(702b) Keynote 2 - Approaches for Active Detection of False Data Injection Attacks Via Process Control System Design
AIChE Annual Meeting
2024
2024 AIChE Annual Meeting
Topical Conference: Next-Gen Manufacturing
Cybersecurity and High-Performance Computing in Next-Gen Manufacturing
Thursday, October 31, 2024 - 1:00pm to 1:30pm
Cyberattack detection approaches are an important component of PCS cybersecurity fortification and detect an attack based on anomalies in data over PCS communication channels [5]. Broadly, detection approaches may be categorized as: passive detection schemes which monitor for attacks without an external intervention (e.g., [6]) and active detection methods which utilize an external intervention to detect an attack (e.g., [7]). The design of a detection approach may consider the class of FDI attack to be detected (see [10] for an elaborate taxonomy of FDI attacks). Passive detection schemes have been proposed for the detection of multiplicative [9] and additive FDI attacks [7], under which data over the compromised PCS communication channel is altered by the multiplication or addition of a factor, respectively. A passive detection method may fail to detect FDI attacks under which the behavior of the altered PCS data is indistinguishable from its attack-free behavior (e.g., a replay attack under which the real-time process data are replaced with their historic âattack-freeâ values [7]). To detect attacks that a passive detection scheme fails to detect, an active detection method utilizing an external intervention is used. Several approaches for active detection have been proposed. Examples include, a method using a watermarking signal to detect attacks [7], and a moving target defense under which an auxiliary system with time-varying dynamics is added to the process [8]. However, the influence of controller design on the ability (or lack thereof) of a detection method [9] for the design of an active detection method has not been explored extensively.
In this work, approaches for the design of an active detection method that leverages the influence of controller design on the ability of a detection scheme to detect an attack are presented. The detection of multiplicative and replay FDI attacks is considered. Implementing an external intervention on the attack-free process may induce transients in the process and trigger false alarms in a detection scheme. A reachable set-based detection scheme that guarantees a zero false alarm rate from an external intervention is utilized. Attacks are classified as detectable, undetectable, and potentially detectable based on the ability of the detection scheme to detect them (called attack detectability). The interdependence between controller design, the closed-loop stability of the attacked process, and attack detectability is rigorously analyzed. Leveraging the analysis, approaches for the design of an active detection method that enables attack detection by enhancing attack detectability is presented. The active detection method may use one of two different types of controller design-based interventions. Under the first intervention, a control design parameter switch is implemented to operate the process under the so-called âattack-sensitiveâ parameters. The attack-sensitive parameters are chosen such that an attack on the process destabilizes it, thereby enabling attack detection. However, attack-sensitive parameters may not exist for all classes of FDI attacks. To guarantee the detection of FDI attacks for which attack-sensitive parameters may not exist (e.g., replay FDI attacks), the second intervention with a setpoint change to induce the so-called âattack-revealingâ perturbations in the process may be used. Using either intervention may result in undesirable performance degradation in the process, and a tradeoff between attack detection and performance degradation may exist. Approaches for managing the tradeoff through active detection method design are discussed. Finally, the design and implementation of an appropriate active detection method is demonstrated using simulations of an illustrative process example. The results demonstrate that the detection of multiplicative and replay FDI attacks may be facilitated by an active detection method utilizing an appropriate controller design-based intervention.
References:
[1] IBM., âWhat is Industry 4.0?â, https://www.ibm.com/topics/industry-4-0. Accessed: 9th June 2024.
[2] Liang, G., Zhao, J., Luo, F., Weller, S.R., and Dong, Z.Y., âA review of false data injection attacks against modern power systemsâ, IEEE Transactions on Smart Grid, vol. 8(4), pp.1630-1638, 2016.
[3] Mtukushe, N., Onaolapo, A.K., Aluko, A., and Dorrell, D.G., âReview of cyberattack implementation, detection, and mitigation methods in cyber-physical systemsâ, Energies, vol. 16(13), p.5206, 2023.
[4] Aljundi, I., Rawashdeh, M., Al-Fayoumi, M., Al-Badarneh, A., and Al-Haija, Q.A., âProtecting Critical National Infrastructures: An Overview of Cyberattacks and Countermeasuresâ, In proceedings of the international conference on WorldS4, Singapore, pp. 295-317, 21-24 August, 2023.
[5] Zhang, D., Wang, Q.G., Feng, G., Shi, Y., and Vasilakos, A.V., âA survey on attack detection, estimation and control of industrial cyberâphysical systemsâ, ISA transactions, vol. 116, pp. 1-16, 2021.
[6] Murguia, C. and Ruths, J., âCUSUM and chi-squared attack detection of compromised sensorsâ, In proceedings of the 2016 IEEE Conference on Control Applications, pp. 474-480, Buenos Aires, Argentina, Sep. 19 - 22, 2016
[7] Liu, H., Mo, Y., and Johansson, K. H., âActive detection against replay attack: A survey on watermark design for cyber-physical systems,â in Lecture Notes in Control and Information Sciences. Springer, 2021, pp. 145â171.
[8] Babadi, N. and Doustmohammadi, N., âA moving target defence approach for detecting deception attacks on cyber-physical systems,â Computers and Electrical Engineering, vol. 100, p. 107931, 2022.
[9] Narasimhan, S., El-Farra, N. H., and Ellis, M. J., âDetectability-based controller design screening for processes under multiplicative cyberattacks,â AIChE Journal, 68:e17430, 2022.
[10] Reda, H.T., Anwar, A. and Mahmood, A., âComprehensive survey and taxonomies of false data injection attacks in smart grids: attack models, targets, and impactsâ, Renewable and Sustainable Energy Reviews, vol. 163, p.112423, 2022.