01 90) and state inconsistencies as definitive forensic evidence. This research demonstrates a highly resilient, real-time intrusion detection and automated forensic solution for mitigating advanced cyber threats in modern ICS environments.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN0001129002
dc.identifier.nimNIM4332201059
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5146
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectDeep Isolation Forest
dc.subjectDigital Forensics
dc.subjectIntrussion Detection System
dc.subjectOpenPLC
dc.subjectStealth Injection.
dc.titleRancang Bangun Sistem Deteksi Intrusi Berbasis Machine Learning dan Akuisisi Bukti Digital Menggunakan Framework PLC-SEIFF untuk Mitigasi Serangan Stealth Injection pada Lingkungan OpenPLC
dc.title.alternativeDESIGN OF A MACHINE LEARNING-BASED INTRUSION DETECTION SYSTEM AND DIGITAL EVIDENCE ACQUISITION USING THE PLC-SEIFF FRAMEWORK TO MITIGATE STEALTH INJECTION ATTACKS IN THE OPENPLC ENVIRONMENT
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332201059_Article.pdf
Size:
968.45 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Lembar_pengesahan.pdf
Size:
318.13 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
707.96 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: