{"id":"https://openalex.org/W3120091939","doi":"https://doi.org/10.1109/nca51143.2020.9306726","title":"Hardware-Performance-Counters-based anomaly detection in massively deployed smart industrial devices","display_name":"Hardware-Performance-Counters-based anomaly detection in massively deployed smart industrial devices","publication_year":2020,"publication_date":"2020-11-24","ids":{"openalex":"https://openalex.org/W3120091939","doi":"https://doi.org/10.1109/nca51143.2020.9306726","mag":"3120091939"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/nca51143.2020.9306726","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://laas.hal.science/hal-03328251/document","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5083287666","display_name":"Malcolm Bourdon","orcid":null},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Malcolm Bourdon","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083520169","display_name":"Pierre-Fran\u00e7ois Gimenez","orcid":"https://orcid.org/0000-0002-4238-4423"},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Pierre-Francois Gimenez","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013666045","display_name":"\u00c9ric Alata","orcid":null},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Eric Alata","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017033585","display_name":"Mohamed Ka\u00e2niche","orcid":"https://orcid.org/0000-0003-4443-5658"},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Mohamed Kaaniche","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041870658","display_name":"Vincent Migliore","orcid":"https://orcid.org/0000-0002-6834-4235"},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Vincent Migliore","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036196105","display_name":"Vincent Nicomette","orcid":"https://orcid.org/0000-0001-9482-004X"},"institutions":[{"id":"https://openalex.org/I190497903","display_name":"Laboratoire d'Analyse et d'Architecture des Syst\u00e8mes","ror":"https://ror.org/03vcm6439","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I134560555","https://openalex.org/I190497903","https://openalex.org/I196454796","https://openalex.org/I205747304","https://openalex.org/I4210095849","https://openalex.org/I4210159245"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Vincent Nicomette","raw_affiliation_strings":["LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)"],"affiliations":[{"raw_affiliation_string":"LAAS-TSF - \u00c9quipe Tol\u00e9rance aux fautes et S\u00fbret\u00e9 de Fonctionnement informatique (France)","institution_ids":["https://openalex.org/I190497903"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5000857027","display_name":"Youssef Laarouchi","orcid":null},"institutions":[{"id":"https://openalex.org/I4210143116","display_name":"\u00c9lectricit\u00e9 de France (France)","ror":"https://ror.org/03wb8xz10","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210143116"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Youssef Laarouchi","raw_affiliation_strings":["EDF R&D - EDF R&D (France)"],"affiliations":[{"raw_affiliation_string":"EDF R&D - EDF R&D (France)","institution_ids":["https://openalex.org/I4210143116"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":4,"citation_normalized_percentile":{"value":0.638126,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":76,"max":79},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.42608953}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7728859},{"id":"https://openalex.org/C190475519","wikidata":"https://www.wikidata.org/wiki/Q544384","display_name":"Massively parallel","level":2,"score":0.61643875},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.6133243},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5712902},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.5647341},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.55809206},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.42608953},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.32414055},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2550676},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/nca51143.2020.9306726","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.laas.fr/hal-03328251","pdf_url":"https://laas.hal.science/hal-03328251/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://laas.hal.science/hal-03328251/file/Anomaly_detection_on_a_large_scale_deployment_of_smart_devices_using_hardware_performance_counters%285%29.pdf","pdf_url":"https://laas.hal.science/hal-03328251