Asyzauri, Sofyan (2026) Studi Komparatif Model Machine Learning Untuk Deteksi Intrusi Pada Komunikasi SCADA Berbasis IEC 60870-5-104. Masters thesis, Institut Teknologi Sepuluh Nopember.
|
Text
6022241095-Master_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (4MB) | Request a copy |
Abstract
Keamanan sistem Supervisory Control and Data Acquisition (SCADA) dalam sektor kelistrikan semakin menjadi perhatian seiring meningkatnya potensi ancaman siber terhadap infrastruktur kritis. Salah satu protokol komunikasi yang umum digunakan dalam sistem SCADA adalah IEC-60870-5-104 (IEC-104), yang secara desain tidak memiliki mekanisme keamanan seperti autentikasi atau enkripsi. Penelitian terdahulu belum mencakup manipulasi data pengukuran yang dikirimkan Remote Terminal Unit ke Master Station, serta belum banyak membandingkan tingkat detectability antar kategori serangan secara konsisten. Penelitian ini membangun testbed SCADA fisik dan mengevaluasi lima skenario serangan pada komunikasi IEC-104: dua serangan ketersediaan (SYN Flood, APDU Flood) dan tiga serangan integritas yaitu Command & Control Injection Attack (CCIA) pada perintah kontrol, serta False Data Injection (FDI) Bias dan FDI Targeted pada data pengukuran. Lima model supervised machine learning dievaluasi secara binary per skenario maupun terintegrasi dalam satu model klasifikasi multi-class. Akurasi binary bervariasi signifikan, dari 85,20% pada CCIA yaitu skenario paling sulit dideteksi hingga lebih dari 99% pada kedua varian FDI, sementara klasifikasi multi-class mencapai akurasi tertinggi 88,96% dengan CCIA tetap berperforma terendah. Temuan utama menunjukkan bahwa kesenjangan detectability antara CCIA dan FDI bukan disebabkan oleh keberadaan ARP spoofing sebagai mekanisme man-in-the-middle melainkan oleh konsistensi jejak ARP dengan jendela serangan: pada FDI, jejak ARP berkorelasi hampir sempurna dengan periode serangan sehingga menjadi sinyal pembeda yang kuat, sedangkan pada CCIA, ARP spoofing berjalan berkelanjutan tanpa dibatasi jendela serangan sehingga kehilangan daya beda. Kebaruan penelitian ini mencakup dataset SCADA fisik berlabel untuk kelima skenario yang dipublikasikan secara terbuka di Zenodo. Secara praktis, hasil evaluasi merekomendasikan Gradient Boosting sebagai inti IDS IEC-104, dengan pemblokiran otomatis (IPS) dibatasi pada serangan yang terdeteksi sangat andal, sebagai masukan bagi pengamanan sistem SCADA di lingkungan PLN dan industri energi.
=======================================================================================================================================
The security of Supervisory Control and Data Acquisition (SCADA) systems in the electricity sector is drawing increasing attention amid growing cyber threats against critical infrastructure. One commonly used protocol is IEC-60870-5-104 (IEC-104), which by design lacks security mechanisms such as authentication or encryption. Prior studies have not covered manipulation of measurement data from the Remote Terminal Unit to Master Station, nor compared detectability across attack categories consistently. This research builds a physical SCADA testbed and evaluates five attack scenarios on IEC-104 communication: two availability attacks (SYN Flood, APDU Flood) and three integrity attacks, namely Command & Control Injection Attack (CCIA) on control commands, and False Data Injection (FDI) Bias and Targeted on measurement data. Five supervised machine learning models are evaluated independently and integrated into a single multi-class model. Binary accuracy varies significantly, from 85.20% on CCIA (the hardest scenario to detect) to over 99% on both FDI variants, while multi-class classification reaches a top accuracy of 88.96% with CCIA remaining the lowest-performing class. The main finding shows the detectability gap between CCIA and FDI is not caused by ARP spoofing's presence but by the consistency of its footprint with the attack window: in FDI, the footprint correlates almost perfectly with the attack period, a strong discriminative signal; in CCIA, ARP spoofing runs continuously regardless of the attack window, losing discriminative power. The novelty of this work includes an openly published (Zenodo) labeled physical-testbed SCADA dataset. Practically, Gradient Boosting is recommended as the core of an IEC-104 IDS, with automatic blocking (IPS) restricted to highly reliably detected attacks, informing the protection of SCADA systems at PLN and in the wider energy industry.
| Item Type: | Thesis (Masters) |
|---|---|
| Uncontrolled Keywords: | Command & Control Injection Attack, False Data Injection, IEC-104, Intrusion Detection, Machine Learning, SCADA, Command & Control Injection Attack, False Data Injection, IEC-104, Intrusion Detection, Machine Learning, SCADA |
| Subjects: | T Technology > T Technology (General) > T57.5 Data Processing |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Electrical Engineering > 20101-(S2) Master Thesis |
| Depositing User: | Sofyan Asyzauri |
| Date Deposited: | 31 Jul 2026 08:05 |
| Last Modified: | 31 Jul 2026 08:05 |
| URI: | http://repository.its.ac.id/id/eprint/140957 |
Actions (login required)
![]() |
View Item |
