Combining switching mechanism with re-initialization and anomaly detection for resiliency of cyber-physical systems

被引:2
作者
Fu, Hao [1 ]
Krishnamurthy, Prashanth [1 ]
Khorrami, Farshad [1 ]
机构
[1] NYU, MetroTech Ctr 5, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 11201 USA
关键词
Cyber-physical system; Redundancy; Switching strategy; Re-initialization; Anomaly detection; Control system; MEAN-SQUARE STABILITY; FAULT-DETECTION; CYBERSECURITY;
D O I
10.1016/j.automatica.2024.111994
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-physical systems (CPS) play a pivotal role in numerous critical real-world applications that have stringent requirements for safety. To enhance the CPS resiliency against attacks, redundancy can be integrated in real-time controller implementations by designing strategies that switch among multiple controllers. However, existing switching strategies typically overlook remediation measures for compromised controllers, opting instead to simply exclude them. Such a solution reduces the CPS redundancy since only a subset of controllers are used. To address this gap, this work proposes a multicontroller switching strategy with periodic re-initialization to remove attacks. Controllers that finish re-initialization can be reused by the switching strategy, preserving the CPS redundancy and resiliency. The proposed switching strategy is designed to ensure that at each switching moment, a controller that has just completed re-initialization is available, minimizing the likelihood of compromise. Additionally, the controller's working period decreases with the number of involved controllers, reducing the controller's exposure time to attacks. An anomaly detector is used to detect CPS attacks during the controller's working period. Upon alarm activation, the current control signal is set to a predefined value, and a switch to an alternative controller occurs at the earliest switching moment. Our switching strategy is shown to be still effective even if the anomaly detector fails to detect (stealthy) attacks. The efficacy of our strategy is analyzed through three derived conditions under a proposed integrated attack-defense model for mean-square boundedness of the CPS states. Simulation results on a third- order system and a single-machine infinite-bus (SMIB) system confirm that our approach significantly bolsters CPS resiliency by leveraging the advantages of re-initialization, anomaly detection, and switching mechanisms. (c) 2024 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
引用
收藏
页数:12
相关论文
共 36 条
[1]   Guaranteed Physical Security with Restart-Based Design for Cyber-Physical Systems [J].
Abdi, Fardin ;
Chen, Chien-Ying ;
Hasan, Monowar ;
Liu, Songran ;
Mohan, Sibin ;
Caccamo, Marco .
2018 9TH ACM/IEEE INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (ICCPS 2018), 2018, :10-21
[2]   On the Security of Cyber-Physical Systems Against Stochastic Cyber-Attacks Models [J].
Abu Al-Haija, Qasem .
2021 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2021, :155-160
[3]   Model-Free Fault Detection and Isolation in Large-Scale Cyber-Physical Systems [J].
Alippi, Cesare ;
Ntalampiras, Stavros ;
Roveri, Manuel .
IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2017, 1 (01) :61-71
[4]   Lyapunov stability analysis for nonlinear delay systems under random effects and stochastic perturbations with applications in finance and ecology [J].
Almutairi, Abdulwahab ;
El-Metwally, H. ;
Sohaly, M. A. ;
Elbaz, I. M. .
ADVANCES IN DIFFERENCE EQUATIONS, 2021, 2021 (01)
[5]   YOLO: Frequently Resetting CPS for Security [J].
Arroyo, Miguel A. ;
Ibn Ziad, M. Tarek ;
Kobayashi, Hidenori ;
Yang, Junfeng ;
Sethumadhavan, Simha .
AUTONOMOUS SYSTEMS: SENSORS, PROCESSING, AND SECURITY FOR VEHICLES AND INFRASTRUCTURE 2019, 2019, 11009
[6]  
Bellman R., 1943, Duke Math. J, V10, DOI [DOI 10.1215/S0012-7094-43-01059-2, 10.1215/s0012-7094-43- 01059-2]
[7]  
Candea G, 2004, USENIX Association Proceedings of the Sixth Symposium on Operating Systems Design and Implementation (OSDE '04), P31
[8]  
Cardenas A. A., 2011, P 6 ACM S INF COMP C, P355, DOI DOI 10.1145/1966913.1966959
[9]  
Evans D, 2011, ADV INFORM SECUR, V54, P29
[10]   A Survey of Physics-Based Attack Detection in Cyber-Physical Systems [J].
Giraldo, Jairo ;
Urbina, David ;
Cardenas, Alvaro ;
Valente, Junia ;
Faisal, Mustafa ;
Ruths, Justin ;
Tippenhauer, Nils Ole ;
Sandberg, Henrik ;
Candell, Richard .
ACM COMPUTING SURVEYS, 2018, 51 (04)