Limiting the Impact of Stealthy Attacks on Industrial Control Systems
Top Cited Papers
- 24 October 2016
- conference paper
- conference paper
- Published by Association for Computing Machinery (ACM)
- p. 1092-1105
- https://doi.org/10.1145/2976749.2978388
Abstract
While attacks on information systems have for most practical purposes binary outcomes (information was manipulated/eavesdropped, or not), attacks manipulating the sensor or control signals of Industrial Control Systems (ICS) can be tuned by the attacker to cause a continuous spectrum in damages. Attackers that want to remain undetected can attempt to hide their manipulation of the system by following closely the expected behavior of the system, while injecting just enough false information at each time step to achieve their goals. In this work, we study if attack-detection can limit the impact of such stealthy attacks. We start with a comprehensive review of related work on attack detection schemes in the security and control systems community. We then show that many of those works use detection schemes that are not limiting the impact of stealthy attacks. We propose a new metric to measure the impact of stealthy attacks and how they relate to our selection on an upper bound on false alarms. We finally show that the impact of such attacks can be mitigated in several cases by the proper combination and configuration of detection schemes. We demonstrate the effectiveness of our algorithms through simulations and experiments using real ICS testbeds and real ICS systems.Keywords
Funding Information
- National Research Foundation Singapore (NRF2014NCR-NCR001-40)
- National Science Foundation (CNS-1553683)
- National Institute of Standards and Technology (70NANB14H236)
- Swedish Research Council (2013-5523)
This publication has 53 references indexed in Scilit:
- A secure control framework for resource-limited adversariesAutomatica, 2015
- Unmanned Aircraft Capture and Control Via GPS SpoofingJournal of Field Robotics, 2014
- Detecting Integrity Attacks on SCADA SystemsIEEE Transactions on Control Systems Technology, 2013
- Evaluating Electricity Theft Detectors in Smart Grid NetworksLecture Notes in Computer Science, 2012
- False data injection attacks against state estimation in electric power gridsACM Transactions on Information and System Security, 2011
- Wavelet networks for nonlinear system modelingNeural Computing & Applications, 2006
- The base-rate fallacy and the difficulty of intrusion detectionACM Transactions on Information and System Security, 2000
- Bro: a system for detecting network intruders in real-timeComputer Networks, 1999
- Detection of stochastic processesIEEE Transactions on Information Theory, 1998
- System identification—A surveyAutomatica, 1971