Generating invariants using design and data-centric approaches for distributed attack detection
Muhammad Azmi Umer,
Aditya Mathur,
Khurum Nazir Junejo and
Sridhar Adepu
International Journal of Critical Infrastructure Protection, 2020, vol. 28, issue C
Abstract:
A cyber attack launched on a critical infrastructure (CI), such as a power grid or a water treatment plant, could lead to anomalous behavior. There exist several methods to detect such behavior. This paper reports on a study conducted to compare two methods for detecting anomalies in CI. One of these methods, referred to as design-centric, generates invariants from the design of a CI. Another method, referred to as data-centric, generates the invariants from data collected from an operational CI. The key question that motivated the study is “How do design and data-centric methods compare in the effectiveness of the generated invariants in detecting process anomalies.” The data-centric approach used Association Rule Mining for generating invariants from operational data. These invariants, and their performance in detecting anomalies, was compared against those generated by a design-centric approach reported in the literature. The entire study was conducted in the context of an operational scaled down version of a water treatment plant.
Keywords: Association rule mining; Critical Infrastructure; Cyber-physical attacks; Distributed attack detection; SCADA security; Machine learning; Water treatment plant (search for similar items in EconPapers)
Date: 2020
References: View complete reference list from CitEc
Citations: View citations in EconPapers (1)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S1874548220300056
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:ijocip:v:28:y:2020:i:c:s1874548220300056
DOI: 10.1016/j.ijcip.2020.100341
Access Statistics for this article
International Journal of Critical Infrastructure Protection is currently edited by Leon Strous
More articles in International Journal of Critical Infrastructure Protection from Elsevier
Bibliographic data for series maintained by Catherine Liu ().