SRID: State Relation Based Intrusion Detection for False Data Injection Attacks in SCADA

SRID: State Relation Based Intrusion Detection for False Data Injection Attacks in SCADA
复制标题

SRID:针对 SCADA 中虚假数据注入攻击的基于状态关系的入侵检测

DOI:
10.1007/978-3-319-11212-1_23
复制
发表时间:
2014
影响因子:
35.6
通讯作者:
G. Gu
G. Gu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yong Wang;Zhaoyan Xu;Jialong Zhang;Lei Xu;Haopei Wang;G. Gu

文献摘要

被引文献

相似文献

定向恶意软件入侵中的高级虚假数据注入攻击正在成为监控和数据采集SCADA系统的一个新的严重威胁。以前已经提出了几种入侵检测方案[1,2]。然而,为资源受限的设备设计有效的实时检测系统仍然是研究界的一个悬而未决的问题。在本文中,我们提出了一种新的基于关系图的检测方案,以对抗SCADA系统中的虚假数据注入攻击,即使注入的数据可能似乎落在有效/正常范围内。为了平衡有效性和效率,我们设计了一种新的检测模型--状态关系图交替向量。此外,我们还提出了一种新的推理算法来推断系统中的注入点,即攻击来源。我们用一个真实的发电厂模拟器来评估SRID。实验结果表明,该算法能够检测出各种虚假数据注入攻击,误检率为0.0125%。同时,SRID能够极大地缩小攻击源的搜索空间,准确定位大部分攻击源。
Advanced false data injection attack in targeted malware intrusion is becoming an emerging severe threat to the Supervisory Control And Data Acquisition SCADA system. Several intrusion detection schemes have been proposed previously [1, 2]. However, designing an effective real-time detection system for a resource-constraint device is still an open problem for the research community. In this paper, we propose a new relation-graph-based detection scheme to defeat false data injection attacks at the SCADA system, even when injected data may seemly fall within a valid/normal range. To balance effectiveness and efficiency, we design a novel detection model, alternation vectors with state relation graph. Furthermore, we propose a new inference algorithm to infer the injection points, i.e., the attack origin, in the system. We evaluate SRID with a real-world power plant simulator. The experiment results show that SRID can detect various false data injection attacks with a low false positive rate at 0.0125%. Meanwhile, SRID can dramatically reduce the search space of attack origins and accurately locate most of attack origins.