论文标题

重新访问IC中的异常检测:旨在隔离攻击和故障

Revisiting Anomaly Detection in ICS: Aimed at Segregation of Attacks and Faults

论文作者

Ahmed, Chuadhry Mujeeb, Prakash, Jay, Zhou, Jianying

论文摘要

在工业控制系统(ICS)中,其复杂的传感器网络,执行器和控制器对关键基础设施和工业生产单位提出了安全问题。该意见论文努力启动有关设计算法的讨论,这些算法可以将攻击与故障隔离开来。大多数提出的异常检测机制无法因故障而区分攻击和异常。我们争论要解决这一重要问题,这是我们在CPS安全研究中的经验。首先,我们利用经济和心理方面的研究和访谈分析来激励。然后突出了主要的挑战。此外,我们提出了多个方法的方向,并提供了适当的推理和ICS系统的示例。

In an Industrial Control System (ICS), its complex network of sensors, actuators and controllers have raised security concerns for critical infrastructures and industrial production units. This opinion paper strives to initiate discussion on the design algorithms which can segregate attacks from faults. Most of the proposed anomaly detection mechanisms are not able to differentiate between an attack and an anomaly due to a fault. We argue on the need of solving this important problem form our experiences in CPS security research. First, we motivate using analysis of studies and interviews though economical and psychological aspects. Then main challenges are highlighted. Further, we propose multiple directions of approach with suitable reasoning and examples from ICS systems.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源