Skip to main content
QUICK REVIEW

[論文レビュー] Intrusion Detection for Industrial Control Systems: Evaluation Analysis and Adversarial Attacks.

Giulio Zizzo, Chris Hankin|arXiv (Cornell University)|Nov 8, 2019
Adversarial Robustness in Machine Learning参考文献 10被引用数 16
ひとこと要約

この論文は、産業制御システムにおけるLSTMベースのインシデント検出システム(IDS)の評価を行い、センサデータを操作することで検出を回避する可能性がある悪意ある攻撃の脆弱性を示している。攻撃後の影響を考慮した場合、F₁スコア0.811 ± 0.0103を達成するデータ漏洩なしのチューニング手法を提案し、実運用における耐性と信頼性を向上させた。

ABSTRACT

Neural networks are increasingly used in security applications for intrusion detection on industrial control systems. In this work we examine two areas that must be considered for their effective use. Firstly, is their vulnerability to adversarial attacks when used in a time series setting. Secondly, is potential over-estimation of performance arising from data leakage artefacts. To investigate these areas we implement a long short-term memory (LSTM) based intrusion detection system (IDS) which effectively detects cyber-physical attacks on a water treatment testbed representing a strong baseline IDS. For investigating adversarial attacks we model two different white box attackers. The first attacker is able to manipulate sensor readings on a subset of the Secure Water Treatment (SWaT) system. By creating a stream of adversarial data the attacker is able to hide the cyber-physical attacks from the IDS. For the cyber-physical attacks which are detected by the IDS, the attacker required on average 2.48 out of 12 total sensors to be compromised for the cyber-physical attacks to be hidden from the IDS. The second attacker model we explore is an $L_{\infty}$ bounded attacker who can send fake readings to the IDS, but to remain imperceptible, limits their perturbations to the smallest $L_{\infty}$ value needed. Additionally, we examine data leakage problems arising from tuning for $F_1$ score on the whole SWaT attack set and propose a method to tune detection parameters that does not utilise any attack data. If attack after-effects are accounted for then our new parameter tuning method achieved an $F_1$ score of 0.811$\pm$0.0103.

研究の動機と目的

  • 産業制御システムにおけるLSTMベースのインシデント検出システム(IDS)が、悪意ある攻撃に対してどれほど脆弱であるかを評価すること。
  • ハイパーパramータチューニング中にデータ漏洩が生じることで性能が過大評価される現象を調査すること。
  • 攻撃データを用いないことでデータ漏洩の兆候を回避するパラメータチューニング手法の開発。
  • 2つの異なる攻撃者モデルを用いて、検出を回避する悪意ある攻撃の有効性を評価すること。
  • IDSがサイバー物理的攻撃を検出できないようにするために、攻撃者が何個のセンサを乗っ取る必要があるかを定量化すること。

提案手法

  • サイバー物理的攻撃を検出するために、SWaT水処理テストベッドデータセットでトレーニングされたLSTMベースのIDSを実装した。
  • 2つのホワイトボックス攻撃者モデルをシミュレートした:1つは特定のセンサの読み取り値を操作するもので、もう1つはL∞-バウンドされた摂動を用いて人間の感覚では検出できないようにするもの。
  • 最適化中に攻撃データを除外することで、データ漏洩を排除する新しいハイパーパramータチューニング戦略を提案した。
  • 主な評価指標としてF₁スコアを用い、チューニングは攻撃のないデータセット部分で実施した。
  • 実世界の検出遅延と持続性を反映させるために、攻撃の後処理効果を評価に組み込んだ。
  • 攻撃の成功度を、侵害されたセンサ数とそれに伴う検出回避率を測定することで評価した。

実験結果

リサーチクエスチョン

  • RQ1時間系列設定において、センサ読み取り値を操作する悪意ある攻撃がLSTMベースのIDSに対してどれほど脆弱であるか?
  • RQ2ハイパーパramータチューニング中に生じるデータ漏洩が、IDS評価における性能の過大評価にどの程度寄与するか?
  • RQ3攻撃者がIDSの検出を回避するために最低限何個のセンサを乗っ取る必要があるか?
  • RQ4L∞-バウンドされた悪意ある攻撃は、検出を回避しつつも、人間には検出できないほどに不顕著な摂動を生成できるか?
  • RQ5データ漏洩なしのチューニング手法は、インシデント検出におけるF₁スコア推定の信頼性を向上させることができるか?

主な発見

  • 攻撃者は平均して12個のセンサのうち2.48個を乗っ取るだけで、LSTMベースのIDSがサイバー物理的攻撃を検出できないようにすることができた。
  • 提案されたデータ漏洩なしのチューニング手法は、攻撃の後処理効果を考慮した場合、F₁スコア0.811 ± 0.0103を達成した。
  • L∞-バウンド攻撃者モデルは、人間には検出できない摂動を生成でき、その結果として検出を回避することができ、巧妙さが裏付けられた。
  • データ漏洩による性能の過大評価が確認された。特に、攻撃全セットを用いてチューニングした場合に顕著であった。
  • 本研究は、標準的な評価手法が攻撃データの汚染によってIDSの耐性を誇張している可能性を浮き彫りにした。
  • 産業制御システムのセキュリティ研究において、きめ細やかで漏洩のない評価プロトコルの必要性が強調された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。