Abstract
Critical infrastructure, such as water treatment facilities, largely relies on the effective functioning of industrial control systems (ICSs). Due to the wide adoption of high-speed network and digital infrastructure technologies, these systems are now highly interconnected not only to corporate networks but also to the public Internet, mostly for remote control and monitoring purposes. Sophisticated cyber-attacks may take advantage the increased interconnectedness or other security gaps of an ICS and infiltrate the system with devastating consequences to the economy, national security, and even human life. Due to the paramount importance of detecting and isolating these attacks, we propose an unsupervised anomaly detection approach that employs causal inference to construct a robust anomaly score in two phases. First, minimal domain knowledge via causal models helps identify critical interdependencies in the system, while univariate models contribute to individually learn the normal behavior of the system’s components. In the final phase, we employ the extreme studentized deviate (ESD) on the computed score to detect attacks and to exclude any irrelevant sensor signals. Our approach is validated on the widely used Secure Water Treatment (SWaT) benchmark, and it exhibits the highest F1 score with zero false alarms, which is extremely important for real-world deployment.
Funder
Österreichische Forschungsförderungsgesellschaft
Graz University of Technology
Subject
Electrical and Electronic Engineering,Biochemistry,Instrumentation,Atomic and Molecular Physics, and Optics,Analytical Chemistry
Reference55 articles.
1. Gill, H. (2008, January 18–20). From vision to reality: Cyber-physical systems. Proceedings of the HCSS National Workshop on New Research Directions for High Confidence Transportation CPS: Automotive, Aviation, and Rail, Austin, TX, USA.
2. Protecting drinking water utilities from cyberthreats;Clark;J. Am. Water Work. Assoc.,2017
3. Magazine, S. (2022, November 05). Hacker Breaks into Florida Water Treatment Facility, Changes Chemical Levels. Available online: https://www.securitymagazine.com/articles/94552-hacker-breaks-into-florida-water-treatment-facility-changes-chemical-levels.
4. A review of cybersecurity incidents in the water sector;Hassanzadeh;J. Environ. Eng.,2020
5. Ahmed, C.M., MR, G.R., and Mathur, A.P. (2020, January 6). Challenges in machine learning based approaches for real-time anomaly detection in industrial control systems. Proceedings of the 6th ACM on Cyber-Physical System Security Workshop, Taipei, Taiwan.
Cited by
5 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献