Affiliation:
1. Zhejiang University of Technology, China
2. Zhejiang University, China
3. Zhejiang Sci-Tech University, China
4. Georgia Institute of Technology, USA
Abstract
ICPS software and hardware suffer from low update frequency, making it easier for insiders to bypass external defenses and launch concealed destructive attacks. To address these concerns, we design a device fingerprinting method based on multi-physical features, augmenting current intrusion detection techniques in the ICPS environment. In this article, we use the sorting system as an example, demonstrating that the proposed device fingerprinting technology has generality in the intrusion detection of ICPS control flow. Specifically, we first formalize the physical model of the sorting system to analyze the critical device features. Then, we extract these physical features from the sensor data collected in a physical testbed. Utilizing featurized data, we train a classifier that generates fingerprints in real-time in the production environment. Moreover, we develop a differential detection model based on device fingerprints to discover stealthy insider attacks efficiently. We evaluate the proposed method in a real-world testbed. Experiment results show that the detecting performance of classifiers approaches 100% when the the number of component types is small.
Funder
National Natural Science Foundation of China
Zhejiang Provincial Natural Science Foundation of China
New Century 151 Talent Project of Zhejiang Province
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications