Why Anomaly-Based Intrusion Detection Systems Have Not Yet Conquered the Industrial Market?

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In this position paper, we tackle the following question: why anomaly-based intrusion detection systems (IDS), despite providing excellent results and holding higher (potential) capabilities to detect unknown (zero-day) attacks, are still marginal in the industry, when compared to, e.g., signature-based IDS? We will try to answer this question by looking at the methods and criteria for comparing IDS as well as a specific problem with anomaly-based IDS. We will propose 3 new criteria for comparing IDS. Finally, we focus our discussion under the specific domain of IDS for critical Industrial control systems (ICS).

Original languageEnglish
Title of host publicationFoundations and Practice of Security - 14th International Symposium, FPS 2021, Revised Selected Papers
EditorsEsma Aïmeur, Maryline Laurent, Reda Yaich, Benoît Dupont, Joaquin Garcia-Alfaro
PublisherSpringer Science and Business Media Deutschland GmbH
Pages341-354
Number of pages14
ISBN (Print)9783031081460
DOIs
Publication statusPublished - 1 Jan 2022
Event14th International Symposium on Foundations and Practice of Security, FPS 2021 - Paris, France
Duration: 7 Dec 202110 Dec 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13291 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference14th International Symposium on Foundations and Practice of Security, FPS 2021
Country/TerritoryFrance
CityParis
Period7/12/2110/12/21

Keywords

  • Anomaly detection
  • Critical infrastructures
  • Explainable artificial intelligence
  • Industrial control system
  • Intrusion detection system

Fingerprint

Dive into the research topics of 'Why Anomaly-Based Intrusion Detection Systems Have Not Yet Conquered the Industrial Market?'. Together they form a unique fingerprint.

Cite this