CRII: SaTC: Preempting Physical Damage from Control-Related Attacks on Smart Grids' Cyber-Physical Infrastructure
CRII: SaTC: Preempting Physical Damage from Control-Related Attacks on Smart Grids' Cyber-Physical Infrastructure
批准号:
2041643
负责人:
Hui Lin
金额:
$14.87万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-08-10 至 2022-05-31
中文摘要
与控制相关的攻击是对智能电网等网络物理系统(CPS)的严重威胁,因为它们可以通过使用以合法格式制作的恶意控制命令来引入灾难性的物理损坏。虽然目前的研究工作集中在检测导致物理损害的恶意命令,但研究人员建议通过在发布恶意命令之前破坏和误导对手的准备来先发制人地防止损害。为了实现这一目标,建议的工作包括:(一)表征智能电网中的网络和物理域的正常活动之间的依赖关系;(二)确定一个网络欺骗范例,以破坏对手的智能电网的知识,通过注入网络数据包代表不存在的计算节点;(三)制作诱饵测量,误导对手设计无损害的攻击策略。拟议的工作将使用软件定义网络(SDN)来防止智能电网的物理损坏,而不改变电网的物理基础设施。随着SDN在不同CPS中的广泛使用,这项工作可以作为未来研究的基础,扩展到更广泛的CPS和物联网领域,连接来自不同应用的设备,如智能健康和智能家居。由于CPS公司正在用先进的网络技术升级他们的网络基础设施,这项工作在真实的公用事业环境中具有很好的应用前景,以提高他们的弹性。拟议的工作有可能将当前的被动检测方法转变为先发制人的方法,用误导性的信息解除对手的武装。这项工作包括以下重点:(i)通过结合数据分析和系统规范,开发跨学科方法,以确定网络和物理领域活动之间的依赖关系。在Bro网络分析仪支持的深度包网络监测所收集的真实的数据的驱动下,这些方法将通过整合来自不同学科的知识,揭示智能电网的全面运行逻辑。(ii)创建基于SDN的平台,以确定类似于正常活动的网络欺骗范例。通过在Bro网络分析仪和SDN网络控制器之间建立交互,研究人员将使用系统活动的建模来注入与正常流量在统计上无法区分的网络流量,以防止对手了解真实的系统配置,而不会影响合法的应用程序。(iii)创建一个算法来制作误导对手的诱饵测量。为了制作欺骗数据包的应用层有效载荷,调查人员将把对手的攻击准备过程建模为优化问题,从而确定诱饵测量,这些诱饵测量将误导对手设计针对不存在的组件的攻击,从而导致很少的物理损害。(iv)使用网络物理测试平台验证所提出的先发制人的方法,该测试平台集成了真实的SDN支持的交换机和由真实的运行数据驱动的电力系统模拟。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Control-related attacks are a severe threat to cyber-physical systems (CPSs) such as smart grids, because they can introduce catastrophic physical damage by using malicious control commands crafted in a legitimate format. While current research efforts have focused on detecting malicious commands that lead to physical damage, the investigator proposes to preemptively prevent the damage by disrupting and misleading adversaries' preparation before they issue the malicious commands. To achieve this objective, the proposed work includes: (i) characterizing dependencies between normal activities from both the cyber and physical domains in smart grids; (ii) determining a network spoofing paradigm to disrupt adversaries' knowledge of smart grids by injecting network packets on behalf of nonexistent computing nodes; and (iii) crafting decoy measurements to mislead adversaries into designing damage-free attack strategies. The proposed work will use software-defined networking (SDN) to prevent physical damage in smart grids without changing the grids' physical infrastructure. With the wide use of SDN in different CPSs, this work may serve as the basis for future research that extends to the broader domains of CPS and Internet-of-Things, which connect devices from different applications, such as smart health and smart home. Since CPS companies are upgrading their cyberinfrastructure with advanced network technologies, this work has promising applications in real utility environments to increase their resilience.The proposed work has the potential to transform current passive detection methods into preemptive approaches that disarm adversaries with misleading information. This work includes the following thrusts: (i) Development of interdisciplinary methods to identify dependencies between activities from the cyber and physical domains by combining data analytics and system specifications. Driven by real data collected from deep-packet network monitoring enabled by the Bro network analyzer, these methods will reveal the thorough operational logic of smart grids by integrating knowledge from different disciplines. (ii) Creation of an SDN-based platform to determine a network spoofing paradigm that resembles normal activities. By establishing interactions between the Bro network analyzer and SDN network controllers, the investigator will use the modeling of system activities to inject network traffic that is statistically indistinguishable from normal traffic to prevent adversaries from learning the true system configuration, without affecting legitimate applications. (iii) Creation of an algorithm to craft decoy measurements that mislead adversaries. To craft the application-layer payload of the spoofed packets, the investigator will model adversaries' attack preparation procedure as an optimization problem and thus determine decoy measurements that will mislead adversaries into designing attacks that target nonexistent components to thus induce little if any physical damage. (iv) Validation of the proposed preemptive approach using a cyber-physical testbed that integrates real SDN-enabled switches and power system simulations driven by real operational data.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DefRec: Establishing Physical Function Virtualization to Disrupt Reconnaissance of Power Grids' Cyber-Physical Infrastructures
DefRec:建立物理功能虚拟化以中断电网网络物理基础设施的侦察
DOI:
10.14722/ndss.2020.24365
发表时间:
2020
期刊:
Network and Distributed Systems Security (NDSS
影响因子:
--
作者:
[Lin, Hui, Zhuang, Jianing, Hu, Yih-Chun, Zhou, Huayu]
通讯作者:
Zhou, Huayu
Cyber-Physical Testbed: Case Study to Evaluate Anti-Reconnaissance Approaches on Power Grids’ Cyber-Physical Infrastructures
网络物理测试台:评估电网反侦察方法的案例研究 – 网络物理基础设施
DOI:
--
发表时间:
2022
期刊:
Proceedings of Learning from Authoritative Security Experiment Results (LASER
影响因子:
--
作者:
[Hui Lin, Bibek Shrestha]
通讯作者:
Hui Lin, Bibek Shrestha
Challenges and Opportunities in the Detection of Safety-Critical Cyberphysical Attacks
检测安全关键型网络物理攻击的挑战和机遇
DOI:
10.1109/mc.2019.2915045
发表时间:
2020
期刊:
Computer
影响因子:
2.2
作者:
[Lin, Hui, Alemzadeh, Homa, Kalbarczyk, Zbigniew, Iyer, Ravishankar]
通讯作者:
Iyer, Ravishankar
Collaborative Research: SaTC: CORE: Small: Enabling Programmable In-Network Security for an Attack-Resilient Smart Grid
-
批准号:2247722
-
项目类别:Standard Grant
-
资助金额:$28.0万
-
财政年份:2023
-
负责人:Hui Lin
-
依托单位:
CAREER: PARP: Mislead Physical-Disruption Attacks by Preemptive Anti-Reconnaissance for Power Grids Cyber-Physical Infrastructures
-
批准号:2144513
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2022
-
负责人:Hui Lin
-
依托单位:
CRII: SaTC: Preempting Physical Damage from Control-Related Attacks on Smart Grids' Cyber-Physical Infrastructure
-
批准号:1850377
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2019
-
负责人:Hui Lin
-
依托单位:
海外基金