🤖 AI Summary
This study addresses the limitations of conventional traffic- or protocol-based detection methods in identifying topology changes induced by cyberattacks in water distribution systems. To overcome this challenge, the authors propose a novel approach that transforms raw network traffic into dynamic graphs and integrates, for the first time, the Graph-based Machine Learning (GPML) framework with dynamic graph modeling. By leveraging community detection and spectral graph features, the method effectively captures temporal topological anomalies caused by attacks. Experimental evaluation on three industrial datasets—HITL, SWaT, and CrossTest—demonstrates that the proposed technique significantly enhances detection performance for both cyber and physical attacks, thereby surpassing the constraints inherent in traditional traffic analysis approaches.
📝 Abstract
Water distribution networks depends on industrial control systems to integrate the physical process with communication network, making them vulnerable to cyberattacks that alter the traffic pattern and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often oversee structural changes that are induced by such attacks. In this work, we presents a topology-driven approach for detection of cyberattacks in water distribution networks based on Graph Processing for Machine Learning (GPML) framework. The raw traffic is transformed into dynamic graphs, from which community and spectral metrics are extracted and analyzed for any structural and communication modifications with time. The proposed methodology is evaluated on three industrial water distribution datasets such as HITL, SWaT, and CrossTest. Spectral and community graph metrics improve the model performance in detection of cyber and pyhiscal attacks across the three datasets.