Autonomous mitigation of cyber risks in the Cyber-Physical Systems

被引:41
|
作者
Kholidy, Hisham A. [1 ]
机构
[1] State Univ New York SUNY Polytech Inst, Coll Engn, Dept Networks & Comp Secur NCS, Utica, NY 13502 USA
关键词
Cyberattacks; CPS security; Risk mitigation; Self-protection; Autonomous intrusion response;
D O I
10.1016/j.future.2020.09.002
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Cyber-Physical Systems (CPS) attacks and vulnerabilities are increasing and the consequences of such attacks can be catastrophic. The CPS needs to be self-resilient to cyber-attacks through a precise autonomous and timely risk mitigation model that can analyze and assess the risk of the CPS and apply a proper response strategy against the ongoing attacks. There is a limited amount of work on the self-protection of the cyber risks in the CPS. This paper contributes toward the need of advanced security approaches to respond against the attacks across the CPS in an autonomous way, with or without including a system administrator in the loop for troubleshooting based on the criticality of the CPS asset that can be protected, once the alert about a possible intrusion has been raised. To this end, this paper augments our existing security framework with an Autonomous Response Controller (ARC). ARC uses our quantitative Hierarchical Risk Correlation Tree (HRCT) that models the paths an attacker can traverse to reach certain goals and measures the financial risk that the CPS assets face from cyber-attacks. ARC also uses a Competitive Markov Decision Process (CMDP) to model the security reciprocal interaction between the protection system and the attacker/adversary as a multi-step, sequential, two player stochastic game in which each player tries to maximize his/her benefit. The experiments' results depict that the accuracy of ARC outperforms the traditional Static Intrusion Response System (S-IRS) by 43.61%. To experimentally test and validate ARC in real-time large-scale data, we run the Aurora attack to open the generator breaker in our testbed to create a cascading failure and voltage collapse. ARC was able to recover the CPS system and provide a timely response in less than 6 s. We compared the output of ARC against the current state of the art, the Suricata intrusion response system. ARC was able to mitigate the single line to ground (SLG) attacks and recover the CPS to its normal state in 122 s before Suricata does. (c) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:171 / 187
页数:17
相关论文
共 50 条
  • [1] Autonomous and Collaborating Cyber-Physical Systems
    van Lier, Ben
    [J]. 2018 22ND INTERNATIONAL CONFERENCE ON SYSTEM THEORY, CONTROL AND COMPUTING (ICSTCC), 2018, : 237 - 243
  • [2] Managing the Risks of Cyber-Physical Systems
    Axelrod, C. Warren
    [J]. 2013 NINTH ANNUAL CONFERENCE ON LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY (LISAT 2013), 2013,
  • [3] The Cross Space Transmission of Cyber Risks in Electric Cyber-Physical Systems
    Wang, Yufei
    Yan, Zhi
    Wang, Jing
    [J]. 2015 11TH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION (ICNC), 2015, : 1275 - 1279
  • [4] Modeling Methodology for Autonomous Cyber-Physical Systems
    Pinto, Alessandro
    [J]. 2ND INTERNATIONAL WORKSHOP ON COMPUTATION-AWARE ALGORITHMIC DESIGN FOR CYBER-PHYSICAL SYSTEMS (CAADCPS 2022), 2022, : 1 - 2
  • [5] Intelligent autonomous cyber-physical systems and applications
    Manogaran, Gunasekaran
    Qudrat-Ullah, Hassan
    Rawal Kshatriya, Bharat S.
    [J]. ENTERPRISE INFORMATION SYSTEMS, 2021, 15 (07) : 909 - 910
  • [6] Trustworthiness-Related Risks in Autonomous Cyber-Physical Production Systems - A Survey
    Zahid, Maryam
    Bucaioni, Alessio
    Flammini, Francesco
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 440 - 445
  • [7] A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber-Physical Systems
    Zebrowski, Piotr
    Couce-Vieira, Aitor
    Mancuso, Alessandro
    [J]. RISK ANALYSIS, 2022, 42 (10) : 2275 - 2290
  • [8] Cyber-Physical Systems of Systems and Complexity Science: The Whole is More than the Sum of Individual and Autonomous Cyber-Physical Systems
    van Lier, Ben
    [J]. CYBERNETICS AND SYSTEMS, 2018, 49 (7-8) : 538 - 565
  • [9] Preliminary Risk and Mitigation Assessment in Cyber-Physical Systems
    Foldvari, Andras
    Brancati, Francesco
    Pataricza, Andras
    [J]. 2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 267 - 274
  • [10] On Threat Modeling and Mitigation of Medical Cyber-Physical Systems
    Almohri, Hussain
    Cheng, Long
    Yao, Danfeng
    Alemzadeh, Homa
    [J]. 2017 IEEE/ACM SECOND INTERNATIONAL CONFERENCE ON CONNECTED HEALTH - APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2017, : 114 - 119