# On the Feasibility of Distinguishing Between Process Disturbances and   Intrusions in Process Control Systems Using Multivariate Statistical Process   Control

**Authors:** Mikel Iturbe, Jos\'e Camacho, I\~naki Garitano, Urko Zurutuza, Roberto, Uribeetxeberria

arXiv: 1706.01679 · 2017-06-07

## TL;DR

This paper proposes an enhanced MSPC-based system for distinguishing between process disturbances and cyber intrusions in process control systems, addressing limitations of previous network-focused anomaly detection methods.

## Contribution

It extends traditional MSPC to include process and controller data, enabling better differentiation between disturbances and attacks in critical infrastructure processes.

## Key findings

- Can distinguish disturbances from intrusions to some extent
- Evaluation on Tennessee-Eastman process demonstrates effectiveness
- Potential for improvement with additional data sources

## Abstract

Process Control Systems (PCSs) are the operating core of Critical Infrastructures (CIs). As such, anomaly detection has been an active research field to ensure CI normal operation. Previous approaches have leveraged network level data for anomaly detection, or have disregarded the existence of process disturbances, thus opening the possibility of mislabelling disturbances as attacks and vice versa. In this paper we present an anomaly detection and diagnostic system based on Multivariate Statistical Process Control (MSPC), that aims to distinguish between attacks and disturbances. For this end, we expand traditional MSPC to monitor process level and controller level data. We evaluate our approach using the Tennessee-Eastman process. Results show that our approach can be used to distinguish disturbances from intrusions to a certain extent and we conclude that the proposed approach can be extended with other sources of data for improving results.

## Full text

_Full body text omitted from this summary view._ Fetch the complete paper as Markdown: https://tomesphere.com/paper/1706.01679/full.md

## Figures

15 figures with captions in the complete paper: https://tomesphere.com/paper/1706.01679/full.md

## References

17 references — full list in the complete paper: https://tomesphere.com/paper/1706.01679/full.md

---
Source: https://tomesphere.com/paper/1706.01679