SIDS: State-based intrusion detection for stage-based cyber physical systems
Abdullah Khalili,
Ashkan Sami,
Amin Khozaei and
Saber Pouresmaeeli
International Journal of Critical Infrastructure Protection, 2018, vol. 22, issue C, 113-124
Abstract:
Attacks to Cyber Physical Systems (CPSs) are detected by Industrial Intrusion Detection Systems (IIDSs). Operation of stage-based CPSs (those for which their underlying process is batch) consists of three parts: normal states, normal transitions between the normal states, and normal time-intervals for transitions. Unfortunately, state-of-the-art IIDSs directly address cyber-attacks that result in anomalous states whereas anomalous transitions or time-intervals can also indicate cyber-attacks. In this paper, a State-based IDS (SIDS) is proposed to detect all three anomalies. For doing this, SIDS first automatically extracts the normal behavior of CPS. Then it monitors current CPS behavior and detects intrusions by directly looking at the data of field layer. A small-scale but real CPS (a mixer process) is provided to illustrate how SIDS works. In addition, experimental results on three cyber-attacks orchestrated on a simulated milk pasteurization process indicate that SIDS can successfully detect cyber-attacks to large I/O CPSs.
Keywords: Cyber Physical System (CPS); Industrial Control; Intrusion Detection System (IDS); Process Control; Security (search for similar items in EconPapers)
Date: 2018
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S1874548216300440
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:ijocip:v:22:y:2018:i:c:p:113-124
DOI: 10.1016/j.ijcip.2018.06.003
Access Statistics for this article
International Journal of Critical Infrastructure Protection is currently edited by Leon Strous
More articles in International Journal of Critical Infrastructure Protection from Elsevier
Bibliographic data for series maintained by Catherine Liu ().