课题基金 / 基金详情

Active Control-Enabled Approaches for Handling Cyberattacks on Process Control Systems

Active Control-Enabled Approaches for Handling Cyberattacks on Process Control Systems
用于处理过程控制系统网络攻击的主动控制方法
批准号:
2137281
负责人:
Matthew Ellis
金额:
$32.47万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2025-05-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
美国化学工业是国民经济的重要组成部分,其制造业务采用先进的过程控制系统(PCS)实现自动化。然而,PCS对数字通信和网络技术的日益依赖,以及网络攻击技术的复杂性和复杂性的增长,使得工业PCS容易受到恶意代理的网络攻击。对PCS的网络攻击旨在破坏过程操作,可能对公共安全和繁荣造成不利影响。提高PCS网络安全的传统方法涉及加强信息技术(IT)系统,以防止网络攻击者或恶意软件访问PCS网络。然而,基于IT的网络安全方法仍然很脆弱,这促使人们在PCS设计和操作中直接考虑网络攻击的威胁。在该项目中,将开发计算和建模工具,以设计基于PCS的检测方法,这些方法能够感知工业相关流程中网络攻击的存在,以增强PCS的弹性和网络安全性。该项目的研究结果将提供基本的见解,可以检测到哪些网络攻击,以及检测灵敏度如何与PCS性能相关联。将招募本科生和研究生研究人员开展研究活动,其中包括对大规模工业流程的模拟网络攻击。总的来说,该项目的变革性影响在于创建了一个网络安全框架,该框架直接融入PCS设计考虑和后续操作,推动PCS网络安全的范式转变,不再将PCS的网络威胁完全视为IT特定问题。先进的通信和网络技术以及日益复杂的网络攻击使得工业PCS容易受到恶意代理的攻击。对PCS的网络攻击旨在破坏运营,破坏流程稳定或导致安全事故。传统上,PCS网络安全一直基于强化信息技术(IT)系统,以防止网络攻击者或恶意软件访问PCS网络。虽然提高IT安全性将防止对PCS的一些网络攻击,但攻击者可能会在过程操作员不知情的情况下长时间规避IT安全措施。基于IT的网络安全的这一基本限制促使人们采取基于控制的方法。在该项目中,将开发主动控制启用的网络攻击检测方法,以发出外部攻击信号,这些攻击操纵通过传感器-控制器和执行器-执行器链路传输的数据。这些方法将直接在PCS设计和操作中纳入网络攻击检测考虑因素。该项目的主要研究目标包括:a)确定网络攻击可检测性的基本属性,包括网络攻击可检测性验证的条件,并阐明PCS设计在网络攻击可检测性中的作用,B)制定PCS设计优化问题,以确保网络攻击的可检测性,c)开发主动网络攻击设计方法,以探测/操纵PCS来检测隐形网络攻击,以及d)将检测方法应用于模拟的基准化学过程,以展示和分析这种新的网络安全方法的性能。该项目预计将推进对网络攻击可检测性的基本理解,并开发用于网络攻击检测的新型控制启用软件工具。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The U.S chemical industry, with manufacturing operations automated using advanced process control systems (PCSs), is a critical component of the national economy. However, the increasing reliance of PCSs on digital communications and networking technologies, together with the growth in complexity and sophistication of cyberattack techniques, have rendered industrial PCSs vulnerable to cyberattacks by malicious agents. Cyberattacks on PCSs aim to disrupt process operations, potentially resulting in adverse effects on public safety and prosperity. The traditional approach for improving cybersecurity of PCSs involves fortifying information technology (IT) systems to prevent a cyberattacker or malicious software from gaining access to the PCS network. However, IT-based cybersecurity approaches remain vulnerable, motivating methods that account for the threat of cyberattacks directly in the PCS design and operation. In this project, computational and modeling tools will be developed to design PCS-based detection methods capable of sensing the presence of cyberattacks in industrially relevant processes to enhance the resiliency and cybersecurity of PCSs. The project findings will provide fundamental insights into which cyberattacks can be detected and how detection sensitivity is linked to PCS performance. Undergraduate and graduate student researchers will be recruited to carry out the research activities, those which include simulated cyberattacks on large-scale industrial processes. Overall, the transformative impact of this project is in its creation of a cybersecurity framework that is directly integrated into PCS design considerations and subsequent operation, driving a paradigm shift in PCS cybersecurity away from treating cyberthreats to PCSs exclusively as an IT-specific problem.The increasing reliance of chemical manufacturing Process Control Systems (PCSs) on advanced communications and networking technologies and the growing sophistication of cyberattacks have rendered industrial PCSs vulnerable to attacks by malicious agents. Cyberattacks on PCSs aim to disrupt operations, destabilize processes, or cause safety incidents. Traditionally, PCS cybersecurity has been based on fortifying Information Technology (IT) systems to prevent a cyberattacker or malicious software from gaining access to the PCS network. While improving IT security will prevent some cyberattacks on PCSs, an attacker may circumvent the IT security measures over extended periods of time without the knowledge of the process operators. This fundamental limitation of IT-based cybersecurity motivates a control-based approach. In this project, active control-enabled cyberattack detection methods will be developed to signal external attacks that manipulate data communicated over the sensor-controller and controller-actuator links. The methods will incorporate cyberattack detection considerations directly in the PCS design and operation. The main research objectives of the project include a) identifying the fundamental properties of cyberattack detectability, including conditions for cyberattack detectability verification, and elucidating the role of the PCS design in cyberattack detectability, b) formulating a PCS design optimization problem that ensures detectability of cyberattacks, c) developing active cyberattack design methodologies to probe/manipulate the PCS to detect stealthy cyberattacks, and d) applying the detection methods to simulated benchmark chemical processes to demonstrate and analyze the performance of this new approach to cybersecurity. The project is expected to advance the fundamental understanding of cyberattack detectability and develop novel control-enabled software tools for cyberattack detection.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
A control‐switching approach for cyberattack detection in process systems with minimal false alarms
一种用于过程系统中网络攻击检测的控制切换方法,可最大限度地减少误报
DOI: 10.1002/aic.17875
发表时间: 2022
期刊: AIChE Journal
影响因子: 3.7
作者: [Narasimhan, Shilpa, El‐Farra, Nael H., Ellis, Matthew J.]
通讯作者: Ellis, Matthew J.
DOI: 10.1016/j.jprocont.2022.05.014
发表时间: 2022-08
期刊: Journal of Process Control
影响因子: 4.2
作者: [Shilpa Narasimhan;N. El‐Farra;M. Ellis]
通讯作者: Shilpa Narasimhan;N. El‐Farra;M. Ellis
DOI: 10.23919/acc53348.2022.9867804
发表时间: 2022-06
期刊: 2022 American Control Conference (ACC)
影响因子: --
作者: [Shilpa Narasimhan;N. El‐Farra;Matthew J. Ellis]
通讯作者: Shilpa Narasimhan;N. El‐Farra;Matthew J. Ellis
A reachable set-based scheme for the detection of false data injection cyberattacks on dynamic processes
一种基于可达集的方案,用于检测动态过程中的虚假数据注入网络攻击
DOI: 10.1016/j.dche.2023.100100
发表时间: 2023
期刊: Digital Chemical Engineering
影响因子: --
作者: [Narasimhan, Shilpa, El-Farra, Nael H., Ellis, Matthew J.]
通讯作者: Ellis, Matthew J.
国内基金
海外基金
Cortical control of internal state in the insular cortex-claustrum region