Autonomous Attack Mitigation for Industrial Control Systems

被引:2
|
作者
Mern, John [1 ]
Hatch, Kyle [2 ]
Silva, Ryan [3 ]
Hickert, Cameron [3 ]
Sookoor, Tamim [3 ]
Kochenderfer, Mykel J. [1 ]
机构
[1] Stanford Univ, Aeronaut & Astronaut, Stanford, CA USA
[2] Stanford Univ, Comp Sci, Stanford, CA USA
[3] Johns Hopkins Univ, Appl Phys Lab, Baltimore, MD USA
来源
52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOP VOLUME (DSN-W 2022) | 2022年
关键词
reinforcement learning; artificial intelligence; machine learning; industrial control systems;
D O I
10.1109/DSN-W54100.2022.00015
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Defending industrial control systems and other networks from cyber attack requires timely responses to alerts and threat intelligence. Decisions about how to respond involve coordinating actions across multiple nodes based on imperfect indicators of compromise while minimizing disruptions to network operations. Currently, playbooks are used to automate portions of a response process, but often leave complex decision-making to a human analyst. In this work, we present a deep reinforcement learning approach to autonomous response and recovery in large industrial control networks. We propose an attention-based neural architecture that is flexible to the size of the network under protection. To train and evaluate the autonomous defender agent, we present an industrial control network simulation environment suitable for reinforcement learning. Experiments show that the learned agent can effectively mitigate advanced attacks that progress with few observable signals over several months before execution. The proposed application of AI/ML techniques for security outperforms a fully automated playbook method in simulation, taking less disruptive actions while also defending more nodes on the network. The learned policy is also more robust to changes in attacker behavior than playbook approaches.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [1] Beyond botnets: Autonomous Firmware Zombie Attack in industrial control systems
    Alavi, Seyed Ali
    Moghadam, Hamed Pourvali
    Jahangir, Amir Hossein
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2025, 48
  • [2] Cyber attack detection and mitigation: Software Defined Survivable Industrial Control Systems
    Sandor, Hunor
    Genge, Bela
    Szanto, Zoltan
    Marton, Lorinc
    Haller, Piroska
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2019, 25 : 152 - 168
  • [3] DEFINING ATTACK PATTERNS FOR INDUSTRIAL CONTROL SYSTEMS
    Chan, Raymond
    Chow, Kam-Pui
    Chan, Chun-Fai
    CRITICAL INFRASTRUCTURE PROTECTION XIII, 2019, 570 : 289 - 309
  • [4] Attack detection/prevention system against cyber attack in industrial control systems
    Yilmaz, Ercan Nurcan
    Gonen, Serkan
    COMPUTERS & SECURITY, 2018, 77 : 94 - 105
  • [5] Industrial challenges for AI systems engineering Towards autonomous industrial systems
    Sawilla, Ingo
    Weber, Christian
    Schmidt, Benedikt
    Ulrich, Marco
    AT-AUTOMATISIERUNGSTECHNIK, 2022, 70 (09) : 805 - 814
  • [6] Poisoning Attacks on Cyber Attack Detectors for Industrial Control Systems
    Kravchik, Moshe
    Biggio, Battista
    Shabtai, Asaf
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 116 - 125
  • [7] Testing the Effectiveness of Attack Detection Mechanisms in Industrial Control Systems
    Sugumar, Gayathri
    Mathur, Aditya
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2017, : 138 - 145
  • [8] Assessing the Effectiveness of Attack Detection at a Hackfest on Industrial Control Systems
    Adepu, Sridhar
    Mathur, Aditya
    IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2021, 6 (02): : 231 - 244
  • [9] Bank of Models: Sensor Attack Detection and Isolation in Industrial Control Systems
    Ahmed, Chuadhry Mujeeb
    Zhou, Jianying
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, CRITIS 2021, 2021, 13139 : 3 - 23
  • [10] GENICS: A Framework for Generating Attack Scenarios for Cybersecurity Exercises on Industrial Control Systems
    Song, Insung
    Jeon, Seungho
    Kim, Donghyun
    Lee, Min Gyu
    Seo, Jung Taek
    APPLIED SCIENCES-BASEL, 2024, 14 (02):