/file/Anomaly_detection_on_a_large_scale_deployment_of_smart_devices_using_hardware_performance_counters%285%29.pdf","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.laas.fr/hal-03328251/file/Anomaly_detection_on_a_large_scale_deployment_of_smart_devices_using_hardware_performance_counters%285%29.pdf","pdf_url":"https://hal.laas.fr/hal-03328251/file/Anomaly_detection_on_a_large_scale_deployment_of_smart_devices_using_hardware_performance_counters%285%29.pdf","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://hal.laas.fr/hal-03328251","pdf_url":"https://laas.hal.science/hal-03328251/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"score":0.57,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":25,"referenced_works":["https://openalex.org/W1988833430","https://openalex.org/W2016565838","https://openalex.org/W2101234009","https://openalex.org/W2119438786","https://openalex.org/W2122646361","https://openalex.org/W2129281431","https://openalex.org/W2134490011","https://openalex.org/W2144182447","https://openalex.org/W2170467352","https://openalex.org/W2296719434","https://openalex.org/W2315350509","https://openalex.org/W2400831011","https://openalex.org/W2508317201","https://openalex.org/W2601243251","https://openalex.org/W2733765803","https://openalex.org/W2807415350","https://openalex.org/W2932551155","https://openalex.org/W2950774332","https://openalex.org/W2951694401","https://openalex.org/W2952311595","https://openalex.org/W2994950844","https://openalex.org/W3144750446","https://openalex.org/W4229530126","https://openalex.org/W4253461361","https://openalex.org/W4256177618"],"related_works":["https://openalex.org/W3187581118","https://openalex.org/W3143747655","https://openalex.org/W3005861778","https://openalex.org/W2901835651","https://openalex.org/W2883616266","https://openalex.org/W2378449000","https://openalex.org/W2372254325","https://openalex.org/W2294483539","https://openalex.org/W2002178493","https://openalex.org/W186576250"],"abstract_inverted_index":{"Energy":[0],"providers":[1],"are":[2,14,49,85],"massively":[3,80],"deploying":[4],"devices":[5,13,48,154],"to":[6,18,27,53,56,76,92,150],"manage":[7,19],"distributed":[8],"resources":[9],"or":[10,26,59],"equipment.":[11],"These":[12,83],"used":[15],"for":[16],"example":[17],"the":[20,29,111,114,119,123,126,129,144,173,176,181,185,190],"energy":[21],"of":[22,31,51,105,113,128,175],"smart":[23],"factories":[24],"efficiently":[25],"monitor":[28],"infrastructure":[30],"smart-grids.":[32],"By":[33],"design,":[34],"they":[35],"typically":[36],"exhibit":[37],"homogeneous":[38],"behavior,":[39],"with":[40],"similar":[41],"software":[42,115,167,187],"and":[43,125,162,169],"hardware":[44,182],"architecture.":[45],"Unfortunately,":[46],"these":[47],"also":[50],"interest":[52],"attackers":[54],"aiming":[55],"develop":[57],"botnets":[58],"compromise":[60],"companies'":[61],"security.":[62],"This":[63],"paper":[64],"presents":[65],"a":[66,97,102,131,139],"new":[67],"protection":[68],"approach":[69,99,177],"based":[70,100],"on":[71,101,110,118,180,189],"Hardware":[72],"Performance":[73],"Counters":[74],"(HPC)":[75],"detect":[77],"anomalies":[78],"in":[79,138,197],"deployed":[81,155],"devices.":[82,120,191],"HPC":[84,107],"processed":[86],"using":[87],"outlier":[88],"detection":[89,161],"algorithms.":[90],"Compared":[91],"existing":[93],"solutions,":[94],"we":[95],"propose":[96],"lightweight":[98],"comparative":[103],"analysis":[104,134],"devices'":[106],"without":[108],"relying":[109],"modeling":[112],"applications":[116],"running":[117,188],"To":[121],"assess":[122],"relevance":[124],"effectiveness":[127],"approach,":[130],"thorough":[132],"experimental":[133],"is":[135],"carried":[136],"out":[137],"representative":[140],"industrial-type":[141],"environment,":[142],"sampling":[143],"data":[145],"from":[146],"100":[147],"Raspberry":[148],"Pi":[149],"simulate":[151],"about":[152],"10,000":[153],"simultaneously.":[156],"The":[157],"results":[158],"show":[159],"high":[160],"performance":[163],"efficiency":[164],"under":[165],"different":[166],"profiles":[168],"attack":[170],"payloads.":[171],"Moreover,":[172],"calibration":[174],"depends":[178],"primarily":[179],"rather":[183],"than":[184],"application":[186],"It":[192],"should":[193],"ease":[194],"its":[195],"deployment":[196],"an":[198],"operational":[199],"environment.":[200]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3120091939","counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3}],"updated_date":"2025-01-15T18:22:06.329795","created_date":"2021-01-18"}