Rancang Bangun Sistem Deteksi Intrusi Berbasis Machine Learning dan Akuisisi Bukti Digital Menggunakan Framework PLC-SEIFF untuk Mitigasi Serangan Stealth Injection pada Lingkungan OpenPLC
| dc.contributor.advisor | Arif, Hamdani | |
| dc.contributor.author | Rhomadhon, Fuad Restu | |
| dc.date.accessioned | 2026-08-14T07:31:19Z | |
| dc.date.issued | 2026-07-20 | |
| dc.description.abstract | Industrial Control Systems (ICS), particularly Programmable Logic Controllers (PLCs), are increasingly vulnerable to stealth program injection attacks that manipulate internal logic without altering physical outputs. Traditional networkbased intrusion detection systems often fail to identify these host-level anomalies, while reactive forensic approaches risk losing volatile memory evidence. This study proposes a novel cyber-physical defense mechanism integrating a Deep Isolation Forest (DIF) machine learning model with the PLC-SEIFF (Security Incident Forensics Framework) for automated digital evidence acquisition. Implemented on an OpenPLC v3 environment simulating a cyber-physical water tank, the DIF model analyzes raw execution time (scan cycle) and physical state correlations to detect logic hijacking via GDB hot-patching. During the internal evaluation phase, the proposed DIF model achieved an accuracy of 99.05% and an F1-Score of 0.9077. Furthermore, during the testing phase with unseen data, the model maintained a robust overall accuracy of 95.00% and a Macro Average F1-Score of 87.43%, successfully capturing all malicious intrusions (100% Recall for the anomaly class) with zero false negatives.Upon anomaly detection, the automated SEIFF integration rapidly acquired volatile memory dumps and network logs, revealing the injected hex payload (b0 01 90) and state inconsistencies as definitive forensic evidence. This research demonstrates a highly resilient, real-time intrusion detection and automated forensic solution for mitigating advanced cyber threats in modern ICS environments. | |
| dc.identifier.citation | IEEE | |
| dc.identifier.kodeprodi | KODEPRODI57302#Rekayasa Keamanan Siber | |
| dc.identifier.nidn | NIDN0001129002 | |
| dc.identifier.nim | NIM4332201059 | |
| dc.identifier.uri | https://repository.polibatam.ac.id//handle/PL29/5146 | |
| dc.language.iso | other | |
| dc.publisher | Politeknik Negeri Batam | |
| dc.subject | Deep Isolation Forest | |
| dc.subject | Digital Forensics | |
| dc.subject | Intrussion Detection System | |
| dc.subject | OpenPLC | |
| dc.subject | Stealth Injection. | |
| dc.title | Rancang Bangun Sistem Deteksi Intrusi Berbasis Machine Learning dan Akuisisi Bukti Digital Menggunakan Framework PLC-SEIFF untuk Mitigasi Serangan Stealth Injection pada Lingkungan OpenPLC | |
| dc.title.alternative | DESIGN OF A MACHINE LEARNING-BASED INTRUSION DETECTION SYSTEM AND DIGITAL EVIDENCE ACQUISITION USING THE PLC-SEIFF FRAMEWORK TO MITIGATE STEALTH INJECTION ATTACKS IN THE OPENPLC ENVIRONMENT | |
| dc.type | Article |
Files
Original bundle
1 - 3 of 3
Loading...
- Name:
- 4332201059_Article.pdf
- Size:
- 968.45 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Lembar_pengesahan.pdf
- Size:
- 318.13 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Borang_Publikasi.pdf
- Size:
- 707.96 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
