A control‐switching approach for cyberattack detection in process systems with minimal false alarms

A control‐switching approach for cyberattack detection in process systems with minimal false alarms
复制标题

一种用于过程系统中网络攻击检测的控制切换方法,可最大限度地减少误报

DOI:
10.1002/aic.17875
复制
发表时间:
2022
期刊:
影响因子:
3.7
通讯作者:
Ellis, Matthew J.
Ellis, Matthew J.
中科院分区:
工程技术3区
文献类型:
--
作者:
Narasimhan, Shilpa;El‐Farra, Nael H.;Ellis, Matthew J.

文献摘要

相似文献

近年来,针对过程控制系统的网络攻击频率有所增加。这项工作考虑了乘性虚假数据注入攻击,该攻击涉及将传感器-控制器通信链路上传递的数据乘以一个因子。提出了一种在两种控制模式之间切换的主动检测方法,以平衡闭环性能和攻击检测能力之间的平衡。在第一种模式下,控制参数的选择采用传统的控制设计准则。在第二种模式下,选择控制参数以增强攻击检测能力。施加切换条件以防止可能由控制模式切换引起的瞬时响应触发的错误报警。这种情况被结合到主动检测方法中,以最大限度地减少错误警报。该主动检测方法被应用于说明性的过程实例,以展示其检测攻击和最大限度地减少错误警报的能力。
The frequency of cyberattacks against process control systems has increased in recent years. This work considers multiplicative false‐data injection attacks involving the multiplication of the data communicated over the sensor‐controller communication link by a factor. An active detection method utilizing switching between two control modes is developed to balance the trade‐off between closed‐loop performance and attack detectability. Under the first mode, the control parameters are selected using traditional control design criteria. Under the second mode, the control parameters are selected to enhance the attack detection capability. A switching condition is imposed to prevent false alarms that could be triggered by the transient response induced by control mode switching. This condition is incorporated into the active detection method to minimize false alarms. The active detection method is applied to illustrative process examples to demonstrate its ability to detect attacks and minimize false alarms.