Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear Approximations

Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear Approximations
复制标题

DOI:
10.1109/rtss49844.2020.00028
复制
发表时间:
2020-12
期刊:
2020 IEEE Real-Time Systems Symposium (RTSS)
影响因子:
--
通讯作者:
Lin Zhang;Xin Chen;Fanxin Kong;A. Cárdenas
Lin Zhang;Xin Chen;Fanxin Kong;A. Cárdenas
中科院分区:
其他
文献类型:
--
作者:
Lin Zhang;Xin Chen;Fanxin Kong;A. Cárdenas

文献摘要

被引文献

相似文献

攻击检测和恢复是安全和弹性网络物理系统运行的基本要素。大部分的文献集中在攻击检测,而离开攻击恢复作为一个开放的问题。在本文中,我们提出了新的攻击恢复控制,以确保网络物理系统。我们的恢复控制包括安全响应攻击所需的新概念,其中包括删除中毒数据,估计当前状态,预测可达状态,以及在线设计一个新的控制器来恢复系统。到目前为止,这种恢复控制器的综合信息物理系统几乎没有调查。为了填补这一空白,我们提出了一个正式的方法为基础的方法来在线计算的恢复控制序列,引导系统下正在进行的传感器攻击从当前状态到目标状态,这样就没有不安全的状态是可达的方式。该方法解决了线性时不变(LTI)模型的可达性问题,并考虑了误差界ε ≥ 0.当线性时不变模型与被控对象动态特性之间的行为差异不大于ε时,保证了所得到的恢复控制对原系统的作用。由于恢复控制应在系统运行时获得和应用,为了保持其计算时间成本尽可能低,我们的方法首先建立一个线性规划约束与相应的约束安全性和目标规格为给定的到达-避免问题,然后使用线性规划求解器找到一个解决方案。为了证明我们的方法的有效性,我们提供了(a)在3个传感器攻击场景下的5个系统模型的比较:修改,延迟和答复;(B)可扩展性分析的基础上的可扩展性模型来评估我们的方法在大规模系统上的性能。
Attack detection and recovery are fundamental elements for the operation of safe and resilient cyber-physical systems. Most of the literature focuses on attack-detection, while leaving attack-recovery as an open problem. In this paper, we propose novel attack-recovery control for securing cyber-physical systems. Our recovery control consists of new concepts required for a safe response to attacks, which includes the removal of poisoned data, the estimation of the current state, a prediction of the reachable states, and the online design of a new controller to recover the system. The synthesis of such recovery controllers for cyber-physical systems has barely investigated so far. To fill this void, we present a formal method-based approach to online compute a recovery control sequence that steers a system under an ongoing sensor attack from the current state to a target state such that no unsafe state is reachable on the way. The method solves a reach-avoid problem on a Linear Time-Invariant (LTI) model with the consideration of an error bound ε ≥ 0. The obtained recovery control is guaranteed to work on the original system if the behavioral difference between the LTI model and the system’s plant dynamics is not larger than ε. Since a recovery control should be obtained and applied at the runtime of the system, in order to keep its computational time cost as low as possible, our approach firstly builds a linear programming restriction with the accordingly constrained safety and target specifications for the given reach-avoid problem, and then uses a linear programming solver to find a solution. To demonstrate the effectiveness of our method, we provide (a) the comparison to the previous work over 5 system models under 3 sensor attack scenarios: modification, delay, and reply; (b) a scalability analysis based on a scalable model to evaluate the performance of our method on large-scale systems.