A controller design for mitigation of passive system identification attacks in networked control systems

被引:8
作者
de Sa, Alan O. [1 ,2 ]
da Costa Carmo, Luiz F. R. [1 ,3 ]
Machado, Raphael C. S. [3 ,4 ]
机构
[1] Univ Fed Rio de Janeiro, Inst Math, NCE, Av Athos da Silveira Ramos 274, BR-68530 Rio De Janeiro, Brazil
[2] Brazilian Navy, Admiral Wandenkolk Instruct Ctr, Rio De Janeiro, Brazil
[3] Natl Inst Metrol Qual & Technol, Av Nossa Senhora das Gracas 50, Rio De Janeiro, Brazil
[4] Rio De Janeiro Fed Ctr Technol Educ, Av Maracana 229, Rio De Janeiro, Brazil
关键词
Networked control system (NCS); Cyber-physical systems; Security; System identification attacks; Switching controller;
D O I
10.1186/s13174-017-0074-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The literature regarding attacks in Networked Control Systems (NCS) indicates that covert and accurate attacks must be designed based on an accurate knowledge about the model of the attacked system. In this context, the literature on NCS presents the Passive System Identification attack as a metaheuristic-based tool to provide the attacker with the required system models. However, the scientific literature does not report countermeasures to mitigate the identification process performed by such passive metaheuristic-based attack. In this sense, this work proposes the use of a randomly switching controller as a countermeasure for the Passive System Identification attack, in case of failure of other conventional security mechanisms - such as encryption, network segmentation and firewall policies. This novel countermeasure aims to hinder the identification of the controller, so that the model obtained by the attacker is imprecise or ambiguous, in such a way that the attacker hesitates to launch covert or model-dependent attacks against the NCS. The simulation results indicate that this countermeasure is capable to mitigate the mentioned attack at the same time that it performs a satisfactory plant control.
引用
收藏
页数:19
相关论文
empty
未找到相关数据