A Deep Learning-based Framework for Conducting Stealthy Attacks in Industrial Control Systems

A Deep Learning-based Framework for Conducting Stealthy Attacks in Industrial Control Systems
复制标题

DOI:
--
复制
发表时间:
2017-09
期刊:
ArXiv
影响因子:
--
通讯作者:
Cheng Feng;Tingting Li;Zhanxing Zhu;D. Chana
Cheng Feng;Tingting Li;Zhanxing Zhu;D. Chana
中科院分区:
其他
文献类型:
--
作者:
Cheng Feng;Tingting Li;Zhanxing Zhu;D. Chana

文献摘要

被引文献

相似文献

工业控制系统(ICS)在许多情况下是关键的国家基础设施的组成部分,越来越多地连接到其他网络和更广泛的互联网,其动机是增强操作功能和提高效率。然而,在这种背景下,很容易看到这些系统的网络攻击面正在扩大,因此开发用于保护ICS的创新解决方案以及充分理解这些解决方案的局限性比以往任何时候都更加重要。基于异常的入侵检测技术的发展提供了保护ICS免受严重物理损害的能力,网络入侵能够通过监测传感器和控制信号的异常活动来传递给他们。最近,已经证明了所谓的隐形攻击的使用,其中注入错误的传感器测量值可以用于模仿正常的控制系统信号,从而击败异常检测器,同时仍然提供攻击目标。在本文中,我们定义了一个基于深度学习的框架,该框架允许攻击者利用目标ICS的最小先验知识进行隐形攻击。具体来说,我们表明,通过拦截传感器和/或控制信号在ICS的一段时间内,恶意程序能够自动学习生成高质量的隐形攻击,可以实现特定的攻击目标,同时绕过黑盒异常检测器。此外,我们证明了我们的框架进行隐形攻击使用两个现实世界的ICS案例研究的有效性。我们认为,我们的研究结果激发了安全界对这一领域的更多关注,因为我们证明,目前假设的成功执行此类攻击的障碍是放松的。
Industrial control systems (ICS), which in many cases are components of critical national infrastructure, are increasingly being connected to other networks and the wider internet motivated by factors such as enhanced operational functionality and improved efficiency. However, set in this context, it is easy to see that the cyber attack surface of these systems is expanding, making it more important than ever that innovative solutions for securing ICS be developed and that the limitations of these solutions are well understood. The development of anomaly based intrusion detection techniques has provided capability for protecting ICS from the serious physical damage that cyber breaches are capable of delivering to them by monitoring sensor and control signals for abnormal activity. Recently, the use of so-called stealthy attacks has been demonstrated where the injection of false sensor measurements can be used to mimic normal control system signals, thereby defeating anomaly detectors whilst still delivering attack objectives. In this paper we define a deep learning-based framework which allows an attacker to conduct stealthy attacks with minimal a-priori knowledge of the target ICS. Specifically, we show that by intercepting the sensor and/or control signals in an ICS for a period of time, a malicious program is able to automatically learn to generate high-quality stealthy attacks which can achieve specific attack goals whilst bypassing a black box anomaly detector. Furthermore, we demonstrate the effectiveness of our framework for conducting stealthy attacks using two real-world ICS case studies. We contend that our results motivate greater attention on this area by the security community as we demonstrate that currently assumed barriers for the successful execution of such attacks are relaxed.