EDBT 2026 Demo / reviewers in the wild / expert
Ankush Meshram
dblp:232/4642
· DBLP profile ↗
7ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0001-6903-9446ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Graph-based Self-learning of Industrial Process Behaviour for Anomaly DetectionabstractThe increasing sophistication of cyber threats targeting industrial control systems (ICS) necessitates advanced anomaly detection techniques capable of identifying attacks by analyzing industrial process data exchange. This paper addresses the challenge of representing and learning the spatio-temporal characteristics of industrial network communication as Graph for self-learning anomaly detection. We propose a novel framework that models the spatio-temporal characteristics as graph snapshots and applies Graph Neural Networks (GNNs) for anomaly detection. Each graph snapshot captures the structural and temporal dynamics of PROFINET-based industrial traffic, with edge features encoding the payload transitions, timing intervals, and cycle counter differences. We evaluate the performance of an isotropic Graph Convolutional Network (GCN) and anisotropic GNN variants – Message Passing Neural Network (MPNN), Gated Graph ConvNet (GatedGCN) and Graph Transformer (GT) – for the task of graph classification on real-world datasets from a miniaturized deterministic production plant. Our evaluation results demonstrate that anisotropic GNN models (MPNN, GatedGCN, GT) achieve complete anomaly detection (specificity) while maintaining perfect recall on normal behavior (sensitivity). In contrast, the isotropic GCN fails to distinguish between normal and anomalous states of the miniaturized plant. These findings highlight the efficacy of encoding spatio-temporal characteristics on graph edges and the capability of anisotropic GNNs to learn complex process behaviors for anomaly detection in the industrial networks of the evaluated production plant. Ankush Meshram, Markus Karch, Christian Haas 0005, Jürgen Beyerer |
KES | 1 |
| 2023 | Towards Self-learning Industrial Process Behaviour from Payload Bytes for Anomaly DetectionabstractNetwork Intrusion Detection System (NIDS) for process-based anomaly detection have been developed as one of the cybersecurity solutions against industrial process targeted attacks such as Stuxnet. In practice, the real-world industrial plants could not complement the advancements in the industrial cybersecurity research as upgrading the infrastructure is an expensive and deterrent process for plant owners. In addition, the infrastructure information might be lost over the intended longer lifetime, hence, configuring a NIDS in the absence of such information is a challenge. Moreover, the existing NIDS solutions analyze the industrial process values/parameters with the knowledge of their semantics, and would fail when the semantics is not known or lost. As a solution to aforementioned problem, we propose an industrial communication paradigm aware Process Payload Profiling Framework (P3F), capable of self-learning process behavior from network traffic without the knowledge of underlying process parameters being exchanged. We also report P3F’s successful detection of an anomaly in the process of a miniaturized PROFINET-based industrial system, caused by a simulated process-targeted cyberattack. Ankush Meshram, Markus Karch, Christian Haas 0005, Jürgen Beyerer |
ETFA | 1 |
| 2023 | Protocol-Agnostic Detection of Stealth Attacks on Networked Control SystemsabstractAttacks on critical infrastructure networks can have severe impact on the physical realm, which makes fast and reliable attack detection a primary security goal. To enhance the security of networked control systems, we introduce a novel approach to detect model-based stealth attacks on industrial real-time protocols. Specifically, we outline how stealth attacks can be detected through passive network monitoring using several supervised and unsupervised machine learning techniques. Our approach leverages computationally inexpensive, well-known detectors (e.g., Support Vector Machines and Local Outlier Factor) and operates in a protocol-agnostic manner that does not require protocol parsing. We evaluate detection capabilities by injecting attack traffic into PROFINET real-time traffic obtained from two different real-world networks. Our results indicate that stealth attacks can be reliably detected within tens of milliseconds. Hauke Heseding, Moritz Dieing, Ankush Meshram, Martina Zitterbart |
INDIN | 3 |
