Early Cyberattack Warning and Response System for MIL-STD-1553 Platforms using Unsupervised Anomaly Detection
Early Cyberattack Warning and Response System for MIL-STD-1553 Platforms using Unsupervised Anomaly Detection
批准号:
560451-2020
负责人:
TRAORE, ISSA
金额:
$6.99万
依托单位:
依托单位国家:
加拿大
项目类别:
Alliance Grants
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31
中文摘要
MIL-STD-1553 是一种军事标准通信协议,已有四十多年的历史,对于各种防御平台的运行至关重要。在制定之初,该标准的构思仅关注可靠性和容错性,而没有关注安全问题。然而,过去几年的情况表明,现代防御平台越来越成为国家和非国家行为者网络攻击的目标。在这种背景下,MIL-STD-1553 数据总线代表了破坏依赖其进行通信的防御平台的主要渠道。拟议项目的目的是探索针对 MIL-STD-1553 数据总线的一系列网络攻击,在测试台中执行相应的攻击场景以生成数据集,并利用该数据集开发一种方案,以使用无监督机器学习模型检测此类攻击。拟议的检测方案将针对 MIL-STD-1553 协议进行定制,并针对针对该平台的更广泛的攻击。 该系统将结合两个不同的传感器,它们协同工作来检测入侵事件。第一个传感器将为通过总线交互的每个组件构建单独的消息传递配置文件,并跟踪它们的行为以识别伪装攻击。 第二个传感器将建立总线上发生的消息传递活动的基线,并使用统计变化点检测来识别一系列异常活动。 该项目将与加拿大网络安全公司 Streamscan 合作进行。
英文摘要
MIL-STD-1553 is a military standard communication protocol that has been around for over four decades and is central to the operation of a wide range of defense platforms. At its inception, the standard was conceived with a focus only on reliability and fault tolerance, with no attention paid to security concerns. However, it has been shown in the last few years that modern defense platforms are increasingly the target of cyber attacks from both state and non-state actors. In such context, MIL-STD-1553 data buses represent prime conduits for compromising defense platforms that rely on them for communications. The purpose of the proposed project is to explore a range of cyberattack against MIL-STD-1553 data buses, execute corresponding attack scenarios in a testbed to generate a dataset, and leverage the dataset to develop a scheme to detect such attacks using unsupervised machine learning models. The proposed detection scheme will be tailored for the MIL-STD-1553 protocol and target a broader range of attacks aimed at this platform. The system will combine two different sensors that work in tandem to detect intrusive events. The first sensor will build a separate messaging profile for each of the components interacting via the bus, and track their behavior in order to identify masquerade attacks. The second sensor will build a baseline of the messaging activity occurring over the bus, and use statistical change point detection to identify a range of anomalous activities. The project will be conducted in partnership with Streamscan, a Canadian cybersecurity company.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金