Skip to main navigation Skip to search Skip to main content

Firewall Log-Based Rule Extraction and Passive Anomaly Detection for Tobacco ICS Security

  • Bingyu Yang
  • , Zhongwei Li*
  • , Fei Wang
  • , Weiming Tong
  • , Qi Shan
  • , Shiyu Liu
  • , Shaoqing Shi
  • , Bo Yang
  • *Corresponding author for this work
  • Ltd.
  • School of Electrical Engineering and Automation, Harbin Institute of Technology
  • Ltd.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Industrial control systems in tobacco manufacturing are increasingly exposed to cyber threats due to interconnected network architectures. To address the limitations of static firewall policies and the lack of interpretable anomaly detection solutions, this paper proposes a rule-mining-based anomaly detection method leveraging historical firewall logs. By applying the Apriori algorithm, frequent communication patterns are extracted to construct behavior models representing normal device interactions. A passive detection prototype is implemented in bypass mode, supporting real-time traffic analysis, rule-based matching, and topology-aware visualization without interfering with production processes. Compared with conventional machine learning approaches, the proposed method emphasizes interpretability, lightweight deployment, and adaptability to evolving industrial environments. Experimental results on real-world firewall logs from a tobacco manufacturing plant validated the feasibility and effectiveness of the proposed approach in identifying anomalous communication behaviors.

Original languageEnglish
Title of host publication2026 11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages586-594
Number of pages9
ISBN (Electronic)9798331562410
DOIs
StatePublished - 2026
Externally publishedYes
Event11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026 - Hefei, China
Duration: 17 Apr 202619 Apr 2026

Publication series

Name2026 11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026

Conference

Conference11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026
Country/TerritoryChina
CityHefei
Period17/04/2619/04/26

Keywords

  • Apriori
  • ICS security
  • association rules
  • passive intrusion detection

Fingerprint

Dive into the research topics of 'Firewall Log-Based Rule Extraction and Passive Anomaly Detection for Tobacco ICS Security'. Together they form a unique fingerprint.

Cite this