| 2022 | CrossTest: a cross-domain physical testbed environment for cybersecurity performance evaluationsabstractNetwork based intrusion detection systems (NIDS) play a vital role in protecting valuable assets or applications in a wide range of industrial domains. Especially commercial NIDS providers need to address very specific requirements and challenges for theses domains, such as supporting a variety of different network protocols. Despite such challenges, most commercial NIDS vendors offer one solution for multiple industrial domains. In contrast, most NIDSs proposed by researchers are evaluated on only a few domain-specific datasets due to the lack of publicly available industrial datasets. Therefore, conclusions about the applicability of research-oriented NIDS across industrial domains cannot be made. Domain-agnostic threat detection methods are required when advanced persistent threats (APT) are evolving across multiple sectors. This research work presents a cross-domain physical cybersecurity testbed environment, CrossTest, for the development and evaluation of domain-agnostic threat detection methods. For this purpose, two testbeds were designed, one for the energy and another for the production domain. Multiple cyber-attacks were implemented in both testbeds and network traffic was recorded as PCAP files. The dataset containing PCAP files with corresponding description will be made publicly available upon request. Furthermore, we demonstrate the evaluation of an open source network traffic analysis tool, Malcolm, with CrossTest. The evaluation identified major issues that are briefly described in this work. Markus Karch, Dennis Rösch, André Kummerow, Ankush Meshram, Christian Haas 0005, Steffen Nicolai |
ETFA | 4 |
| 2022 | Towards a Better Understanding of Machine Learning based Network Intrusion Detection Systems in Industrial NetworksabstractIt is crucial in an industrial network to understand how and why a intrusion detection system detects, classifies, and reports intrusions. With the ongoing introduction of machine learning into the research area of intrusion detection, this understanding gets even more important since the used systems often appear as a black-box for the user and are no longer understandable in an intuitive and comprehensible way. We propose a novel approach to understand the internal characteristics of a machine learning based network intrusion detection system. This approach includes methods to understand which data sources the system uses, to evaluate whether the system uses linear or non-linear classification approaches, and to find out which underlying machine learning model is implemented in the system. Our evaluation on two publicly available industrial datasets shows that the detection of the data source and the differentiation between linear and non-linear models is possible with our approach. In addition, the identification of the underlying machine learning model can be accomplished with statistical significance for non-linear models. The information made accessible by our approach helps to develop a deeper understanding of the functioning of a network intrusion detection system, and contributes towards developing transparent machine learning based intrusion detection approaches. Anne Borcherding, Lukas Feldmann, Markus Karch, Ankush Meshram, Jürgen Beyerer |
ICISSP | 4 |
| 2019 | Automated Incident Response for Industrial Control Systems Leveraging Software-defined NetworkingabstractModern technologies and concepts for Industrial Control Systems (ICS) are evolving towards high flexibility of processes and respectively networks. Such dynamic networks are already functioning well, for example in data centres. This is enabled by application of the Software-defined Networking (SDN) paradigm. For this reason, ICS is currently adopting SDN. The concept of having a centralized view of the network and generating packet forwarding rules to control it enables performing automated responses to network events and classified incidents via SDN. This automation can provide timely and, due to the holistic view of the network, accurate incident response actions. However, availability, safety, real-time and redundancy requirements within the ICS domain restrict the application of such an automated approach. At present, SDN-based incident response (SDN-IR) does not take into consideration these requirements. In this work, we identify possible SND-based response actions to ICS incidents and introduce classification of assets and links. Furthermore, we present a concept for SDN-IR where a predefined rule set restricts the response actions based on the asset’s classification thereby satisfying ICS specific requirements. Subsequently, we describe and evaluate a prototype implementation of this concept, built with the open-source SDN platform OpenDaylight and the SDN protocol OpenFlow. Florian Patzer, Ankush Meshram, Maximilian Heß |
ICISSP | 2 |
| 2018 | Towards Computer-Aided Security Life Cycle Management for Critical Industrial Control Systems
Florian Patzer, Ankush Meshram, Pascal Birnstill, Christian Haas 0005, Jürgen Beyerer |
CRITIS | 2 |