Channel-State-Based Fingerprinting against Physical Access Attack in Industrial Field Bus Network

Channel-State-Based Fingerprinting against Physical Access Attack in Industrial Field Bus Network
复制标题

针对工业现场总线网络中物理访问攻击的基于通道状态的指纹识别

DOI:
10.1109/jiot.2021.3126461
复制
发表时间:
2021
影响因子:
10.6
通讯作者:
T. Liu
T. Liu
中科院分区:
计算机科学1区
文献类型:
--
作者:
P. Liu;Y. Liu;X. Wang;C. Fang;X. Guan;T. Liu

文献摘要

被引文献

相似文献

工业物联网的发展使工业控制系统更容易受到网络攻击。为了防止上层IP网络中的攻击,已经提出了许多防御措施。然而,底层现场总线网络的安全性还没有得到足够的重视。攻击者可以通过未经授权的物理访问将入侵设备接入现场总线网络。由于攻击者的行为在窃听或窃听时具有高度的隐蔽性,因此通过网络流量识别这些不活动的入侵设备具有挑战性和成本。然而,可以利用由侵入设备引起的信道状态的不可避免的变化来检测未经授权的物理访问。从理论上证明了现场总线网络接入侵入设备后,传输信号的电压幅值会发生变化。利用信号的变化,我们提出了一种未经授权的物理访问检测方法,通过指纹的信道状态。具体而言,我们采用弱信号处理技术来恢复信号的弱变化,并提取其特征进行检测。基于一个真实的试验平台验证了该检测方法的有效性。仿真实验结果表明,该方法能有效检测不同场景下的入侵设备。
The development of Industrial Internet of Things has made industrial control systems more vulnerable to cyber attacks. Many defense measures have been proposed to prevent attacks in upper IP-based networks. However, the security of underlying field bus networks has not received enough attention. Adversaries could tap intrusive devices into the field bus network via unauthorized physical access. As adversaries’ behaviors could be highly concealed when they are eavesdropping or camouflaging, it is challenging and costly to identify these inactive intrusive devices through the network traffic. However, inevitable changes in channel state caused by intrusive devices could be leveraged to detect unauthorized physical access. This article theoretically proves that the transmitted signal’s voltage amplitude would vary after tapping intrusive devices into the field bus network. Leveraging the signal’s variation, we propose an unauthorized physical access detection method via fingerprinting the channel state. Specifically, we adopt weak signal processing technologies to recover the signal’s weak variation and extract its features for detection. The effectiveness of the proposed detection method is validated based on a real testbed. Moreover, simulation experiments with diverse settings demonstrate that the proposed detection method could successfully detect intrusive devices under different scenarios.