Uppsats
Homomorphic vs Functional Encryption in Intrusion Detection Systems for OT Networks
H
Chalmers tekniska högskola / Institutionen för data och informationsteknik
Publicerad: 2025
Sammanfattning
As the number and complexity of cybersecurity threats against Operational Technology (OT) systems rise, the need for effective countermeasures becomes increasingly critical. One such countermeasure is the deployment of Intrusion Detection Systems (IDS) that monitor for signs of malicious activity. However, the implementation of IDSs can present several challenges. OT devices can be resource-constrained, and personnel with expertise in IDS can be difficult to find. For these reasons, IDS functionality is frequently outsourced to external parties. While effective, this solution raises concerns due to the large amount of potentially sensitive data that is shared with the external party. To address the privacy risks of data sharing, a surge in research has focused on cryptographic techniques that enable privacy-preserving external IDSs. While many interesting techniques have been presented, few studies include rigorous performance evaluations and technical comparisons between different approaches. This thesis aims to fill this gap by comparing two cryptographictechniques in an OT setting.The first technique uses Cheon-Kim-Kim-Song (CKKS), an instance of homomorphicencryption (HE) that allows an IDS server to perform computations on encrypteddata. The resulting values are then decrypted by the client to determine whetherthe system has been compromised. The second approach uses function-hiding innerproduct encryption (FHIPE), an instance of functional encryption (FE). It enables anexternal IDS server to calculate the distance between a client system’s normal stateand current state without revealing either. This distance is then used for intrusiondetection.The HE and FE techniques are evaluated on the Secure Water Treatment (SWaT)dataset using a neural network-based IDS. The results show that both methodsachieve threat detection accuracy comparable to their unencrypted counterpart. Theadditional detection latency introduced by the systems is found to be less than 125ms. The client-side memory demands are less than 4 MB for the HE approach andless than 82 kB for the FE approach. Lastly, while both schemes increase the averagenetwork payload size significantly, the overall bandwidth usage remains manageablefor most modern systems.
Information
- Författare
- Ndaw Berbres, Jibbril, Stenhammar, Valdemar
- Lärosäte / institution
- Chalmers tekniska högskola / Institutionen för data och informationsteknik
- Publiceringsdatum
- 2025
- Uppsatstyp
- H
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, Göteborgs universitet/Institutionen för data- och informationsteknik
Almström, Jonas, Forssell, Carl, Johansson, Kalle
Publicerad: 2026-02-19
H, Chalmers tekniska högskola / Institutionen för data och informationsteknik
HANI, SALAM, LINDER, JONATHAN
Publicerad: 2025
H, Chalmers tekniska högskola / Institutionen för data och informationsteknik
Karki, Ishwor, Albutihe, Ismael
Publicerad: 2024
H, Chalmers tekniska högskola / Institutionen för data och informationsteknik
Vallander, Johan
Publicerad: 2026
H, Chalmers tekniska högskola / Institutionen för data och informationsteknik
Flink, Lucas
Publicerad: 2026
Master-uppsats, Stockholms universitet/Institutionen för data- och systemvetenskap
Rahman, Suraiya, Perumath, Neethu
Publicerad: 2025