[论文解读] Dynamic Watermarking: Active Defense of Networked Cyber-Physical Systems
本文提出动态水印技术作为网络化网络物理系统(CPS)的主动防御机制,其中执行器向控制回路注入私有激励信号,以检测恶意传感器篡改。通过分析传感器测量值与预期水印信号之间的统计一致性,该方法实现了高可靠性的实时攻击检测,仿真结果表明在二阶ARX系统中,攻击在5000个时间步内被检测到,且误报率较低。
The coming decades may see the large scale deployment of networked cyber-physical systems to address global needs in areas such as energy, water, healthcare, and transportation. However, as recent events have shown, such systems are vulnerable to cyber attacks. Being safety critical, their disruption or misbehavior can cause economic losses or injuries and loss of life. It is therefore important to secure such networked cyber-physical systems against attacks. In the absence of credible security guarantees, there will be resistance to the proliferation of cyber-physical systems, which are much needed to meet global needs in critical infrastructures and services. This paper addresses the problem of secure control of networked cyber-physical systems. This problem is different from the problem of securing the communication network, since cyber-physical systems at their very essence need sensors and actuators that interface with the physical plant, and malicious agents may tamper with sensors or actuators, as recent attacks have shown. We consider physical plants that are being controlled by multiple actuators and sensors communicating over a network, where some sensors could be "malicious," meaning that they may not report the measurements that they observe. We address a general technique by which the actuators can detect the actions of malicious sensors in the system, and disable closed-loop control based on their information. This technique, called "watermarking," employs the technique of actuators injecting private excitation into the system which will reveal malicious tampering with signals. We show how such an active defense can be used to secure networked systems of sensors and actuators.
研究动机与目标
- 为解决安全关键型网络物理系统(CPS)抵御内部人员及基于传感器的网络攻击这一关键挑战,此类攻击可绕过传统网络安全防护。
- 通过聚焦物理层完整性(传感器与执行器直接与物理对象交互),克服被动网络安全防护的局限性。
- 开发一种可推广的主动防御机制,实现对恶意传感器行为的检测,而无需依赖加密密钥或对攻击模式的先验知识。
- 通过执行器利用嵌入的私有激励信号验证传感器测量值的真实性,确保CPS中的安全控制。
- 为检测如Stuxnet或Maroochy-Shire事件中所见的隐蔽攻击(攻击者操纵传感器数据以逃避检测)提供一种实用且可扩展的解决方案。
提出的方法
- 该方法通过执行器向控制输入注入仅控制器和执行器知晓的私有、非重复激励信号,实现动态水印技术。
- 系统将被控对象建模为稳定的ARX过程,执行器应用同时包含反馈和私有激励信号的控制输入。
- 采用序列假设检验,基于最近观测值的负对数似然函数,将其与正常运行下的期望分布进行比较。
- 似然函数在最近测量值的滑动窗口上计算,若其超过预设阈值,则触发报警,表明可能存在传感器被入侵。
- 水印信号被设计为与过程噪声在统计上可区分,即使攻击者估计并关联过程噪声,也能实现检测。
- 该方法利用物理信号的语义一致性:任何因恶意报告导致的信号行为偏离,都将破坏水印信号的统计模式。
实验结果
研究问题
- RQ1是否可开发一种主动防御机制,在不依赖加密认证的情况下,检测网络化CPS中恶意传感器篡改?
- RQ2如何将私有激励信号注入控制回路,以实现对传感器操纵的检测,同时保持系统稳定性?
- RQ3动态水印技术在多大程度上可检测那些模仿正常系统行为的隐蔽攻击(如重放传感器数据或估计过程噪声)?
- RQ4何种统计检验可可靠检测因传感器被入侵导致的信号行为偏离,且误报率较低?
- RQ5该方法是否可推广至非最小相位的非线性及高阶系统,而不仅限于最小相位ARX系统?
主要发现
- 在二阶ARX系统中,动态水印技术成功检测到第4500个时间步启动的传感器攻击,负对数似然函数在攻击发生后持续上升。
- 该方法在无需攻击模式先验知识的情况下实现可靠检测,即使攻击者估计并关联过程噪声以逃避检测亦然。
- 在正常运行期间,似然函数保持在可接受范围内,表明在良性条件下误报率较低。
- 该方法在传统检测算法难以察觉的系统中(如具有相关噪声和可观测性受限的系统)有效检测到攻击。
- 仿真结果证实,水印信号可嵌入控制输入中而不引起系统失稳,因为系统为最小相位,且预均衡器确保了稳定性。
- 该方法提供了一种可扩展的非加密防御机制,适用于电力系统、交通系统及工业控制系统等安全关键型CPS的实时部署。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。