Skip to main content
QUICK REVIEW

[論文レビュー] No Need to Know Physics: Resilience of Process-based Model-free Anomaly Detection for Industrial Control Systems

Alessandro Erba, Nils Ole Tippenhauer|arXiv (Cornell University)|Dec 7, 2020
Smart Grid Security and Resilience参考文献 21被引用数 5
ひとこと要約

本論文は、物理システムの知識を一切必要とせずに、モデルフリーのプロセスベース異常検出手法を回避する合成センサースプーフィング攻撃を生成する一般化されたフレームワークを提案する。初期の検出性能は強く示されたが、空間的および時間的相関のモデル化が不十分なため、評価された検出器の4つ中3つがこれらの攻撃に対して失敗する一方、1つのレジリエンスを持つ検出器は、制約のないリプレイが使われない限り性能を維持する。

ABSTRACT

In recent years, a number of process-based anomaly detection schemes for Industrial Control Systems were proposed. In this work, we provide the first systematic analysis of such schemes, and introduce a taxonomy of properties that are verified by those detection systems. We then present a novel general framework to generate adversarial spoofing signals that violate physical properties of the system, and use the framework to analyze four anomaly detectors published at top security conferences. We find that three of those detectors are susceptible to a number of adversarial manipulations (e.g., spoofing with precomputed patterns), which we call Synthetic Sensor Spoofing and one is resilient against our attacks. We investigate the root of its resilience and demonstrate that it comes from the properties that we introduced. Our attacks reduce the Recall (True Positive Rate) of the attacked schemes making them not able to correctly detect anomalies. Thus, the vulnerabilities we discovered in the anomaly detectors show that (despite an original good detection performance), those detectors are not able to reliably learn physical properties of the system. Even attacks that prior work was expected to be resilient against (based on verified properties) were found to be successful. We argue that our findings demonstrate the need for both more complete attacks in datasets, and more critical analysis of process-based anomaly detectors. We plan to release our implementation as open-source, together with an extension of two public datasets with a set of Synthetic Sensor Spoofing attacks as generated by our framework.

研究の動機と目的

  • 産業制御システム(ICS)におけるモデルフリーのプロセスベース異常検出手法のレジリエンスを体系的に分析すること。
  • 物理的プロセス特性のモデル化が不十分であることが原因で生じる既存の異常検出器の脆弱性を特定すること。
  • 物理的システムの知識が不要な状態で、検出を回避できる一貫性のある悪意あるスプーフィング信号を生成する一般化可能なフレームワークを開発すること。
  • 攻撃者が物理的システムの知識がなくても検出を回避可能であることを実証し、従来の「ステルス性」に関する仮定に疑問を呈すること。
  • 標的化され、物理的特性に配慮した悪意ある攻撃を用いた異常検出器の評価を促進するための強化されたデータセットの構築を提言すること。

提案手法

  • 異常検出器が検証する物理的特性の分類法を提案:時間的整合性、空間的整合性、統計的特性。
  • 通常のシステム動作の受動的観測のみを用いて、合成センサースプーフィング攻撃を生成する一般化されたフレームワークを設計。
  • 物理的制約(定数値や事前に計算されたノイズパターンなど)に反するが、統計的および時間的パターンを保持するスプーフィング信号を構築。
  • リプレイ、定数スプーフィング、ノイズベースのパターンを含む攻撃を実装。これらは通常の動作を模倣しながら検出を回避する。
  • 生成されたスプーフィング攻撃を含む実世界のICSデータセットを用いて検出器を評価。
  • 検出失敗の度合いを測定するために、再現率(真正陽性率)を用いて検出器の性能を測定。

実験結果

リサーチクエスチョン

  • RQ1物理システムの知識がなくても、モデルフリーの異常検出器は悪意あるスプーフィング攻撃を回避可能か?
  • RQ2時間的、空間的、統計的特性のうち、スプーフィング攻撃に対する検出器のレジリエンスに重要なのはどれか?
  • RQ3同じ悪意ある攻撃に対して、なぜ一部の検出器はレジリエンスを示すが、他の検出器は失敗するのか?
  • RQ4既存の公開データセットは、現実の悪意ある操作パターンをどれほど適切に反映していないのか?
  • RQ5検出器のレジリエンスを評価するための一貫性のある、検出不能なスプーフィング信号を生成する一般フレームワークを構築可能か?

主な発見

  • 評価された4つのモデルフリー異常検出器のうち3つが合成センサースプーフィング攻撃に対して脆弱であり、再現率はそれぞれ0.63から0.06、0.47から0.0、0.28から0.0に低下した。
  • 単純な定数スプーフィング攻撃ですら、2つの検出器の再現率を0.0にまで低下させ、基本的な操作でも検出を回避可能であることを示した。
  • レジリエンスを持つ検出器(Chen et al. [8])は、制約のないリプレイが使われない限り性能を維持する。これは、時間的および空間的相関のモデル化に依存していることを示している。
  • モデルから時間的および空間的特徴を除去すると、もともとレジリエンスを持つ検出器も脆弱になる。これは、これらの特徴がレジリエンスの鍵であることを証明している。
  • フレームワークは、人間には検出可能だが検出器には検出されないスプーフィング信号を効果的に生成した。これにより、攻撃の有効性とステルス性が裏付けられた。
  • 従来、物理的特性の検証に基づく検出器のレジリエンスに関する仮定は不十分であることが判明した。物理的特性に反する攻撃でも、検出を回避できるからである。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。