arXiv:2511.00360cs.CRcs.AI2025-11

分析五个主流数据集在能源领域威胁覆盖的缺失,揭示检测短板。

Mind the Gap: Missing Cyber Threat Coverage in NIDS Datasets for the Energy Sector

  • 用MITRE ATT&CK框架系统评估数据集对能源场景的覆盖度
  • 仅38%~56%的攻击技术被数据集覆盖,关键环节如横向移动缺漏严重
  • 建议融合CIC-IDS2017、Sherlock等数据集以提升检测能力,适合安全研究者

基于公开数据集开发的网络入侵检测系统(NIDS)主要针对企业环境,难以有效应对能源基础设施中信息与运营技术融合的场景。本研究采用五步分析法,评估五个常用数据集(CIC-IDS2017、SWaT、WADI、Sherlock、CIC-Modbus2023)对从真实能源事件中提取的274个可网络观测的MITRE ATT&CK技术的覆盖情况。共识别出94个可被检测的技术。结果显示,Sherlock数据集平均覆盖率达0.56,仅次于CIC-IDS2017的0.55,而SWaT和WADI最低,仅为0.38。三者组合可实现92%的整体覆盖,凸显其互补性。研究发现横向移动和工业协议操控等关键攻击行为存在显著遗漏,为未来数据集改进和混合IT/OT环境下的NIDS评估提供明确方向。

原文摘要 · Abstract (English)

Network Intrusion Detection Systems (NIDS) developed using publicly available datasets predominantly focus on enterprise environments, raising concerns about their effectiveness for converged Information Technology (IT) and Operational Technology (OT) in energy infrastructures. This study evaluates the representativeness of five widely used datasets: CIC-IDS2017, SWaT, WADI, Sherlock, and CIC-Modbus2023 against network-detectable MITRE ATT&CK techniques extracted from documented energy sector incidents. Using a structured five-step analytical approach, this article successfully developed and performed a gap analysis that identified 94 network observable techniques from an initial pool of 274 ATT&CK techniques. Sherlock dataset exhibited the highest mean coverage (0.56), followed closely by CIC-IDS2017 (0.55), while SWaT and WADI recorded the lowest scores (0.38). Combining CIC-IDS2017, Sherlock, and CIC-Modbus2023 achieved an aggregate coverage of 92%, highlighting their complementary strengths. The analysis identifies critical gaps, particularly in lateral movement and industrial protocol manipulation, providing a clear pathway for dataset enhancement and more robust NIDS evaluation in hybrid IT/OT energy environments.

入侵检测能源安全数据集评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。