Power-Grid Controller Anomaly Detection with Enhanced Temporal Deep Learning

Power-Grid Controller Anomaly Detection with Enhanced Temporal Deep Learning
复制标题

DOI:
10.1109/trustcom/bigdatase.2019.00030
复制
发表时间:
2018-06
期刊:
2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/13th IEEE International Conference On Big Data Science And Engineering (TrustCom/BigDataSE)
影响因子:
--
通讯作者:
Zecheng He;Aswin Raghavan;Guangyuan Hu;S. Chai;Ruby B. Lee
Zecheng He;Aswin Raghavan;Guangyuan Hu;S. Chai;Ruby B. Lee
中科院分区:
其他
文献类型:
--
作者:
Zecheng He;Aswin Raghavan;Guangyuan Hu;S. Chai;Ruby B. Lee

文献摘要

被引文献

相似文献

对安全至关重要的网络物理系统(如电网)的控制器是一类非常重要的计算机系统。针对电网系统控制代码的攻击,尤其是零日攻击,可能是灾难性的。及早发现异常可以防止进一步的损害。然而,检测零日攻击是极具挑战性的,因为它们没有已知的代码和未知的行为。此外,如果从控制器收集的数据通过网络传输到服务器进行异常行为的分析和检测,这将创建一个非常大的攻击面,并且还会延迟检测。为了解决这个问题,我们提出了硬件性能计数器(hpc)的重构误差分布(RED),并在此基础上建立了一个数据驱动防御系统。具体来说,我们首先训练一个时间深度学习模型,仅使用这些电网系统中每天运行的合法进程的正常HPC读数来模拟电网控制器的正常行为。然后,我们使用来自常用hpc的实时数据运行该模型。通过使用有效的统计检验估计正常行为的分布偏差,我们使用所提出的RED来增强对异常行为的时间深度学习检测。在实际电网控制器上的实验结果表明,该方法能够以高准确率(99.9%)、接近零误报和短延迟(<360ms)检测异常行为。
Controllers of security-critical cyber-physical systems, like the power grid, are a very important class of computer systems. Attacks against the control code of a power-grid system, especially zero-day attacks, can be catastrophic. Earlier detection of the anomalies can prevent further damage. However, detecting zero-day attacks is extremely challenging because they have no known code and have unknown behavior. Furthermore, if data collected from the controller is transferred to a server through networks for analysis and detection of anomalous behavior, this creates a very large attack surface and also delays detection. In order to address this problem, we propose Reconstruction Error Distribution (RED) of Hardware Performance Counters (HPCs), and a data-driven defense system based on it. Specifically, we first train a temporal deep learning model, using only normal HPC readings from legitimate processes that run daily in these power-grid systems, to model the normal behavior of the power-grid controller. Then, we run this model using real-time data from commonly available HPCs. We use the proposed RED to enhance the temporal deep learning detection of anomalous behavior, by estimating distribution deviations from the normal behavior with an effective statistical test. Experimental results on a real power-grid controller show that we can detect anomalous behavior with high accuracy (>99.9%), nearly zero false positives and short (<360ms) latency.