首页> 外文会议>IEEE Conference on Communications and Network Security >BLOC: A Game-Theoretic Approach to Orchestrate CPS against Cyber Attacks
【24h】

BLOC: A Game-Theoretic Approach to Orchestrate CPS against Cyber Attacks

机译:BLOC:针对网络攻击编排CPS的博弈论方法

获取原文

摘要

Securing Cyber-Physical Systems (CPS) against cyber-attacks is challenging due to the wide range of possible attacks - from stealthy ones that seek to manipulate/drop/delay control and measurement signals to malware that infects host machines that control the physical process. This has prompted the research community to address this problem through developing targeted methods that protect and check the run-time operation of the CPS. Since protecting signals and checking for errors result in performance penalties, they must be performed within the delay bounds dictated by the control loop. Due to the large number of potential checks that can be performed, coupled with various degrees of their effectiveness to detect a wide range of attacks, strategic assignment of these checks in the control loop is a critical endeavor. To that end, this paper presents a coherent runtime framework - which we coin BLOC - for orchestrating the CPS with check blocks to secure them against cyber attacks. BLOC capitalizes on game theoretical techniques to enable the defender to find an optimal randomized use of check blocks to secure the CPS while respecting the control-loop constraints. We develop a Stackelberg game model for stateless blocks and a Markov game model for stateful ones and derive optimal policies that minimize the worst-case damage from rational adversaries. We validate our models through extensive simulations as well as a real implementation for a HVAC system.
机译:由于可能的攻击范围很广,因此保护网络物理系统(CPS)免受网络攻击的挑战十分艰巨-从试图操纵/丢弃/延迟控制和测量信号的隐形攻击到感染控制物理过程的主机的恶意软件。这促使研究界通过开发有针对性的方法来保护和检查CPS的运行时解决此问题。由于保护信号和检查错误会导致性能下降,因此必须在控制回路规定的延迟范围内执行信号。由于可以执行大量潜在的检查,并且检测各种攻击的有效性程度各不相同,因此在控制回路中对这些检查进行战略性分配是一项至关重要的工作。为此,本文提出了一个一致的运行时框架(我们将其称为BLOC),用于协调带有检查块的CPS,以保护其免受网络攻击。 BLOC利用博弈论技术,使防御者能够在遵守控制环约束的同时找到检查块的最佳随机使用方式,以确保CPS的安全。我们为无状态块开发了Stackelberg博弈模型,为有状态块开发了Markov博弈模型,并推导出了最佳策略,可以最大程度地减少理性对手的最坏情况造成的损失。我们通过广泛的仿真以及HVAC系统的实际实现来验证我们的模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号