NoiSense Print: Detecting Data Integrity Attacks on Sensor Measurements Using Hardware-based Fingerprints

被引:20
作者
Ahmed, Chuadhry Mujeeb [1 ]
Mathur, Aditya P. [1 ]
Ochoa, Martin [1 ,2 ]
机构
[1] Singapore Univ Technol & Design, 8 Somapah Rd, Singapore, Singapore
[2] AppGate Inc, Dallas, TX USA
关键词
Cyber physical systems; CPS security; ICS security; sensors security; device fingerprinting; physical attacks; sensor fingerprinting; attack detection; sensor noise; process noise; CPS threat modeling; challenge response protocol; machine learning-based intrusion detection; PHYSICAL DEVICE;
D O I
10.1145/3410447
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fingerprinting of various physical and logical devices has been proposed for uniquely identifying users or devices of mainstream IT systems such as PCs, laptops, and smart phones. However, the application of such techniques in Industrial Control Systems (ICS) is less explored for reasons such as a lack of direct access to such systems and the cost of faithfully reproducing realistic threat scenarios. This work addresses the feasibility of using fingerprinting techniques in the context of realistic ICS related to water treatment and distribution systems. A model-free sensor fingerprinting scheme (NoiSense) and a model-based sensor fingerprinting scheme (NoisePrint) are proposed. Using extensive experimentation with sensors, it is shown that noise patterns due to microscopic imperfections in hardware manufacturing can uniquely identify sensors with accuracy as high as 97%. The proposed technique can be used to detect physical attacks, such as the replacement of legitimate sensors by faulty or manipulated sensors. For NoisePrint, a combined fingerprint for sensor and process noise is created. The difference (called residual), between expected and observed values, i.e., noise, is used to derive a model of the system. It was found that in steady state the residual vector is a function of process and sensor noise. Data from experiments reveals that a multitude of sensors can be uniquely identified with a minimum accuracy of 90% based on NoisePrint. Also proposed is a novel challenge-response protocol that exposes more powerful cyber-attacks, including replay attacks.
引用
收藏
页数:35
相关论文
共 76 条
  • [1] Generalized attacker and attack models for Cyber Physical Systems
    Adepu, Sridhar
    Mathur, Aditya
    [J]. PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS, VOL 1, 2016, : 283 - 292
  • [2] Ahmed C.M., 2016, SMART CITY SECURITY, P1, DOI DOI 10.1109/SCSPW.2016.7509557
  • [3] Ahmed C. M., 2017, P 3 INT WORKSH CYB P, P25, DOI DOI 10.1145/3055366.3055375
  • [4] Ahmed C. Mujeeb, 2017, ARXIVCSCR171201598
  • [5] NoisePrint: Attack Detection Using Sensor and Process Noise Fingerprint in Cyber Physical Systems
    Ahmed, Chuadhry Mujeeb
    Ochoa, Martin
    Zhou, Jianying
    Mathur, Aditya P.
    Qadeer, Rizwan
    Murguia, Carlos
    Ruths, Justin
    [J]. PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 483 - 497
  • [6] Noise Matters: Using Sensor and Process Noise Fingerprint to Detect Stealthy Cyber Attacks and Authenticate sensors in CPS
    Ahmed, Chuadhry Mujeeb
    Zhou, Jianying
    Mathur, Aditya P.
    [J]. 34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018), 2018, : 566 - 581
  • [7] Model-based Attack Detection Scheme for Smart Water Distribution Networks
    Ahmed, Chuadhry Mujeeb
    Murguia, Carlos
    Ruths, Justin
    [J]. PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 101 - 113
  • [8] Ahmed Chuadhry Mujeeb, 2020, IEEE SECUR PRIVACY
  • [9] Alur R, 2015, PRINCIPLES OF CYBER-PHYSICAL SYSTEMS, P1
  • [10] Cyber Security of Water SCADA Systems-Part II: Attack Detection Using Enhanced Hydrodynamic Models
    Amin, Saurabh
    Litrico, Xavier
    Sastry, S. Shankar
    Bayen, Alexandre M.
    [J]. IEEE TRANSACTIONS ON CONTROL SYSTEMS TECHNOLOGY, 2013, 21 (05) : 1679 - 1693