Felix Specht

dblp:170/0474 · DBLP profile ↗
← Back
5ranked-venue papers
5as first author
3since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 5 first-author · 3 since 2021
YearPublicationVenuePosition
2024 Efficient Machine Learning-Based Security Monitoring and Cyberattack Classification of Encrypted Network Traffic in Industrial Control Systems
abstract
Security monitoring is a key aspect to detect cyberattacks against industrial control systems. However, with the increasing use of encryption in industrial communication protocols, traditional monitoring solutions based on deep packet inspection are becoming less effective. This paper introduces a novel approach for efficient machine learning-based security monitoring and cyberattack classification in encrypted network traffic, named CyberClas+. The approach converts network traffic into time series by computing network metrics and analyzes these time series with a combination of threshold learning and machine learning. Evaluation results on an industrial control system show a classification accuracy of 97% across 14 different cyberattack techniques, with a significantly decreased execution time compared to conventional machine learning methods.
Felix Specht, Jens Otto
ETFA1
2023 Generation of Synthetic Data to Improve Security Monitoring for Cyber-Physical Production Systems
abstract
Machine learning based security monitoring can be used to detect cyberattacks and malfunctions in cyber-physical production systems. Acquiring real data sets for training machine learning algorithms is a problem due to high costs, low data quality, data diversity, and the violation of privacy policies. This paper introduces CyberSyn, a novel approach to generate synthetic data sets for machine learning based security monitoring systems. The generated data sets are analyzed using data quality metrics. Two scenarios from process manufacturing and industrial communication networks are used to evaluate the introduced approach. The proposed approach is able to generate synthetic data sets for both scenarios.
Felix Specht, Jens Otto, Daniel Ratz
INDIN1
2022 Cyberattack Impact Reduction using Software-Defined Networking for Cyber-Physical Production Systems
abstract
Cyberattacks on cyber-physical production systems lead to manipulation of the physical process and pose a serious threat to machines and employees. Preventing cyberattacks and reducing their negative impact is an important aspect of security. This paper presents an approach to reduce the impact of cyberattacks. The approach uses software-defined networking (SDN) in combination with network metrics. The network metrics enable measuring the impact of cyberattacks and the impact reduction by the SDN approach. The SDN approach utilizes four different prevention techniques as countermeasures. Scenarios from discrete manufacturing are used to evaluate the approach. The approach reduces the average impact of the selected cyber-attacks from 82.9% to 98.1%.
Felix Specht, Jens Otto, Jens Eickmeyer
INDIN1
2018 Generation of Adversarial Examples to Prevent Misclassification of Deep Neural Network based Condition Monitoring Systems for Cyber-Physical Production Systems
abstract
Deep neural network based condition monitoring systems are used to detect system failures of cyber-physical production systems. However, a vulnerability of deep neural networks are adversarial examples. They are manipulated inputs, e.g. process data, with the ability to mislead a deep neural network into misclassification. Adversarial example attacks can manipulate the physical production process of a cyber-physical production system without being recognized by the condition monitoring system. Manipulation of the physical process poses a serious threat for production systems and employees. This paper introduces CyberProtect, a novel approach to prevent misclassification caused by adversarial example attacks. CyberProtect generates adversarial examples and uses them to retrain deep neural networks. This results in a hardened deep neural network with a significant reduced misclassification rate. The proposed countermeasure increases the classification rate from 20% to 82%, as proved by empirical results.
Felix Specht, Jens Otto, Oliver Niggemann, Barbara Hammer
INDIN1
2015 Exploiting multicore processors in PLCs using libraries for IEC 61131-3
abstract
This paper presents an approach for exploiting multicore hardware architectures on coding level for the IEC 61131-3. An interface between the IEC 61131-3 code and software of a different programming language outsources the actual parallel workload. For validation purpose, an embedded multicore hardware is used as a controlling device, which executes software for the use case of model based condition monitoring. The case study results show an explicit benefit of the multicore exploiting software in comparison to its singlecore counterpart, which is reflected with a faster processing of up to a factor of 3. Overall, this approach can be used for developing high performance applications or for accelerating existing applications in industry.
Felix Specht, Holger Flatt, Jens Eickmeyer, Oliver Niggemann
ETFA1