Using timing-based side channels for anomaly detection in industrial control systems

被引:16
|
作者
Dunlap, Stephen [1 ]
Butts, Jonathan [2 ]
Lopez, Juan [3 ]
Rice, Mason [1 ]
Mullins, Barry [1 ]
机构
[1] Air Force Inst Technol, Dept Elect & Comp Engn, Wright Patterson AFB, OH 45433 USA
[2] QED Secure Solut, 417 Forest Ridge Dr, Coppell, TX 75019 USA
[3] Appl Res Solut, 51 Plum St, Beavercreek, OH 45440 USA
关键词
industrial control systems; Programmable logic controllers; Modification attacks; Side channels; Anomaly detection;
D O I
10.1016/j.ijcip.2016.07.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The critical infrastructure, which includes the electric power grid, railroads and water treatment facilities, is dependent on the proper operation of industrial control systems. However, malware such as Stuxnet has demonstrated the ability to alter industrial control system parameters to create physical effects. Of particular concern is malware that targets embedded devices that monitor and control system functionality, while masking the actions from plant operators and security analysts. Indeed, system security relies on guarantees that the assurance of these devices can be maintained throughout their lifetimes. This paper presents a novel approach that uses timing-based side channel analysis to establish a unique device fingerprint that helps detect unauthorized modifications of the device. The approach is applied to an Allen Bradley ControlLogix programmable logic controller where execution time measurements are collected and analyzed by a custom anomaly detection system to detect abnormal behavior. The anomaly detection system achieves true positive rates of 0.978-1.000 with false positive rates of 0.033-0.044. The test results demonstrate the feasibility of using timing-based side channel analysis to detect anomalous behavior in programmable logic controllers. Published'by Elsevier B.V.
引用
收藏
页码:12 / 26
页数:15
相关论文
共 50 条
  • [1] Timing-based Anomaly Detection in Embedded Systems
    Lu, Sixing
    Seo, Minjun
    Lysecky, Roman
    [J]. 2015 20TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2015, : 809 - 814
  • [2] Timing-Based Anomaly Detection in SCADA Networks
    Lin, Chih-Yuan
    Nadjm-Tehrani, Simin
    Asplund, Mikael
    [J]. CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2017), 2018, 10707 : 48 - 59
  • [3] Subcomponent Timing-based Detection of Malware in Embedded Systems
    Lu, Sixing
    Lysecky, Roman
    Rozenblit, Jerzy
    [J]. 2017 IEEE 35TH INTERNATIONAL CONFERENCE ON COMPUTER DESIGN (ICCD), 2017, : 17 - 24
  • [4] Anomaly Detection in Embedded Systems Using Power and Memory Side Channels
    Park, Jiho
    Surabhi, Virinchi Roy
    Krishnamurthy, Prashanth
    Garg, Siddharth
    Karri, Ramesh
    Khorrami, Farshad
    [J]. 2020 IEEE EUROPEAN TEST SYMPOSIUM (ETS 2020), 2020,
  • [5] Anomaly detection for industrial control systems using process mining
    Myers, David
    Suriadi, Suriadi
    Radke, Kenneth
    Foo, Ernest
    [J]. COMPUTERS & SECURITY, 2018, 78 : 103 - 125
  • [6] Anomaly detection using invariant rules in Industrial Control Systems
    Zhu, Qilin
    Ding, Yulong
    Jiang, Jie
    Yang, Shuang-Hua
    [J]. Control Engineering Practice, 2025, 154
  • [7] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Wang, Weiping
    Wang, Zhaorong
    Zhou, Zhanfan
    Deng, Haixia
    Zhao, Weiliang
    Wang, Chunyang
    Guo, Yongzhen
    [J]. TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (06) : 821 - 832
  • [8] Anomaly Detection of Industrial Control Systems Based on Transfer Learning
    Weiping Wang
    Zhaorong Wang
    Zhanfan Zhou
    Haixia Deng
    Weiliang Zhao
    Chunyang Wang
    Yongzhen Guo
    [J]. Tsinghua Science and Technology, 2021, 26 (06) : 821 - 832
  • [9] Correlation-Based Anomaly Detection in Industrial Control Systems
    Jadidi, Zahra
    Pal, Shantanu
    Hussain, Mukhtar
    Thanh, Kien Nguyen
    [J]. SENSORS, 2023, 23 (03)
  • [10] Using Side -Channels to Detect Abnormal Behavior in Industrial Control Systems
    Bolboaca, Roland
    Genge, Bela
    Haller, Piroska
    [J]. 2019 IEEE 15TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTER COMMUNICATION AND PROCESSING (ICCP 2019), 2019, : 435 - 441