A Data-Driven Framework for Verified Detection of Replay Attacks on Industrial Control Systems

计算机科学 工业控制系统 控制(管理) 控制系统 重放攻击 嵌入式系统 实时计算 计算机安全 工程类 人工智能 散列函数 电气工程
作者
Sara Gargoum,Negar Yassaie,Ahmad W. Al-Dabbagh,Chen Feng
出处
期刊:IEEE Transactions on Automation Science and Engineering [Institute of Electrical and Electronics Engineers]
卷期号:: 1- 被引量:2
标识
DOI:10.1109/tase.2024.3394315
摘要

This paper addresses data-driven replay attack detection on industrial control systems. The primary challenge in detection lies in distinguishing replayed sensor measurements from normal measurements using only time series data. This is tackled through a novel two-stage detection and verification framework. The first stage consists of continuous real-time monitoring of sensor measurement patterns using matrix profile based change-point detection, used to indicate a possibility of a replay attack. The second stage verifies the presence of a replay attack by introducing spatial features to newly defined time series data. This is implemented by generating spectrograms of the time series measurements using short-time Fourier transform. Then, the spectrograms are split into image frames to form temporal sequences, creating spatio-temporal features that distinguish replay attacks. To capture both the spatial and temporal features, we utilise a Convolutional Long Short-Term Memory (ConvLSTM) neural network and implement it in an autoencoder architecture, in order to analyse data patterns in an unsupervised manner, where the replay attack is detected based on the reconstruction error. We demonstrate the effectiveness of our framework in the detection of different replay attack scenarios using the Tennessee Eastman process benchmark simulation system/process. Note to Practitioners —This paper is motivated by the importance of cyberattack detection in industrial control systems that are essential for the stable operation of many practical applications, such as in chemical processing and manufacturing plants, and power and water distribution networks. Specifically, replay attack detection using data-driven methods is explored, eliminating the need for an accurate process model which may be tedious to obtain. However, the attack's implementation using actual/valid operational data to replicate normal behaviour, makes it difficult to detect using basic data-driven methods, resulting in an increased likelihood of false alarms or missed detection. To address this challenge, a two-stage detection and verification framework is proposed. The first stage performs real-time monitoring of sensor measurements using change-point detection on time series data patterns. The second stage verifies the occurrence of a replay attack by introducing spatial features to newly defined time series data. This framework therefore eliminates false/missed detection, and offers practitioners a robust method to enhance security measures in industrial control systems, minimising the risks posed by malicious replay attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
大模型应助幽默鹭洋采纳,获得10
刚刚
Mu5k完成签到,获得积分10
1秒前
TTw发布了新的文献求助10
2秒前
爆米花应助激昂的青雪采纳,获得30
2秒前
qyl1023给qyl1023的求助进行了留言
2秒前
清清完成签到,获得积分10
3秒前
3秒前
FashionBoy应助bofu采纳,获得10
3秒前
SONG完成签到,获得积分10
4秒前
8秒前
甜甜芾完成签到,获得积分10
9秒前
共享精神应助三又一十八采纳,获得10
9秒前
Mycee完成签到 ,获得积分10
10秒前
GJL完成签到,获得积分20
10秒前
小十七果发布了新的文献求助10
10秒前
TTw完成签到,获得积分10
10秒前
赵亚男关注了科研通微信公众号
10秒前
11秒前
11秒前
Dding完成签到,获得积分10
12秒前
1514536hhh发布了新的文献求助30
12秒前
清爽绣连发布了新的文献求助30
12秒前
boyue完成签到,获得积分10
12秒前
wanci应助bofu采纳,获得10
13秒前
lightsyang完成签到,获得积分10
15秒前
15秒前
16秒前
fan发布了新的文献求助10
16秒前
魔幻友菱完成签到 ,获得积分10
17秒前
17秒前
17秒前
yx_cheng应助英俊绿柏采纳,获得20
17秒前
18秒前
19秒前
19秒前
桐桐应助yyy采纳,获得10
19秒前
wu8577应助bofu采纳,获得10
20秒前
司空豁发布了新的文献求助20
20秒前
qian72133完成签到,获得积分10
21秒前
李健应助科研小扒菜采纳,获得10
21秒前
高分求助中
The Mother of All Tableaux Order, Equivalence, and Geometry in the Large-scale Structure of Optimality Theory 2400
Ophthalmic Equipment Market by Devices(surgical: vitreorentinal,IOLs,OVDs,contact lens,RGP lens,backflush,diagnostic&monitoring:OCT,actorefractor,keratometer,tonometer,ophthalmoscpe,OVD), End User,Buying Criteria-Global Forecast to2029 2000
Optimal Transport: A Comprehensive Introduction to Modeling, Analysis, Simulation, Applications 800
Official Methods of Analysis of AOAC INTERNATIONAL 600
ACSM’s Guidelines for Exercise Testing and Prescription, 12th edition 588
T/CIET 1202-2025 可吸收再生氧化纤维素止血材料 500
Interpretation of Mass Spectra, Fourth Edition 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 冶金 细胞生物学 免疫学
热门帖子
关注 科研通微信公众号,转发送积分 3956302
求助须知:如何正确求助?哪些是违规求助? 3502493
关于积分的说明 11108085
捐赠科研通 3233179
什么是DOI,文献DOI怎么找? 1787199
邀请新用户注册赠送积分活动 870515
科研通“疑难数据库(出版商)”最低求助积分说明 802105