A Data-Driven Framework for Verified Detection of Replay Attacks on Industrial Control Systems

计算机科学 工业控制系统 控制(管理) 控制系统 重放攻击 嵌入式系统 实时计算 计算机安全 工程类 人工智能 散列函数 电气工程
作者
Sara Gargoum,Negar Yassaie,Ahmad W. Al-Dabbagh,Chen Feng
出处
期刊:IEEE Transactions on Automation Science and Engineering [Institute of Electrical and Electronics Engineers]
卷期号:: 1- 被引量:2
标识
DOI:10.1109/tase.2024.3394315
摘要

This paper addresses data-driven replay attack detection on industrial control systems. The primary challenge in detection lies in distinguishing replayed sensor measurements from normal measurements using only time series data. This is tackled through a novel two-stage detection and verification framework. The first stage consists of continuous real-time monitoring of sensor measurement patterns using matrix profile based change-point detection, used to indicate a possibility of a replay attack. The second stage verifies the presence of a replay attack by introducing spatial features to newly defined time series data. This is implemented by generating spectrograms of the time series measurements using short-time Fourier transform. Then, the spectrograms are split into image frames to form temporal sequences, creating spatio-temporal features that distinguish replay attacks. To capture both the spatial and temporal features, we utilise a Convolutional Long Short-Term Memory (ConvLSTM) neural network and implement it in an autoencoder architecture, in order to analyse data patterns in an unsupervised manner, where the replay attack is detected based on the reconstruction error. We demonstrate the effectiveness of our framework in the detection of different replay attack scenarios using the Tennessee Eastman process benchmark simulation system/process. Note to Practitioners —This paper is motivated by the importance of cyberattack detection in industrial control systems that are essential for the stable operation of many practical applications, such as in chemical processing and manufacturing plants, and power and water distribution networks. Specifically, replay attack detection using data-driven methods is explored, eliminating the need for an accurate process model which may be tedious to obtain. However, the attack's implementation using actual/valid operational data to replicate normal behaviour, makes it difficult to detect using basic data-driven methods, resulting in an increased likelihood of false alarms or missed detection. To address this challenge, a two-stage detection and verification framework is proposed. The first stage performs real-time monitoring of sensor measurements using change-point detection on time series data patterns. The second stage verifies the occurrence of a replay attack by introducing spatial features to newly defined time series data. This framework therefore eliminates false/missed detection, and offers practitioners a robust method to enhance security measures in industrial control systems, minimising the risks posed by malicious replay attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
yuhaha完成签到,获得积分10
刚刚
爱笑完成签到,获得积分10
刚刚
哈哈完成签到 ,获得积分10
刚刚
nyfz2002发布了新的文献求助10
1秒前
1秒前
LXX-k完成签到,获得积分10
1秒前
问问大哥发布了新的文献求助200
2秒前
心灵美的山蝶完成签到,获得积分10
2秒前
宋呵呵完成签到 ,获得积分10
2秒前
深情安青应助lipc采纳,获得10
3秒前
传奇3应助hao采纳,获得10
3秒前
雷小牛完成签到 ,获得积分10
3秒前
薛洁洁完成签到 ,获得积分10
3秒前
unborned完成签到 ,获得积分10
3秒前
4秒前
冷静芹菜完成签到 ,获得积分10
4秒前
太阳风暴剑完成签到,获得积分10
6秒前
bkagyin应助西屋采纳,获得10
7秒前
丫丫完成签到 ,获得积分10
7秒前
完美世界应助edisondc采纳,获得10
9秒前
闪闪的飞兰完成签到,获得积分10
9秒前
daijk发布了新的文献求助30
10秒前
saxg_hu完成签到,获得积分10
10秒前
mojojo完成签到 ,获得积分10
10秒前
烟花应助a7489420采纳,获得10
10秒前
海洋完成签到,获得积分10
11秒前
will_fay完成签到,获得积分10
11秒前
18°N天水色完成签到,获得积分10
11秒前
小十二完成签到,获得积分10
11秒前
zhangpeng完成签到,获得积分10
11秒前
D_Kuromi完成签到,获得积分10
11秒前
fyl完成签到,获得积分10
11秒前
雷大帅完成签到,获得积分10
12秒前
琉琉硫完成签到,获得积分20
13秒前
alalalal发布了新的文献求助10
13秒前
方方完成签到,获得积分10
14秒前
成梦完成签到,获得积分10
14秒前
今日不再蛇皇完成签到,获得积分10
15秒前
刘孝鹏完成签到,获得积分10
15秒前
跳跳妈妈完成签到,获得积分10
18秒前
高分求助中
Evolution 10000
Distribution Dependent Stochastic Differential Equations 500
A new species of Coccus (Homoptera: Coccoidea) from Malawi 500
A new species of Velataspis (Hemiptera Coccoidea Diaspididae) from tea in Assam 500
PraxisRatgeber: Mantiden: Faszinierende Lauerjäger 500
The Kinetic Nitration and Basicity of 1,2,4-Triazol-5-ones 440
Die Gottesanbeterin: Mantis religiosa: 656 400
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3158752
求助须知:如何正确求助?哪些是违规求助? 2809955
关于积分的说明 7884750
捐赠科研通 2468704
什么是DOI,文献DOI怎么找? 1314374
科研通“疑难数据库(出版商)”最低求助积分说明 630601
版权声明 602012