Anomaly-Based Detection and Classification of Attacks in Cyber-Physical Systems

被引:10
|
作者
Kreimel, Philipp [1 ]
Eigner, Oliver [1 ]
Tavolato, Paul [1 ]
机构
[1] Univ Appl Sci St Polten, Matthias Corvinus Str 15, A-3100 St Polten, Austria
来源
PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017) | 2017年
关键词
Anomaly detection; machine learning; cyber-physical systems;
D O I
10.1145/3098954.3103155
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-physical systems are found in industrial and production systems, as well as critical infrastructures. Due to the increasing integration of IP-based technology and standard computing devices, the threat of cyber-attacks on cyber-physical systems has vastly increased. Furthermore, traditional intrusion defense strategies for IT systems are often not applicable in operational environments. In this paper we present an anomaly-based approach for detection and classification of attacks in cyber-physical systems. To test our approach, we set up a test environment with sensors, actuators and controllers widely used in industry, thus, providing system data as close as possible to reality. First, anomaly detection is used to define a model of normal system behavior by calculating outlier scores from normal system operations. This valid behavior model is then compared with new data in order to detect anomalies. Further, we trained an attack model, based on supervised attacks against the test setup, using the naive Bayes classifier. If an anomaly is detected, the classification process tries to classify the anomaly by applying the attack model and calculating prediction confidences for trained classes. To evaluate the statistical performance of our approach, we tested the model by applying an unlabeled dataset, which contains valid and anomalous data. The results show that this approach was able to detect and classify such attacks with satisfactory accuracy.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] An Anomaly Detection Framework for Digital Twin Driven Cyber-Physical Systems
    Gao, Chuanchao
    Park, Heejong
    Easwaran, Arvind
    ICCPS'21: PROCEEDINGS OF THE 2021 ACM/IEEE 12TH INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (WITH CPS-IOT WEEK 2021), 2021, : 44 - 54
  • [42] Attacks detection in Cyber-Physical Systems with Neural Networks: a case study
    Bernardeschi, Cinzia
    Dini, Gianluca
    Palmieri, Maurizio
    Vivani, Alessio
    2024 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, ISCC 2024, 2024,
  • [43] Real-time detection of deception attacks in cyber-physical systems
    Feiyang Cai
    Xenofon Koutsoukos
    International Journal of Information Security, 2023, 22 : 1099 - 1114
  • [44] Rethinking the Operation Pattern for Anomaly Detection in Industrial Cyber-Physical Systems
    Cheng, Zishuai
    Cui, Baojiang
    Fu, Junsong
    APPLIED SCIENCES-BASEL, 2023, 13 (05):
  • [45] A Subspace Method for Time Series Anomaly Detection in Cyber-Physical Systems
    Vides, Fredy
    Segura, Esteban
    Vargas-Aguero, Carlos
    IFAC PAPERSONLINE, 2022, 55 (41): : 58 - 63
  • [46] A Survey of Network Attacks on Cyber-Physical Systems
    Cao, Liwei
    Jiang, Xiaoning
    Zhao, Yumei
    Wang, Shouguang
    You, Dan
    Xu, Xianli
    IEEE ACCESS, 2020, 8 : 44219 - 44227
  • [47] Cross-Level Detection Framework for Attacks on Cyber-Physical Systems
    Brien Croteau
    Deepak Krishnankutty
    Kiriakos Kiriakidis
    Tracie Severson
    Chintan Patel
    Ryan Robucci
    Erick Rodriguez-Seda
    Nilanjan Banerjee
    Journal of Hardware and Systems Security, 2017, 1 (4) : 356 - 369
  • [48] Real-time detection of deception attacks in cyber-physical systems
    Cai, Feiyang
    Koutsoukos, Xenofon
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (05) : 1099 - 1114
  • [49] Detection, reconstruction and mitigation of deception attacks in nonlinear cyber-physical systems
    Shahriari-kahkeshi, Maryam
    Alem, Sayed Amirhosein
    Shi, Peng
    INTERNATIONAL JOURNAL OF ADAPTIVE CONTROL AND SIGNAL PROCESSING, 2024, 38 (09) : 2972 - 2995
  • [50] A Blended Active Detection Strategy for False Data Injection Attacks in Cyber-Physical Systems
    Ghaderi, Mohsen
    Gheitasi, Kian
    Lucia, Walter
    IEEE TRANSACTIONS ON CONTROL OF NETWORK SYSTEMS, 2021, 8 (01): : 168 - 176