Skip to main content
QUICK REVIEW

[論文レビュー] On Decidability of Existence of Nonblocking Supervisors Resilient to Smart Sensor Attacks

Rong Su|arXiv (Cornell University)|Sep 6, 2020
Petri Nets in System Modeling参考文献 30被引用数 4
ひとこと要約

本稿は、離散イベントシステムにおけるスマートセンサ攻撃に対して耐性を持つ非ブロッキングなスーパvisorの存在の決定可能性を確立する。リスクペアと真正な符号化方式を導入することで、プラント、スーパvisor、損傷言語が正則である場合、耐性を持つスーパvisorをアルゴリズム的に合成可能であることを証明し、スマートサイバー攻撃に関するDES文献における最初のこのような結果をもたらす。

ABSTRACT

Cybersecurity of discrete event systems (DES) has been gaining more and more attention recently, due to its high relevance to the so-called 4th industrial revolution that heavily relies on data communication among networked systems. One key challenge is how to ensure system resilience to sensor and/or actuator attacks, which may tamper data integrity and service availability. In this paper we focus on some key decidability issues related to smart sensor attacks. We first present a sufficient and necessary condition that ensures the existence of a smart sensor attack, which reveals a novel demand-supply relationship between an attacker and a controlled plant, represented as a set of risky pairs. Each risky pair consists of a damage string desired by the attacker and an observable sequence feasible in the supervisor such that the latter induces a sequence of control patterns, which allows the damage string to happen. It turns out that each risky pair can induce a smart weak sensor attack. Next, we show that, when the plant, supervisor and damage language are regular, it is computationally feasible to remove all such risky pairs from the plant behaviour, via a genuine encoding scheme, upon which we are able to establish our key result that the existence of a nonblocking supervisor resilient to smart sensor attacks is decidable. To the best of our knowledge, this is the first result of its kind in the DES literature on cyber attacks. The proposed decision process renders a specific synthesis procedure that guarantees to compute a resilient supervisor whenever it exists, which so far has not been achieved in the literature.

研究の動機と目的

  • 離散イベントシステムにおける、すべてのスマートセンサ攻撃に対して耐性を持つ非ブロッキングスーパvisorが存在しうるかどうかという未解決問題に取り組む。
  • このような耐性スーパvisorがアルゴリズム的に合成可能となる条件を形式化する。
  • 耐性スーパvisorの存在を決定する手続きを確立し、DESにおけるサイバーフィジカルセキュリティ分野における重要な空白を埋める。
  • 攻撃者の目的と観測可能なシステム動作を結びつける「リスクペア」として、スマートセンサ攻撃を新たな特徴付けで提示する。
  • 存在する限りにおいて、耐性スーパvisorを保証的に計算可能な構成的合成手法を提供する。

提案手法

  • 攻撃者が望む損傷文字列と、制御パターンの系列によって損傷を引き起こせるスーパvisorで実現可能な観測可能な系列からなる『リスクペア』の概念を導入する。
  • 各リスクペアがスマート弱いセンサ攻撃を誘発することを示し、攻撃者が損傷を負わせつつも検知されない能力を形式化する。
  • すべてのリスクペアをプラントの動作から除去する真正な符号化方式を提案し、こうした攻撃の可能性を完全に排除する。
  • 製品オートマトン $Π(Σ)$ の制御可能で到達可能な部分オートマトンに基づくスーパvisor合成手順を構築し、条件付き制御可能性と観測可能性を保証する。
  • 観測、制御、攻撃対応情報を符号化する状態を備えた形式的オートマトンモデル $Π(Σ)$ を用いて、スーパvisorの動作を表現する。
  • 耐性スーパvisorの存在と制御可能で到達可能な部分オートマトンの存在との間の同値性を確立し、決定可能性を実現する。

実験結果

リサーチクエスチョン

  • RQ1離散イベントシステムにおいて、すべての可能なスマートセンサ攻撃に対して耐性を持つ非ブロッキングスーパvisorが存在する条件は何か?
  • RQ2システムの構成要素が正則である場合、このような耐性スーパvisorの存在がアルゴリズム的に決定可能か?
  • RQ3観測可能な動作と制御パターンの観点から、スマートセンサ攻撃をどのように形式的に特徴付けられるか?
  • RQ4非ブロッキング動作を保証するとともに、すべてのスマート攻撃に対して耐性を持つスーパvisorを合成可能か?
  • RQ5隠れ、知的なセンサ攻撃に対して耐性を持つために、スーパvisorとプラントが満たすべき構造的性質は何か?

主な発見

  • プラント、スーパvisor、損傷言語が正則である場合、スマートセンサ攻撃に対して耐性を持つ非ブロッキングスーパvisorの存在は決定可能である。
  • すべてのリスクペアをシステム動作から除去する真正な符号化方式を用いることで、耐性スーパvisorをアルゴリズム的に合成可能である。
  • 本稿は、$Π(Σ)$ の制御可能で到達可能な部分オートマトンと非ブロッキングな耐性スーパvisor候補との間の一対一対応関係を確立した。
  • 本手法は、存在する限りにおいて耐性スーパvisorを保証的に計算可能であり、DESベースのサイバーフィジカルセキュリティ分野における長年の未解決問題を解決する。
  • リスクペアによるスマート攻撃の特徴付けは、攻撃者の目的とシステムの観測可能性の間の根本的な「需要・供給」関係を明らかにする。
  • 本結果は、スマートセンサ攻撃に対する耐性スーパvisor制御の決定可能性を確立したDES文献における最初の結果であり、構成的合成手順を備えている。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。