[论文解读] Supervisory Control of Discrete-event Systems under Attacks
本文提出了一种针对在多对手网络攻击下传感器观测被污染的离散事件系统(DES)的监督控制框架。它引入了一种新型的攻击下可观察性条件,并表明对于输出符号攻击(即攻击者插入或删除特定符号)的情形,通过修改输出映射,可使用经典DES工具实现监督控制,从而在不扩展状态空间的前提下实现多项式时间验证与监督器合成。
We consider a multi-adversary version of the supervisory control problem for discrete-event systems, in which an adversary corrupts the observations available to the supervisor. The supervisor's goal is to enforce a specific language in spite of the opponent's actions and without knowing which adversary it is playing against. This problem is motivated by applications to computer security in which a cyber defense system must make decisions based on reports from sensors that may have been tampered with by an attacker. We start by showing that the problem has a solution if and only if the desired language is controllable (in the Discrete event system classical sense) and observable in a (novel) sense that takes the adversaries into account. For the particular case of attacks that insert symbols into or remove symbols from the sequence of sensor outputs, we show that testing the existence of a supervisor and building the supervisor can be done using tools developed for the classical DES supervisory control problem, by considering a family of automata with modified output maps, but without expanding the size of the state space and without incurring on exponential complexity on the number of attacks considered., we construct observers that are robust against attacks and lead to an automaton representation of the supervisor. We also develop a test for observability under such replacement-removal attacks by using the so-called product automata.
研究动机与目标
- 解决在未知网络对手操纵传感器观测时,离散事件系统监督控制的挑战。
- 构建一个博弈论框架,使监督器在对手操纵传感器数据的情况下仍能强制执行期望语言。
- 确定在不预先知晓哪个对手处于活动状态的情况下,存在一个监督器以战胜任何对手的充分必要条件。
- 聚焦于输出符号攻击——即对手在传感器日志中插入或删除特定符号——并提供高效的合成方法。
- 通过证明可观察性测试与监督器构建可简化为具有修改输出映射的经典DES问题,实现实际部署。
提出的方法
- 引入一个零和多对手博弈模型,其中监督器必须在对手操纵观测序列的情况下强制执行语言K。
- 定义一种新的攻击下可观察性概念,其依赖于对手操纵输出字符串中特定符号的能力。
- 针对输出符号攻击,通过移除任意一对对手可能共同攻击的符号,构建一组具有修改输出映射的自动机族。
- 在该自动机族上测试经典可观察性,以验证攻击下的新可观察性条件。
- 构建一个有限状态机监督器,用于追踪首次观测到的利用符号,其状态对应于干净状态、s1、s2等,基于观测到的攻击模式。
- 通过组合每对对手的独立监督器来合成监督器,使用一个公式根据观测字符串中是否存在利用符号来禁用或启用转移。
实验结果
研究问题
- RQ1在何种条件下,存在一个监督器,能够对抗多个未知对手对传感器观测的操纵,强制执行期望语言K?
- RQ2如何重新定义可观察性,以考虑离散事件系统中输出符号被对手操纵的情形?
- RQ3能否将输出符号攻击下的监督控制问题简化为不扩展状态空间的经典DES控制问题?
- RQ4在该类攻击下,验证可观察性与构建监督器的计算复杂度是多少?
- RQ5如何设计一个监督器,以应对对手身份不确定的情况,同时确保安全性和活锁性质的正确强制执行?
主要发现
- 当且仅当期望语言K在经典意义下是可控的且在攻击下可观测时,监督器存在;这一新条件考虑了对手对输出符号的操纵。
- 对于输出符号攻击,攻击下的可观察性测试可简化为在具有修改输出映射的自动机族上检查经典可观察性,从而实现多项式时间验证。
- 通过经典DES工具,无需扩展原始被控对象自动机的状态空间,即可实现输出符号攻击下的监督器合成。
- 所需监督器的数量为O(|A|²),其中|A|为对手数量,每个监督器在最坏情况下关于被控对象状态数具有指数复杂度。
- 一种将所有对手同时建模于状态空间中的替代方法,其最坏情况复杂度为O(e^{|A||X|}),相比之下,所提方法显著更高效。
- 可实际实现一个监督器,作为具有M+1个状态的有限状态机,其中M为不同利用符号的数量,通过追踪首次观测到的利用符号来做出控制决策。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。