• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Efficient Cyberattack Detection in Logs of Cyber-Physical Production Systems
 
  • Details
  • Full
Options
2026
Journal Article
Title

Efficient Cyberattack Detection in Logs of Cyber-Physical Production Systems

Abstract
Cyber-physical production systems are increasingly targeted by cyberattacks, making security monitoring essential. Log analysis is a crucial component of security monitoring, but it is often hampered by the large volume and unstructured nature of log data from diverse hardware and software components. This paper introduces CyberLog, a novel approach for the efficient detection of cyberattacks based on log data. CyberLog combines clustering and process mining techniques in a two-step process. First, it preprocesses and clusters log messages by extracting common patterns, or templates, using the Drain algorithm. These templates are then automatically annotated with security techniques based on the MITRE ATT&CK framework for industrial control systems. Second, the approach learns behavior models by calculating dependency scores between templates, which are then used to represent the system’s behavior as a behavior model. The effectiveness of CyberLog is demonstrated by learning and visualizing behavior models from three distinct programmable logic controllers in a realistic industrial control system testbed. The resulting models provide a clear representation of system behavior, establishing a foundation for subsequent security monitoring.
Author(s)
Otto, Jens  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Specht, Felix  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Journal
Procedia computer science  
Conference
International Conference on System-Integrated Intelligence 2025  
Open Access
File(s)
Download (1.16 MB)
Rights
CC BY-NC-ND 4.0: Creative Commons Attribution-NonCommercial-NoDerivatives
DOI
10.1016/j.procs.2026.02.029
10.24406/publica-8092
Additional link
Full text
Language
English
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Keyword(s)
  • Security Monitoring

  • Log Analysis

  • Cyberattack Detection

  • Cyber-Physical Production Systems

  • Machine Learning

  • Process Mining

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024