...
首页> 外文期刊>Future generation computer systems >Autonomous mitigation of cyber risks in the Cyber-Physical Systems
【24h】

Autonomous mitigation of cyber risks in the Cyber-Physical Systems

机译:网络物理系统中的网络风险自主减缓

获取原文
获取原文并翻译 | 示例
           

摘要

The Cyber-Physical Systems (CPS) attacks and vulnerabilities are increasing and the consequences of such attacks can be catastrophic. The CPS needs to be self-resilient to cyber-attacks through a precise autonomous and timely risk mitigation model that can analyze and assess the risk of the CPS and apply a proper response strategy against the ongoing attacks. There is a limited amount of work on the self-protection of the cyber risks in the CPS. This paper contributes toward the need of advanced security approaches to respond against the attacks across the CPS in an autonomous way, with or without including a system administrator in the loop for troubleshooting based on the criticality of the CPS asset that can be protected, once the alert about a possible intrusion has been raised. To this end, this paper augments our existing security framework with an Autonomous Response Controller (ARC). ARC uses our quantitative Hierarchical Risk Correlation Tree (HRCT) that models the paths an attacker can traverse to reach certain goals and measures the Financial risk that the CPS assets face from cyber-attacks. ARC also uses a Competitive Markov Decision Process (CMDP) to model the security reciprocal interaction between the protection system and the attacker/adversary as a multi-step, sequential, two-player stochastic game in which each player tries to maximize his/her benefit. The experiments' results depict that the accuracy of ARC outperforms the traditional Static Intrusion Response System (S-IRS) by 43.61%. To experimentally test and validate ARC in real-time large-scale data, we run the Aurora attack to open the generator breaker in our testbed to create a cascading failure and voltage collapse. ARC was able to recover the CPS system and provide a timely response in less than 6 s. We compared the output of ARC against the current state of the art, the Suricata intrusion response system. ARC was able to mitigate the single line to ground (SLG) attacks and recover the CPS to its normal state in 122 s before Suricata does.
机译:网络物理系统(CPS)攻击和漏洞正在增加,并且这种攻击的后果可能是灾难性的。通过精确的自主和及时的风险缓解模型,CPS需要自我适应网络攻击,可以分析和评估CPS的风险,并对正在进行的攻击应用适当的反应策略。关于CPS中网络风险的自我保护有限的工作。本文有助于提前安全方法,以自主方式响应CPS的攻击,在循环中,无需基于可以保护的CPS资产的临界,循环中的系统管理员进行故障排除提出了关于可能的入侵的警报。为此,本文增加了我们现有的安全框架与自主响应控制器(ARC)。 ARC使用我们的定量分层风险相关树(HRCT)模型攻击者可以遍历攻击某些目标并测量CPS资产从网络攻击面临的财务风险。 ARC也使用竞争性的马尔可夫决策过程(CMDP)来模拟保护系统和攻击者/对手之间的安全互惠交互,作为一个多步,顺序,双手随机游戏,其中每个玩家试图最大化他/她的利益。实验结果描绘了电弧优于传统静态入侵响应系统(S-IRS)的准确性43.61%。为了在实验测试和验证ARC的实时大规模数据中,我们运行Aurora攻击以打开测试台中的发电机断路器,以创建级联故障和电压崩溃。电弧能够恢复CPS系统,并在不到6秒内提供及时的响应。我们将电弧输出与现有技术,Suricata入侵响应系统进行比较。弧能够将单线降低到地面(SLG)攻击,并在Suricata确实在122秒内将CPS恢复到其正常状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号