Deep-Learning Approach to the Detection and Localization of Cyber-Physical Attacks on Water Distribution Systems

Deep-Learning Approach to the Detection and Localization of Cyber-Physical Attacks on Water Distribution Systems
复制标题

DOI:
10.1061/(asce)wr.1943-5452.0000983
复制
发表时间:
2018-10-01
影响因子:
3.1
通讯作者:
Galelli, Stefano
Galelli, Stefano
中科院分区:
环境科学与生态学3区
文献类型:
--
作者:
Taormina, Riccardo;Galelli, Stefano

文献摘要

被引文献

相似文献

最近,针对水处理厂和分配系统的网络物理攻击的频率和严重性不断增加,需要开发有助于保护这些关键基础设施的入侵检测方案。本文提供了一种专门用于检测和定位针对供水系统的网络攻击的算法。该算法建立在学习数据驱动模型的理念之上,该模型可重现配电系统中观察到的所有水力过程的模式:该模型使用与正常操作条件相关的数据进行训练,以便不良地重现异常模式,例如由网络攻击引起的异常模式。建模过程是使用自动编码器进行的,自动编码器是一种深度学习神经网络架构,能够构建高维输入数据模式的压缩且有意义的表示。该算法是在为攻击检测算法之战设计的三个数据集上开发和测试的,这是现阶段唯一可用的开源数据,用于水网络网络安全的研究。结果表明,检测算法可以识别数据集中的所有攻击,包括那些损害数据完整性的攻击。该算法还有两个重要的功能:它定位受到攻击的组件,并且仅使用与正常操作条件相关的数据来开发,这些数据通常可供自来水公司使用。
The recent increase in frequency and severity of cyber-physical attacks on water treatment plants and distribution systems calls for the development of intrusion detection schemes that help protect these critical infrastructures. This paper contributes an algorithm specifically designed for detecting and localizing cyber attacks against water distribution systems. The algorithm builds on the idea of learning a data-driven model that reproduces the patterns of all hydraulic processes observed within a distribution system: the model is trained using data pertaining to normal operating conditions, in order to poorly reproduce anomalous patterns, such as those induced by cyber attacks. The modeling process is carried out using autoencoders, a deep learning neural network architecture capable of building a compressed and meaningful representation of high-dimensional input data patterns. The algorithm is developed and tested on three data sets devised for the Battle of the Attack Detection Algorithmsthe only open-source data available, at this stage, for research in cyber security of water networks. Results show that the detection algorithm can identify all attacks featured in the data sets, including those compromising data integrity. The algorithm has two additional important features: it localizes the components under attack, and it is developed using only data pertaining to normal operating conditions, which are generally available to water utilities.