2026-08-04T00:00:00-05:00
Loading Events

COMMITTEE CHAIR: Dr. Justin Foreman

TITLE: MULTI-LEVEL, MULTI-PROTOCOL AUTONOMOUS INTRUSION DETECTION FRAMEWORK FOR INDUSTRIAL OPERATIONAL-TECHNOLOGY NETWORKS

ABSTRACT: Modern industrial facilities such as power grids, water treatment plants, and manufacturing lines increasingly connect their operational-technology (OT) systems to enterprise IT networks. This convergence improves efficiency but widens the attack surface, because industrial protocols such as MQTT, Modbus TCP, and DNP3 were designed for reliability and interoperability long before cybersecurity became a central design concern. These protocols now carry traffic across multiple levels of the Purdue reference model, yet most existing intrusion detection research addresses only a single protocol, stops at producing an alert, gives little attention to where a detector should sit in the network, and offers operators limited insight into why an alert was raised. This dissertation proposes and evaluates a multi-level, multi-protocol autonomous intrusion detection framework for these converged environments. The framework places a dedicated passive detection agent at the correct Purdue level for each protocol: MQTT at the integration level (Level 3.5), Modbus TCP at the supervisory-control level (Levels 1–2), and DNP3 at the field-device level (Level 1). Each agent follows the same four-step process. It passively observes traffic, extracts protocol-specific features, classifies the traffic with a machine-learning model, and produces an English explanation for the operator through a rule-based content-awareness layer. This explanation approach is deterministic and fully auditable, which suits safety-critical OT settings; large-language-model-based explanation is reserved as future work.The methodology combined benchmark evaluation, feature extraction directly from raw packet captures, supervised learning, imbalance-treatment comparison, deliberate leakage prevention, and behavior-only ablation testing, validated end-to-end in the ICS-SimLab containerized testbed. Across all three protocols, Random Forest proved the most defensible classifier. SMOTE consistently outperformed naive upsampling on MQTT but produced classifier-dependent results on Modbus TCP. Per-packet timing features dominated detection across every protocol, though ablations showed that full-feature performance relied partly on network-identity features, an honest limit on cross-site transfer. The study finds that a passive, explainable, availability-preserving autonomous framework is feasible across multiple industrial protocols, while future work must validate cross-agent coordination, cross-site transfer, robustness against evasive attacks, and production deployment.

Room Location: Electrical and Computer Engineering Department Conference Room 315D

Share This Story, Choose Your Platform!

Go to Top