From System Specification to Anomaly Detection (and back)

From System Specification to Anomaly Detection (and back)
复制标题

从系统规范到异常检测(以及返回)

DOI:
--
复制
发表时间:
2017
期刊:
CPS-SPC@CCS
影响因子:
--
通讯作者:
S. Tonetta
S. Tonetta
中科院分区:
--
文献类型:
--
作者:
D. Fauri;D. R. D. Santos;Elisa Costante;J. Hartog;S. Etalle;S. Tonetta

文献摘要

被引文献

相似文献

工业控制系统具有严格的安全和安保要求。通过指定可能存在故障的系统并对其进行监控以确保这些故障得到妥善解决,可以获得高度的安全保证。解决安全问题需要考虑不可预测的攻击者行为。异常检测,其数据驱动的方法,可以检测到简单的不寻常的行为和基于系统的攻击,如恶意软件的传播;另一方面,异常检测不太适合检测更复杂的基于进程的攻击,并且它在存在警报的情况下几乎不提供可操作性。异常检测的替代方案是使用基于规范的入侵检测,它更适合检测基于进程的攻击,但通常设置成本高,可扩展性差。我们建议联合收割机结合一个轻量级的正式系统规范与异常检测,提供数据驱动的监测。该组合基于将规范的元素映射到网络流量的元素。这允许从正式规范中提取要监视的位置和相关的上下文信息,从而在语义上丰富所引发的警报并使其可操作。另一方面,它还允许在正式模型中对基于数据的属性进行欠规范;一些谓词可以不被解释,而监控可以用来学习它们的模型。我们在一个智能制造用例上展示了我们的方法。
Industrial control systems have stringent safety and security demands. High safety assurance can be obtained by specifying the system with possible faults and monitoring it to ensure these faults are properly addressed. Addressing security requires considering unpredictable attacker behavior. Anomaly detection, with its data driven approach, can detect simple unusual behavior and system-based attacks like the propagation of malware; on the other hand, anomaly detection is less suitable to detect more complex emph{process-based} attacks and it provides little actionability in presence of an alert. The alternative to anomaly detection is to use specification-based intrusion detection, which is more suitable to detect process-based attacks, but is typically expensive to set up and less scalable. We propose to combine a lightweight formal system specification with anomaly detection, providing data-driven monitoring. The combination is based on mapping elements of the specification to elements of the network traffic. This allows extracting locations to monitor and relevant context information from the formal specification, thus semantically enriching the raised alerts and making them actionable. On the other hand, it also allows under-specification of data-based properties in the formal model; some predicates can be left uninterpreted and the monitoring can be used to learn a model for them. We demonstrate our methodology on a smart manufacturing use case.