Assessing Model-free Anomaly Detection in Industrial Control Systems Against Generic Concealment Attacks

被引:1
|
作者
Erba, Alessandro [1 ,2 ]
Tippenhauer, Nils Ole [1 ]
机构
[1] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[2] Saarland Univ, Saarbrucken Grad Sch Comp Sci, Saarbrucken, Germany
关键词
Concealment attacks; Anomaly Detection; Industrial Control;
D O I
10.1145/3564625.3564633
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, a number of model-free process-based anomaly detection schemes for Industrial Control Systems (ICS) were proposed. Model-free anomaly detectors are trained directly from process data and do not require process knowledge. They are validated based on a set of public data with limited attacks present. As result, the resilience of those schemes against general concealment attacks is unclear. In addition, no structured discussion on the properties verified by the detectors exists. In this work, we provide the first systematic analysis of such anomaly detection schemes, focusing on six model-free process-based anomaly detectors. We hypothesize that the detectors verify a combination of temporal, spatial, and statistical consistencies. To test this, we systematically analyse their resilience against generic concealment attacks. Our generic concealment attacks are designed to violate a specific consistency verified by the detector, and require no knowledge of the attacked physical process or the detector. In addition, we compare against prior work attacks that were designed to attack neural network-based detectors. Our results demonstrate that the evaluated model-free detectors are in general susceptible to generic concealment attacks. For each evaluated detector, at least one of our generic concealment attacks performs better than prior work attacks. In particular, the results allow us to show which specific consistencies are verified by each detector. We also find that prior work attacks that target neural-network architectures transfer surprisingly well against other architectures.
引用
收藏
页码:412 / 426
页数:15
相关论文
共 50 条
  • [31] On the Generation of Anomaly Detection Datasets in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Celdran, Alberto Huertas
    Garcia Clemente, Felix J.
    Cadenas Sarmiento, Cristian
    Del Canto Masa, Carlos Javier
    Mendez Nistal, Ruben
    [J]. IEEE ACCESS, 2019, 7 : 177460 - 177473
  • [32] MADICS: A Methodology for Anomaly Detection in Industrial Control Systems
    Perales Gomez, Angel Luis
    Fernandez Maimo, Lorenzo
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    [J]. SYMMETRY-BASEL, 2020, 12 (10):
  • [33] Nonlinear model-free control and ARX modeling of industrial motor
    Sarostad M.
    Piltan F.
    Ashkezari F.D.
    Sulaiman N.B.
    [J]. International Journal of Smart Home, 2016, 10 (12): : 63 - 76
  • [34] Secure Planning Against Stealthy Attacks via Model-Free Reinforcement Learning
    Bozkurt, Alper Kamil
    Wang, Yu
    Pajic, Miroslav
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA 2021), 2021, : 10656 - 10662
  • [35] Distributed model-free adaptive control for multi-agent systems with external disturbances and DoS attacks
    Chen, Run-Ze
    Li, Yuan-Xin
    Hou, Zhong-Sheng
    [J]. INFORMATION SCIENCES, 2022, 613 : 309 - 323
  • [36] Event-Triggered Model-Free Adaptive Control for Nonlinear Multiagent Systems Under Jamming Attacks
    Wang, Xijuan
    Hua, Changchun
    Qiu, Yunfei
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2023, 35 (10) : 1 - 9
  • [37] Deep Learning based Efficient Anomaly Detection for Securing Process Control Systems against Injection Attacks
    Potluri, Sasanka
    Diedrich, Christian
    [J]. 2019 IEEE 15TH INTERNATIONAL CONFERENCE ON AUTOMATION SCIENCE AND ENGINEERING (CASE), 2019, : 854 - 860
  • [38] A model-free approach to fault detection of periodic systems
    Zhang, P
    Ding, SX
    [J]. 2005 IEEE INTERNATIONAL SYMPOSIUM ON INTELLIGENT CONTROL & 13TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION, VOLS 1 AND 2, 2005, : 843 - 848
  • [39] Defense against DoS and load altering attacks via model-free control: A proposal for a new cybersecurity setting
    Fliess, Michel
    Join, Cedric
    Sauter, Dominique
    [J]. 5TH CONFERENCE ON CONTROL AND FAULT-TOLERANT SYSTEMS (SYSTOL 2021), 2021, : 58 - 65
  • [40] Prescribed performance-based resilient model-free adaptive control for CPSs against aperiodic DoS attacks
    Sun, Shan-Shan
    Li, Yuan-Xin
    Hou, Zhongsheng
    [J]. INTERNATIONAL JOURNAL OF ROBUST AND NONLINEAR CONTROL, 2024, 34 (05) : 3335 - 3350