This paperdescribesanoveldomain-awareanomalydetectionsystemthatdetects
irregular changesinModbus/TCPSCADAcontrolregistervalues.Theresearchdiscovered
the presenceofthreeclassesofregisters:(i)sensorregisters;(ii)counterregisters;and(iii)
constant registers.Anautomaticclassifier wasdevelopedtoidentifytheseclasses.
Additionally,parameterizedbehaviormodelswerecreatedforeachclass.Duringits
learning phase,theanomalydetectionsystemusedtheclassifier toidentifythedifferent
types ofregistersandinstantiatedthemodelforeachregisterbasedonitstype.Duringthe
enforcement phase,thesystemdetecteddeviationsfromthemodel.Theanomaly
detection systemwasevaluatedusing131hoftraffic fromaproductionSCADAsystem.
The classifier hadatruepositiveclassification rateof93%.Duringtheenforcementphase,
a 0.86%falsealarmratewasobtainedforthecorrectly-classified registers.