Supervisory Control of Discrete-Event Systems Under Attacks

Supervisory Control of Discrete-Event Systems Under Attacks
复制标题

DOI:
10.1007/s13235-018-0285-3
复制
发表时间:
2019-12-01
影响因子:
1.5
通讯作者:
Hespanha, Joao P.
Hespanha, Joao P.
中科院分区:
数学4区
文献类型:
--
作者:
Wakaiki, Masashi;Tabuada, Paulo;Hespanha, Joao P.

文献摘要

被引文献

相似文献

我们考虑离散事件系统(DES)的监督控制问题的多对手版本,其中对手破坏了监督者可用的观察结果。监督者的目标是强制执行特定的语言,无论对手的行为如何,并且不知道它正在对抗哪个对手。这个问题是由计算机安全应用引起的,其中网络防御系统必须根据可能被攻击者篡改的传感器的报告做出决策。我们首先表明,当且仅当所需的语言是可控的(在 DES 经典意义上)并且在考虑对手的(新颖)意义上是可观察的时,问题才有解决方案。对于将符号插入传感器输出序列或从传感器输出序列中删除符号的攻击的特定情况,我们表明,可以使用为经典 DES 监督控制问题开发的工具来测试监督者的存在并构建监督者,通过考虑具有修改后的输出映射的自动机系列,但不会扩展状态空间的大小,也不会在所考虑的攻击数量上产生指数复杂性。
We consider a multi-adversary version of the supervisory control problem for discrete-event systems (DES), in which an adversary corrupts the observations available to the supervisor. The supervisor's goal is to enforce a specific language in spite of the opponent's actions and without knowing which adversary it is playing against. This problem is motivated by applications to computer security in which a cyber defense system must make decisions based on reports from sensors that may have been tampered with by an attacker. We start by showing that the problem has a solution if and only if the desired language is controllable (in the DES classical sense) and observable in a (novel) sense that takes the adversaries into account. For the particular case of attacks that insert symbols into or remove symbols from the sequence of sensor outputs, we show that testing the existence of a supervisor and building the supervisor can be done using tools developed for the classical DES supervisory control problem, by considering a family of automata with modified output maps, but without expanding the size of the state space and without incurring on exponential complexity on the number of attacks considered.