2017/07/10 by Ilija Jovanov, Jovanov, Ilija, Miroslav Pajić +1 · 1 citation
Engineering · Computer Science · #Smart Grid Security and Resilience #Network Security and Intrusion Detection #Security and Verification in Computing
paper · pdf · doi:10.48550/arxiv.1707.02950
The increase in network connectivity has also resulted in several\nhigh-profile attacks on cyber-physical systems. An attacker that manages to\naccess a local network could remotely affect control performance by tampering\nwith sensor measurements delivered to the controller. Recent results have shown\nthat with network-based attacks, such as Man-in-the-Middle attacks, the\nattacker can introduce an unbounded state estimation error if measurements from\na suitable subset of sensors contain false data when delivered to the\ncontroller. While these attacks can be addressed with the standard\ncryptographic tools that ensure data integrity, their continuous use would\nintroduce significant communication and computation overhead. Consequently, we\nstudy effects of intermittent data integrity guarantees on system performance\nunder stealthy attacks. We consider linear estimators equipped with a general\ntype of residual-based intrusion detectors (including \χ2 and SPRT\ndetectors), and show that even when integrity of sensor measurements is\nenforced only intermittently, the attack impact is significantly limited;\nspecifically, the state estimation error is bounded or the attacker cannot\nremain stealthy. Furthermore, we present methods to: (1) evaluate the effects\nof any given integrity enforcement policy in terms of reachable\nstate-estimation errors for any type of stealthy attacks, and (2) design an\nenforcement policy that provides the desired estimation error guarantees under\nattack. Finally, on three automotive case studies we show that even with less\nthan 10% of authenticated messages we can ensure satisfiable control\nperformance in the presence of attacks.\n