论文标题
重播攻击的顺序检测
Sequential detection of Replay attacks
论文作者
论文摘要
对网络物理系统的攻击最多的攻击形式之一是重播攻击。重播信号的统计相似性和真实的观察结果使重播攻击难以检测。在本文中,我们通过在控制输入中添加水印,然后使用累积总和(CUSUM)测试对创新信号和水印信号进行累积总和测试进行弹性检测来解决重播攻击检测的问题。我们在重播攻击之前和之后的两个关节分布之间得出了Kullback-Liebler Divergence(KLD)的表达,这与检测延迟无关紧要。我们对派生的KLD表达进行结构分析,并提出了一种改善相对程度大于一个系统的系统的KLD技术。提出了一种找到最佳水印信号差异的方案,以提高控制成本的固定增加,以最大程度地提高CUSUM测试的KLD。我们提供各种数值模拟结果来支持我们的理论。还将提出的方法与最先进的方法进行了比较。
One of the most studied forms of attacks on the cyber-physical systems is the replay attack. The statistical similarities of the replay signal and the true observations make the replay attack difficult to detect. In this paper, we have addressed the problem of replay attack detection by adding watermarking to the control inputs and then performed resilient detection using cumulative sum (CUSUM) test on the joint statistics of the innovation signal and the watermarking signal. We derive the expression of the Kullback-Liebler divergence (KLD) between the two joint distributions before and after the replay attack, which is asymptotically inversely proportional to the detection delay. We perform structural analysis of the derived KLD expression and suggest a technique to improve the KLD for the systems with relative degree greater than one. A scheme to find the optimal watermarking signal variance for a fixed increase in the control cost to maximize the KLD under the CUSUM test is presented. We provide various numerical simulation results to support our theory. The proposed method is also compared with a state-of-the-art method.