Checking is Believing: Event-Aware Program Anomaly Detection in Cyber-Physical Systems

نویسندگان

چکیده

Securing cyber-physical systems (CPS) against malicious attacks is of paramount importance because these may cause irreparable damages to physical systems. Recent studies have revealed that control programs running on CPS devices suffer from both control-oriented (e.g., code-injection or code-reuse attacks) and data-oriented non-control data attacks). Unfortunately, existing detection mechanisms are insufficient detect runtime exploits, due the lack execution semantics checking. In this work, we propose Orpheus, a new security methodology for defending by enforcing semantics. We first present general method reasoning program (i.e., causal dependencies between context flows), including event identification dependence analysis. As an instantiation then behavior model, i.e., event-aware finite-state automaton (eFSA). eFSA takes advantage event-driven nature incorporates checking in anomaly detection. It detects exploits if specific missing along with corresponding dependent state transition. evaluate our prototype's performance conducting case under attacks. Results show can successfully different Our prototype Raspberry Pi incurs low overhead, taking 0.0001s each transition integrity checking, 0.063s~0.211s contextual consistency

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Event Detection through Differential Pattern Mining in Cyber-Physical Systems

Extracting knowledge from sensor data for various purposes has received a great deal of attention by the data mining community. For the purpose of event detection in cyber-physical systems (CPS), e.g., damage in building or aerospace vehicles from the continuous arriving data is challenging due to the detection quality. Traditional data mining schemes are used to reduce data that often use metr...

متن کامل

Statistical Model Checking for Cyber-Physical Systems

Statistical Model Checking is useful in situations where it is either inconvenient or impossible to build a concise representation of the global transition relation. This happens frequently with cyberphysical systems: Two examples are verifying Stateflow-Simulink models and in reasoning about biochemical reactions in Systems Biology. The main problem with Statistical Model Checking is caused by...

متن کامل

Resource-aware control for cyber-physical systems

An efficient usage of available resources is a substantial requirement for the successful control design in cyber-physical systems. Recent results indicate major benefits of event-based control compared to conventional designs, when resources such as communication, energy, and/or computation, are scarce. In this work we consider multiple control loops which share the communication resource. We ...

متن کامل

Embedded Cyber-Physical Anomaly Detection in Smart Meters

Smart grid security has many facets, ranging over a spectrum from resisting attacks aimed at supervisory and control systems, to end user privacy concerns while monitored by the utility enterprise. This multi-faceted problem also includes vulnerabilities that arise from deployment of local cyber-physical attacks at a smart metering location, with a potential to a) manipulate the measured energy...

متن کامل

On the Learning of Timing Behavior for Anomaly Detection in Cyber-Physical Production Systems

Model-based anomaly detection approaches by now have established themselves in the field of engineering sciences. Algorithms from the field of artificial intelligence and machine learning are used to identify a model automatically based on observations. Many algorithms have been developed to manage different tasks such as monitoring and diagnosis. However, the usage of the factor of time in mod...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: IEEE Transactions on Dependable and Secure Computing

سال: 2021

ISSN: ['1941-0018', '1545-5971', '2160-9209']

DOI: https://doi.org/10.1109/tdsc.2019.2906161