Understanding the physical and economic consequences of attacks on control systems

Understanding the physical and economic consequences of attacks on control systems
复制标题

DOI:
10.1016/j.ijcip.2009.06.001
复制
发表时间:
2009-10-01
影响因子:
3.6
通讯作者:
Sastry, Shankar
Sastry, Shankar
中科院分区:
工程技术3区
文献类型:
--
作者:
Huang, Yu-Lun;Cardenas, Alvaro A.;Sastry, Shankar

文献摘要

被引文献

相似文献

本文介绍了一种开发控制系统攻击威胁模型的方法。这些模型对于分析获得控制系统资产访问权的攻击者所采取的行动以及评估攻击者的行动对被控制的物理过程的影响非常有用。本文提出了完整性攻击和拒绝服务(DoS)攻击的模型,并评估了化学反应器系统的物理和经济后果的攻击。分析揭示了两个要点。首先,当反应器处于稳定状态时,拒绝服务攻击不会产生显著影响;然而,将拒绝服务攻击与相对无害的完整性攻击相结合,会迅速导致反应器进入不安全状态。其次,试图增加化学反应器的操作成本的攻击涉及与对工厂安全的攻击完全不同的策略(即,试图关闭反应堆或引起爆炸的人)。(C)2009 Elsevier B. V.保留所有权利。
This paper describes an approach for developing threat models for attacks on control systems. These models are useful for analyzing the actions taken by an attacker who gains access to control system assets and for evaluating the effects of the attacker's actions on the physical process being controlled. The paper proposes models for integrity attacks and denial-of-service (DoS) attacks, and evaluates the physical and economic consequences of the attacks on a chemical reactor system. The analysis reveals two important points. First, a DoS attack does not have a significant effect when the reactor is in the steady state; however, combining the DoS attack with a relatively innocuous integrity attack rapidly causes the reactor to move to an unsafe state. Second, an attack that seeks to increase the operational cost of the chemical reactor involves a radically different strategy than an attack on plant safety (i.e., one that seeks to shut down the reactor or cause an explosion). (C) 2009 Elsevier B.V. All rights reserved.