Integrating Design and Data Centric Approaches to Generate Invariants for Distributed Attack Detection

Integrating Design and Data Centric Approaches to Generate Invariants for Distributed Attack Detection
复制标题

集成设计和以数据为中心的方法来生成分布式攻击检测的不变量

DOI:
--
复制
发表时间:
2017
期刊:
CPS-SPC@CCS
影响因子:
--
通讯作者:
Sridhar Adepu
Sridhar Adepu
中科院分区:
--
文献类型:
--
作者:
Muhammad Umer;A. Mathur;K. N. Junejo;Sridhar Adepu

文献摘要

被引文献

相似文献

进程异常用于检测对水处理厂和发电厂等关键基础设施的网络物理攻击。使用控制工厂内过程的物理和化学行为的规则,可以识别过程异常。这些规则通常被称为不变量,可以直接从工厂设计或从运行中产生的数据推导出来。但是,对于可操作的遗留工厂,可以考虑使用以数据为中心的方法来派生不变量。本文报告的研究比较了以设计为中心和以数据为中心的派生流程不变量的方法。这项研究是利用一个运行中的水处理厂的设计和数据进行的。研究结果支持这样一种猜想,即这两种方法本身都是不够的,因此,这两种方法应该整合在一起。
Process anomaly is used for detecting cyber-physical attacks on critical infrastructure such as plants for water treatment and electric power generation. Identification of process anomaly is possible using rules that govern the physical and chemical behavior of the process within a plant. These rules, often referred to as invariants, can be derived either directly from plant design or from the data generated in an operational. However, for operational legacy plants, one might consider a data-centric approach for the derivation of invariants. The study reported here is a comparison of design-centric and data-centric approaches to derive process invariants. The study was conducted using the design of, and the data generated from, an operational water treatment plant. The outcome of the study supports the conjecture that neither approach is adequate in itself, and hence, the two ought to be integrated.