首页|EPASAD:ellipsoid decision boundary based Process-Aware Stealthy Attack Detector

EPASAD:ellipsoid decision boundary based Process-Aware Stealthy Attack Detector

扫码查看
Due to the importance of Critical Infrastructure(CI)in a nation's economy,they have been lucrative targets for cyber attackers.These critical infrastructures are usually Cyber-Physical Systems such as power grids,water,and sewage treatment facilities,oil and gas pipelines,etc.In recent times,these systems have suffered from cyber attacks numer-ous times.Researchers have been developing cyber security solutions for Cis to avoid lasting damages.According to standard frameworks,cyber security based on identification,protection,detection,response,and recovery are at the core of these research.Detection of an ongoing attack that escapes standard protection such as firewall,anti-virus,and host/network intrusion detection has gained importance as such attacks eventually affect the physical dynamics of the system.Therefore,anomaly detection in physical dynamics proves an effective means to implement defense-in-depth.PASAD is one example of anomaly detection in the sensor/actuator data,representing such systems'physical dynamics.We present EPASAD,which improves the detection technique used in PASAD to detect these micro-stealthy attacks,as our experiments show that PASAD's spherical boundary-based detection fails to detect.Our method EPASAD overcomes this by using Ellipsoid boundaries,thereby tightening the boundaries in various dimen-sions,whereas a spherical boundary treats all dimensions equally.We validate EPASAD using the dataset produced by theTE-process simulator and the C-town datasets.The results show that EPASAD improves PASAD's average recall by 5.8%and 9.5%for the two datasets,respectively.

Intrusion detection systemCritical infrastructure securityIndustrial control systemMachine learning

Vikas Maurya、Rachit Agarwal、Saurabh Kumar、Sandeep Shukla

展开 >

Department of Computer Science and Engineering,Indian Institute of Technology Kanpur,kanpur,India

Merkle Science,Bangalore,India

C3iHub(Technology Innovation Hub on CyberSecurity and Cyber Security for Cyber-Physical Systems)at IIT Kanpur

2024

网络空间安全科学与技术(英文版)

网络空间安全科学与技术(英文版)

EI
ISSN:
年,卷(期):2024.7(3)