Skip to main content
QUICK REVIEW

[论文解读] Supervisor Synthesis to Thwart Cyber Attack with Bounded Sensor Reading Alterations

Rong Su|arXiv (Cornell University)|Aug 14, 2016
Petri Nets in System Modeling参考文献 12被引用 6
一句话总结

本文提出了一种监督器合成方法,以防御对传感器读数在有界范围内进行篡改的网络攻击,采用基于离散事件系统的正式框架。证明了最大攻击模型(ABSRA)的存在性,并提出了一种算法,用于合成对ABSRA具有鲁棒性的监督器,该监督器可检测攻击或防止其造成危害,从而在部分可观测条件下确保系统安全。

ABSTRACT

One of the major challenges about cyber physical systems is how to prevent cyber attacks to ensure system integrity. There has been a large number of different types of attacks discussed in the modern control and computer science communities. In this paper we aim to investigate one special type of attacks in the discrete-event system framework, where an attacker can arbitrarily alter sensor readings after intercepting them from a target system in order to trick a given supervisor to issue control commands improperly, driving the system to an undesirable state. We first consider the cyber attack problem from an attacker point of view, and formulate an attack with bounded sensor reading alterations (ABSRA) problem. We then show that the supremal (or least restrictive) ABSRA exists and can be synthesized, as long as the plant model and the supervisor model are regular, i.e., representable by finite-state automata. Upon the synthesis of the supremal ABSRA, we present a synthesis algorithm, which ensures that a computed supervisor will be ABSRA-robust , i.e., either an ABSRA will be detectable or will not lead the system to an undesirable state.

研究动机与目标

  • 为应对保护网络物理系统免受智能、隐蔽数据欺骗攻击的挑战,此类攻击会篡改传感器读数。
  • 将一类称为有界传感器读数篡改攻击(ABSRA)的攻击形式化为具有隐蔽性和破坏性特征的有限状态转移器。
  • 开发一种合成算法,生成对任意ABSRA均具有鲁棒性的监督器,该监督器可检测攻击或阻止其导致不良状态。
  • 确定使ABSRA鲁棒监督器存在的最小受保护可观测字母表。

提出的方法

  • 将攻击者的行为建模为有限状态转移器,表示对可观测传感器读数的有界篡改,同时保持隐蔽性和可控性。
  • 将最大ABSRA定义为满足有界篡改约束且可通过监督控制理论计算的最不具限制性的攻击模型。
  • 采用基于组合的方法:计算被控对象、攻击者模型和监督器的乘积,以验证在攻击下是否存在可达的坏标记状态。
  • 应用一种合成过程,计算最大可控且正常的语言,以确保鲁棒性,利用正常性保持计算可行性。
  • 制定最小受保护可观测字母表选择问题,并通过可观测事件子集的暴力枚举方法求解。
  • 利用现有集中式监督控制在部分可观测条件下的研究成果,以确保攻击模型和监督器合成的可判定性与可计算性。

实验结果

研究问题

  • RQ1能否为离散事件系统中传感器读数的有界篡改构造最大攻击模型?
  • RQ2在何种条件下可合成对所有可能的ABSRA攻击均具有鲁棒性的监督器?
  • RQ3是否可以确定使ABSRA鲁棒监督器存在的最小受保护可观测事件集合?
  • RQ4如何在不依赖实时攻击检测的情况下确保监督器的鲁棒性?

主要发现

  • 当被控对象和监督器均可有限表示(即为正则语言)时,最大ABSRA存在且可计算,从而确保最不具限制性的攻击模型。
  • 可合成对ABSRA具有鲁棒性的监督器,使得任何攻击要么因系统异常行为而被检测,要么不会导致系统进入不良状态。
  • 在单个水箱示例中,仅需一个受保护的可观测字母表(例如 {h=H})即可使ABSRA鲁棒监督器存在。
  • 最小受保护可观测字母表问题具有可判定性,可通过暴力枚举求解,尽管其时间复杂度随可观测事件集大小呈指数增长。
  • 所提方法在实际中可行,因为正常性条件(即仅需禁用可观测和可控事件)在实际工业控制系统中自然满足。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。