Use cases and applications
In this section, two examples of anomaly detection in an ICS are presented. The first one uses a graph neural network-based method to illustrate anomaly detection by considering the connections among the components in the ICS. The second example shows ransomware detection, which is targeting one of the most important fields in the ICS. Detailed information about them is presented as follows.
Anomaly detection for the ICS
As mentioned in [8] in the References section, practically, most ICSs and their components have significant time series characteristics, and datasets of ICSs are collected with the multivariate time series (MTS) feature. However, most of the existing anomaly detection that works practically does not consider the structure information of the system, such as the connection among the nodes in the ICS. GDN [9] is an unsupervised anomaly detection method using graph attention networks. It combines the structure of existing relationships...