• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion Detection
 
  • Details
  • Full
Options
2025
Conference Paper
Title

GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion Detection

Abstract
Protecting industrial control systems against cyberattacks is crucial to counter escalating threats to critical infrastructure. To this end, Industrial Intrusion Detection Systems (IIDSs) provide an easily retrofittable approach to uncover attacks quickly and before they can cause significant damage. Current research focuses either on maximizing automation, usually through heavy use of machine learning, or on expert systems that rely on detailed knowledge of the monitored systems. While the former hinders the interpretability of alarms, the latter is impractical in real deployments due to excessive manual work for each individual deployment. To bridge the gap between maximizing automation and leveraging expert knowledge, we introduce GeCo, a novel IIDS based on automatically derived comprehensible models of benign system behavior. GeCo leverages state-space models mined from historical process data to minimize manual effort for operators while maintaining high detection performance and generalizability across diverse industrial domains. Our evaluation against state-of-the-art IIDSs and datasets demonstrates GeCo’s superior performance while remaining comprehensible and performing on par with expert-derived rules. GeCo represents a critical step towards empowering operators with control over their cybersecurity toolset, thereby enhancing the protection of valuable physical processes in industrial control systems and critical infrastructures.
Author(s)
Wolsing, Konrad
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Wagner, Eric
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Lux, Luisa
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Wehrle, Klaus  
RWTH Aachen University
Henze, Martin  
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Mainwork
34th USENIX Security Symposium 2025. Proceedings  
Conference
USENIX Security Symposium 2025  
Link
Link
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024