Checking is Believing: Event-Aware Program Anomaly Detection in Cyber-Physical Systems
نویسندگان
چکیده
Securing cyber-physical systems (CPS) against malicious attacks is of paramount importance because these may cause irreparable damages to physical systems. Recent studies have revealed that control programs running on CPS devices suffer from both control-oriented (e.g., code-injection or code-reuse attacks) and data-oriented non-control data attacks). Unfortunately, existing detection mechanisms are insufficient detect runtime exploits, due the lack execution semantics checking. In this work, we propose Orpheus, a new security methodology for defending by enforcing semantics. We first present general method reasoning program (i.e., causal dependencies between context flows), including event identification dependence analysis. As an instantiation then behavior model, i.e., event-aware finite-state automaton (eFSA). eFSA takes advantage event-driven nature incorporates checking in anomaly detection. It detects exploits if specific missing along with corresponding dependent state transition. evaluate our prototype's performance conducting case under attacks. Results show can successfully different Our prototype Raspberry Pi incurs low overhead, taking 0.0001s each transition integrity checking, 0.063s~0.211s contextual consistency
منابع مشابه
Event Detection through Differential Pattern Mining in Cyber-Physical Systems
Extracting knowledge from sensor data for various purposes has received a great deal of attention by the data mining community. For the purpose of event detection in cyber-physical systems (CPS), e.g., damage in building or aerospace vehicles from the continuous arriving data is challenging due to the detection quality. Traditional data mining schemes are used to reduce data that often use metr...
متن کاملStatistical Model Checking for Cyber-Physical Systems
Statistical Model Checking is useful in situations where it is either inconvenient or impossible to build a concise representation of the global transition relation. This happens frequently with cyberphysical systems: Two examples are verifying Stateflow-Simulink models and in reasoning about biochemical reactions in Systems Biology. The main problem with Statistical Model Checking is caused by...
متن کاملResource-aware control for cyber-physical systems
An efficient usage of available resources is a substantial requirement for the successful control design in cyber-physical systems. Recent results indicate major benefits of event-based control compared to conventional designs, when resources such as communication, energy, and/or computation, are scarce. In this work we consider multiple control loops which share the communication resource. We ...
متن کاملEmbedded Cyber-Physical Anomaly Detection in Smart Meters
Smart grid security has many facets, ranging over a spectrum from resisting attacks aimed at supervisory and control systems, to end user privacy concerns while monitored by the utility enterprise. This multi-faceted problem also includes vulnerabilities that arise from deployment of local cyber-physical attacks at a smart metering location, with a potential to a) manipulate the measured energy...
متن کاملOn the Learning of Timing Behavior for Anomaly Detection in Cyber-Physical Production Systems
Model-based anomaly detection approaches by now have established themselves in the field of engineering sciences. Algorithms from the field of artificial intelligence and machine learning are used to identify a model automatically based on observations. Many algorithms have been developed to manage different tasks such as monitoring and diagnosis. However, the usage of the factor of time in mod...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: IEEE Transactions on Dependable and Secure Computing
سال: 2021
ISSN: ['1941-0018', '1545-5971', '2160-9209']
DOI: https://doi.org/10.1109/tdsc.2019.2906161