AI-enabled Cybersecurity Framework for Industrial Control Systems

dc.contributor.advisorKarimipour, Hadis
dc.contributor.advisorDehghantanha, Ali
dc.contributor.authorNamavar Jahromi, Amir
dc.contributor.committeememberLeung, Henry KY
dc.contributor.committeememberTan, Peng Seng Benjamin
dc.contributor.committeememberLu, Rongxing
dc.date2023-02
dc.date.accessioned2022-12-19T18:45:05Z
dc.date.available2022-12-19T18:45:05Z
dc.date.issued2022-12-14
dc.description.abstractIndustrial Control System (ICS), one type of Operational Technology (OT), plays an essential role in monitoring and controlling critical infrastructures such as power plants, smart grids, oil and gas industries, and transportation. To maintain the security of ICSs from cyber-attacks, they were placed on isolated communication networks, which were relatively obscure and unknown to most attackers. However, integrating the Internet of Things (IoT) in ICSs allows remote monitoring, access, and control of critical infrastructure, leading to more agile and efficient systems. However, it increases the vulnerabilities of these systems towards cyber-attacks. Due to the ICS functionality in critical infrastructures, a compromise in the system may lead to severe danger to human life or the environment. Moreover, the growing number of cyber-attacks against ICS in recent years elevates a significant concern for proper and timely security solutions for these systems. Besides, due to the differences between the IT and OT networks, IT cyber-security solutions are unsuitable for ICS. These differences include network protocols, performance metrics, and asset characteristics. Besides, in IT networks, the main focus is on throughput management of the network, while the OT focuses on reliability and punctuality. In this thesis, an AI-enabled framework will be proposed to secure the ICS networks and reduce the risk of harmful effects on human lives and the environment. The proposed framework includes cyber-attack detection, cyber-attack localization, cyber-threat hunting, cyber-attack projection, and cyber-attack attribution components. Furthermore, the proposed methods for the mentioned components will focus on the challenges of using machine learning techniques in the cybersecurity of the ICS, such as using imbalanced data and data privacy of training the models on the cloud. An ensemble of two unsupervised deep neural networks with a decision tree classifier will be proposed for the cyber-attack detection component. Furthermore, a federated learning-based technique will be proposed for the cyber-threat hunting component to build a powerful hunting component based on several ICS data with privacy-preserving and without sharing the data. Moreover, attack projection will be modeled using the combination of deep reinforcement learning and deep neural networks. In the end, an ensemble of several deep neural networks will be proposed for the attack attribution. These components build a more secure infrastructure by early detecting incoming attacks, hunting the evaded threats, determining the attack trajectory, and analyzing their impact.en_US
dc.identifier.citationNamavar Jahromi, A. (2022). AI-enabled cybersecurity framework for industrial control systems (Doctoral thesis, University of Calgary, Calgary, Canada). Retrieved from https://prism.ucalgary.ca.en_US
dc.identifier.urihttp://hdl.handle.net/1880/115600
dc.identifier.urihttps://dx.doi.org/10.11575/PRISM/40534
dc.language.isoengen_US
dc.publisher.facultySchulich School of Engineeringen_US
dc.publisher.institutionUniversity of Calgaryen
dc.rightsUniversity of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission.en_US
dc.subjectIndustrial control systems (ICS)en_US
dc.subjectcybersecurityen_US
dc.subjectmachine learningen_US
dc.subjectcyber-attack detectionen_US
dc.subjectdeep learningen_US
dc.subjectrepresentation learningen_US
dc.subjectreinforcement learningen_US
dc.subjectfederated learningen_US
dc.subjectcyber-attack projectionen_US
dc.subjectcyber-threat huntingen_US
dc.subjectcyber-attack attributionen_US
dc.subject.classificationArtificial Intelligenceen_US
dc.subject.classificationComputer Scienceen_US
dc.subject.classificationPsychology--Industrialen_US
dc.titleAI-enabled Cybersecurity Framework for Industrial Control Systemsen_US
dc.typedoctoral thesisen_US
thesis.degree.disciplineEngineering – Electrical & Computeren_US
thesis.degree.grantorUniversity of Calgaryen_US
thesis.degree.nameDoctor of Philosophy (PhD)en_US
ucalgary.item.requestcopytrueen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
ucalgary_2022_namavarjahromi_amir.pdf
Size:
6 MB
Format:
Adobe Portable Document Format
Description:
Thesis
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.62 KB
Format:
Item-specific license agreed upon to submission
Description: