首页> 外文会议>International workshop on critical information infrastructures security;CRITIS 2009 >Trouble Brewing: Using Observations of Invariant Behavior to Detect Malicious Agency in Distributed Control Systems
【24h】

Trouble Brewing: Using Observations of Invariant Behavior to Detect Malicious Agency in Distributed Control Systems

机译:故障酿造:使用不变行为的观察来检测分布式控制系统中的恶意代理

获取原文

摘要

Recent research on intrusion detection in supervisory data acquisition and control (SCADA) and DCS systems has focused on anomaly detection at protocol level based on the well-defined nature of traffic on such networks. Here, we consider attacks which compromise sensors or actuators (including physical manipulation), where intrusion may not be readily apparent as data and computational states can be controlled to give an appearance of normality, and sensor and control systems have limited accuracy. To counter these, we propose to consider indirect relations between sensor readings to detect such attacks through concurrent observations as determined by control laws and constraints. We use a brewery bulk and fill pasteurizer as a specimen for biochemical processes. We motivate our approach by considering possible attacks and means of detection. Here we rely on the existence of nonlinear relationships which allow us to attach a greater significance to small differences in sensor readings than would otherwise be the case and demonstrate the insufficiency of existing sensor placement and measurement frequency to detect such attacks.
机译:监视数据采集和控制(SCADA)和DCS系统中的入侵检测的最新研究基于这种网络上流量的明确定义,着重于协议级别的异常检测。在这里,我们考虑会危害传感器或执行器(包括物理操纵)的攻击,由于数据和计算状态可以被控制以呈现正常状态,因此入侵可能不容易显而易见,并且传感器和控制系统的精度有限。为了解决这些问题,我们建议考虑传感器读数之间的间接关系,以通过控制律和约束条件确定的并发观测来检测此类攻击。我们使用啤酒厂的散装和巴氏灭菌器作为生化过程的样本。我们通过考虑可能的攻击和检测手段来激发我们的方法。在这里,我们依赖于非线性关系的存在,这使我们对传感器读数的细微差别比在其他情况下具有更大的意义,并证明了现有传感器的位置和测量频率不足以检测此类攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号