iDDAF: An Intelligent Deceptive Data Acquisition Framework for Secure Cyber-Physical Systems

iDDAF: An Intelligent Deceptive Data Acquisition Framework for Secure Cyber-Physical Systems
复制标题

DOI:
10.1007/978-3-030-90022-9_17
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Md Hasan Shahriar;M. Rahman;Nur Imtiazul Haque;Badrul Chowdhury;S. Whisenant
Md Hasan Shahriar;M. Rahman;Nur Imtiazul Haque;Badrul Chowdhury;S. Whisenant
中科院分区:
其他
文献类型:
--
作者:
Md Hasan Shahriar;M. Rahman;Nur Imtiazul Haque;Badrul Chowdhury;S. Whisenant

文献摘要

相似文献

物联网(IoT)和网络物理系统(CPS)正在创建混合平台,这些平台在所有现代基础设施中变得无处不在。随着复杂和异构系统的集成,恶意用户可能有大量机会渗透网络,窃取敏感信息,将精心制作的虚假数据注入测量数据,或用假数据包淹没网络。这种恶意活动可能会阻止合法请求,甚至误导控制中心做出错误的决定。基于敏捷性的防御机制是强大的欺骗对手通过随机化的传感器数据在不同的通信层次。在误导攻击者的同时,控制中心必须检索实际数据以正确操作系统。现有机制考虑与控制中心共享精确的重映射模式。这种直接分享引起了对他们的进一步攻击和通信间接费用的关注。因此,我们提出了iDSPs,一个智能欺骗防御为基础的数据采集框架,利用系统不可知的预测和重新映射模型在控制器级别,以确保全面的安全解决方案(CIA黑社会)的任何分层CPS网络。在该框架中,数据报告/中继节点随机化相关联的传感器地址/ID并添加诱饵数据,而控制中心的预测机制将原始ID重新分配给测量值并在必要时估算缺失的数据。因此,任何侦察尝试都失败了,巧妙地改变测量结果变成随机数据注入,使其很容易将其作为异常值删除。在标准IEEE 14总线系统上进行的实验结果表明,iDtron可以检测并完全缓解不同类型的网络攻击。
Internet of Things (IoT) and Cyber-Physical Systems (CPSs) are creating hybrid platforms that are becoming ubiquitous in all modern infrastructure. As complex and heterogeneous systems are getting integrated, a malicious user can have tremendous opportunities to infiltrate networks, steal sensitive information, inject cleverly crafted false data into measurements, or overwhelm networks with fake packets. Such malicious activities can prevent legitimate requests or even mislead the control center to make erroneous decisions. Agility-based defense mechanisms are robust in deceiving adversaries by randomizing the sensor data at different communication hierarchy levels. While misleading the attackers, the control center must retrieve the actual data to operate the system correctly. Existing mechanisms consider sharing the exact remapping pattern with the control center. Such direct sharing raises the concern of further attacks on them and communication overheads. Hence, we propose iDDAF, an intelligent deception defense-based data acquisition framework that leverages system-agnostic prediction and remapping model at the controller level to ensure a comprehensive security solutions (CIA triad) for any hierarchical CPSs network. In this framework, the data reporting/relaying nodes randomize the associated sensor addresses/IDs and add decoy data, while the prediction mechanism at the control center reassigns the original IDs to the measurements and impute the missing data if necessary. Hence, any reconnaissance attempt fails, artfully altered measurements turn into random data injections, making it easy to remove them as outliers. Experimental results on the standard IEEE 14 bus system show that iDDAF can detect and completely mitigate different types of cyberattacks.