<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T01:04:39Z</responseDate><request verb="GetRecord" identifier="oai:odr.chalmers.se:20.500.12380/300050" metadataPrefix="dim">https://odr.chalmers.se/server/oai/request</request><GetRecord><record><header><identifier>oai:odr.chalmers.se:20.500.12380/300050</identifier><datestamp>2026-02-27T10:05:37Z</datestamp><setSpec>Technology</setSpec><setSpec>com_20.500.12380_11</setSpec><setSpec>com_20.500.12380_1</setSpec><setSpec>col_20.500.12380_29</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="author">Ström, David</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author">Sinai Nadkarni, Viren</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="sv">Chalmers tekniska högskola / Institutionen för data och informationsteknik</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="examiner">Jonsson, Erland</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2019-07-12T12:14:18Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2019-07-12T12:14:18Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="sv">2019</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="submitted">2019</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/20.500.12380/300050</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="coursecode" lang="sv">DATX05</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="sv">Over the last decade, Industrial Control Systems (ICSs), which manage critical infrastructure&#xd;
such as power, water and gas distribution systems, are increasingly&#xd;
being targeted by sophisticated cyberattacks. It is of paramount importance that&#xd;
necessary safeguards are in place for these systems to avoid potentially catastrophic&#xd;
damage. Intrusion Detection Systems (IDSs) can be used to monitor computer&#xd;
systems for signs of attacks and are commonly of two types: signature-based or&#xd;
anomaly-based. Signature-based IDSs work by using a database of known traffic&#xd;
patterns to identify malicious activity. Attacks against ICSs are specialised and&#xd;
crafted to exploit specific protocol semantics and setup. As such, building a signature&#xd;
database which incorporates all attack properties is difficult. This has led to a&#xd;
growing interest in doing anomaly-based intrusion detection using information from&#xd;
the industrial processes, such as sensor readings and control commands.&#xd;
Research has shown that process-level anomaly detection can identify a large range&#xd;
of attack types, but so far there have been limited insights into whether processlevel&#xd;
anomaly detection is suitable for modern ICS software. Questions such as if the&#xd;
cost of processing a large number of signals is reasonable, if it is feasible to integrate&#xd;
anomaly detection into existing ICS software, need a deeper understanding.&#xd;
This study aims to evaluate the suitability of using process-level anomaly detection&#xd;
in production-grade ICS software. The platform is provided by ABB, a major international&#xd;
supplier of ICSs. We focus on two time series algorithms: Process-Aware&#xd;
Stealthy Attack Detection (PASAD) and Auto-Regression (AR) modelling.&#xd;
Our findings show that both methods can successfully be used in large-scale ICS&#xd;
software. AR gives throughput one magnitude higher than PASAD, while PASAD&#xd;
is better at detecting stealthy attacks and attacks in noisy signals. PASAD can also&#xd;
leverage GPU capabilities, but needs buffering to outperform CPU implementations.&#xd;
The design of PASAD means that it requires a large amount of memory to model&#xd;
signals which have many values representing the normal behaviour. On the whole, we&#xd;
find that process-level anomaly detection can be a reliable complementary security&#xd;
mechanism for ICS deployments.</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="sv">eng</dim:field>
   <dim:field mdschema="dc" element="setspec" qualifier="uppsok">Technology</dim:field>
   <dim:field mdschema="dc" element="subject" lang="sv">Anomaly detection</dim:field>
   <dim:field mdschema="dc" element="subject" lang="sv">Intrusion detection</dim:field>
   <dim:field mdschema="dc" element="subject" lang="sv">Industrial control systems</dim:field>
   <dim:field mdschema="dc" element="subject" lang="sv">Electrical grid</dim:field>
   <dim:field mdschema="dc" element="title" lang="sv">Process-level Anomaly Detection in Industrial Control Systems</dim:field>
   <dim:field mdschema="dc" element="type" qualifier="degree" lang="sv">Examensarbete för masterexamen</dim:field>
   <dim:field mdschema="dc" element="type" qualifier="uppsok">H</dim:field>
   <dim:field mdschema="local" element="programme">Computer systems and networks (MPCSN), MSc</dim:field>
   <dim:field mdschema="others" element="access-status">open.access</dim:field>
</dim:dim></metadata></record></GetRecord></OAI-PMH>