TY - GEN
T1 - Firewall Log-Based Rule Extraction and Passive Anomaly Detection for Tobacco ICS Security
AU - Yang, Bingyu
AU - Li, Zhongwei
AU - Wang, Fei
AU - Tong, Weiming
AU - Shan, Qi
AU - Liu, Shiyu
AU - Shi, Shaoqing
AU - Yang, Bo
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Industrial control systems in tobacco manufacturing are increasingly exposed to cyber threats due to interconnected network architectures. To address the limitations of static firewall policies and the lack of interpretable anomaly detection solutions, this paper proposes a rule-mining-based anomaly detection method leveraging historical firewall logs. By applying the Apriori algorithm, frequent communication patterns are extracted to construct behavior models representing normal device interactions. A passive detection prototype is implemented in bypass mode, supporting real-time traffic analysis, rule-based matching, and topology-aware visualization without interfering with production processes. Compared with conventional machine learning approaches, the proposed method emphasizes interpretability, lightweight deployment, and adaptability to evolving industrial environments. Experimental results on real-world firewall logs from a tobacco manufacturing plant validated the feasibility and effectiveness of the proposed approach in identifying anomalous communication behaviors.
AB - Industrial control systems in tobacco manufacturing are increasingly exposed to cyber threats due to interconnected network architectures. To address the limitations of static firewall policies and the lack of interpretable anomaly detection solutions, this paper proposes a rule-mining-based anomaly detection method leveraging historical firewall logs. By applying the Apriori algorithm, frequent communication patterns are extracted to construct behavior models representing normal device interactions. A passive detection prototype is implemented in bypass mode, supporting real-time traffic analysis, rule-based matching, and topology-aware visualization without interfering with production processes. Compared with conventional machine learning approaches, the proposed method emphasizes interpretability, lightweight deployment, and adaptability to evolving industrial environments. Experimental results on real-world firewall logs from a tobacco manufacturing plant validated the feasibility and effectiveness of the proposed approach in identifying anomalous communication behaviors.
KW - Apriori
KW - ICS security
KW - association rules
KW - passive intrusion detection
UR - https://www.scopus.com/pages/publications/105042350570
U2 - 10.1109/ICSP69961.2026.11540660
DO - 10.1109/ICSP69961.2026.11540660
M3 - 会议稿件
AN - SCOPUS:105042350570
T3 - 2026 11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026
SP - 586
EP - 594
BT - 2026 11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 11th International Conference on Intelligent Computing and Signal Processing, ICSP 2026
Y2 - 17 April 2026 through 19 April 2026
ER -