首页> 外文会议>IEEE International Conference on Smart Grid Communications >Controller-aware false data injection against programmable logic controllers
【24h】

Controller-aware false data injection against programmable logic controllers

机译:针对可编程逻辑控制器的控制器感知错误数据注入

获取原文
获取外文期刊封面目录资料

摘要

Control systems rely on accurate sensor measurements to safely regulate physical processes. In False Data Injection (FDI) attacks, adversaries inject forged sensor measurements into a control system in hopes of misguiding control algorithms into taking dangerous actions. Traditional FDI attacks mostly require adversaries to know the full system topology, i.e., hundreds or thousands of lines and buses, while having unpredictable consequences. In this paper, we present a new class of FDI attacks directly against individual Programmable Logic Controllers (PLCs), which are ubiquitous in power generation and distribution. Our attack allows the adversary to have only partial information about the victim subsystem, and produces a predictable malicious result. Our attack tool analyzes an I/O trace of the compromised PLCs to produce a set of inputs to achieve the desired PLC outputs, i.e., the system behavior. It proceeds in two steps. First, our tool constructs a model of the PLC's internal logic from the I/O traces. Second, it searches for a set of inputs that cause the model to calculate the desired malicious behavior. We evaluate our tool against a set of representative control systems and show that it is a practical threat against insecure sensor configurations.
机译:控制系统依靠准确的传感器测量来安全地调节物理过程。在虚假数据注入(FDI)攻击中,对手会将伪造的传感器测量值注入到控制系统中,以期误导控制算法采取危险措施。传统的FDI攻击通常要求对手了解整个系统的拓扑结构,即成百上千的线路和总线,同时带来不可预测的后果。在本文中,我们提出了一种直接针对单个可编程逻辑控制器(PLC)的新型FDI攻击,这种方法在发电和配电中无处不在。我们的攻击使对手仅拥有有关受害者子系统的部分信息,并产生可预测的恶意结果。我们的攻击工具分析了受感染PLC的I / O跟踪,以生成一组输入以实现所需的PLC输出(即系统行为)。它分两步进行。首先,我们的工具根据I / O轨迹构建PLC内部逻辑模型。其次,它搜索导致模型计算所需恶意行为的一组输入。我们根据一组代表性的控制系统对我们的工具进行了评估,结果表明该工具实际上对不安全的传感器配置构成了威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号