Research on abnormal detection of ModbusTCP/IP protocol based on one-class SVM

In order to discover security risks of industrial control system using the Modbus TCP/IP protocol, this paper proposed a construct frequency feature vector data preprocessing methods. This method taken the Modbus TCP/IP message sequence of the normal communication state in the industrial control system as the research object, and extracted the combination of the function code and the register start address as feature. After processing the collected data, an anomaly detection model based on the one-class Support Vector Machine was designed to identify the abnormal traffic in the communication process. Finally, the flow collection was carried out under the environment of 1000MW power plant semi physical communication, and the detection model was simulated and verified. The experimental results showed that the model can accurately identify the abnormal Modbus TCP/IP traffic.