Resilience to denial-of-service and integrity attacks: A structured systems approach *

被引:5
|
作者
Ramasubramanian, Bhaskar [1 ]
Rajan, M. A. [2 ]
Chandra, M. Girish [2 ]
Cleaveland, Rance I. [3 ,4 ]
Marcus, Steven [3 ,5 ]
机构
[1] Univ Washington, Dept Elect & Comp Engn, Network Secur Lab, Seattle, WA 98195 USA
[2] Tata Consultancy Serv, Innovat Labs, Bangalore 560066, Karnataka, India
[3] Univ Maryland, Inst Syst Res, College Pk, MD 20742 USA
[4] Univ Maryland, Dept Comp Sci, College Pk, MD 20742 USA
[5] Univ Maryland, Dept Elect & Comp Engn, College Pk, MD USA
关键词
Structured system; Structural resilience; Denial of service attack; Right unmatched vertex; Strongly connected component; Switched system; CONTROLLABILITY PROBLEM;
D O I
10.1016/j.ejcon.2021.09.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The resilience of cyberphysical systems to denial-of-service (DoS) and integrity attacks is studied in this paper. The cyberphysical system is modeled as a linear structured system, and its resilience to an attack is interpreted in a graph theoretical framework. The structural resilience of the system is characterized in terms of unmatched vertices in maximum matchings of the bipartite graph and connected components of directed graph representations of the system under attack. We first present conditions for the system to be resilient to DoS attacks when an adversary may block access or turn off certain inputs to the system. We extend this analysis to characterize resilience of the system when an adversary might additionally have the ability to affect the implementation of state-feedback control strategies. This is termed an integrity attack. We establish conditions under which a system that is structurally resilient to a DoS attack will also be resilient to a certain class of integrity attacks. Finally, we formulate an extension to the case of switched linear systems, and derive conditions for such systems to be structurally resilient to a DoS attack.(c) 2021 European Control Association. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:61 / 69
页数:9
相关论文
共 50 条
  • [41] An efficient filter for denial-of-service bandwidth attacks
    Abdelsayed, S
    Glimsholt, D
    Leckie, C
    Ryan, S
    Shami, S
    GLOBECOM'03: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-7, 2003, : 1353 - 1357
  • [42] On the Move: Evading Distributed Denial-of-Service Attacks
    Stavrou, Angelos
    Fleck, Daniel
    Kolias, Constantinos
    COMPUTER, 2016, 49 (03) : 104 - 107
  • [43] Safe and Secure Networked Control Systems under Denial-of-Service Attacks
    Amin, Saurabh
    Cardenas, Alvaro A.
    Sastry, S. Shankar
    HYBRID SYSTEMS: COMPUTATION AND CONTROL, 2009, 5469 : 31 - +
  • [44] Generator of Slow Denial-of-Service Cyber Attacks
    Sikora, Marek
    Fujdiak, Radek
    Kuchar, Karel
    Holasova, Eva
    Misurec, Jiri
    SENSORS, 2021, 21 (16)
  • [45] Estimates of success rates of Denial-of-Service attacks
    Sommestad, Teodor
    Holm, Hannes
    Ekstedt, Mathias
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 21 - 28
  • [46] Effectiveness and Detection of Denial-of-Service Attacks in Tor
    Danner, Norman
    Defabbia-Kane, Sam
    Krizanc, Danny
    Liberatore, Marc
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2012, 15 (03)
  • [47] Denial-of-Service Attacks in OpenFlow SDN Networks
    Kandoi, Rajat
    Antikainen, Markku
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1322 - 1326
  • [48] Detection of Denial-of-Service Attacks with SNMP/RMON
    Boyar, O.
    Ozen, M. E.
    Metin, B.
    2018 IEEE 22ND INTERNATIONAL CONFERENCE ON INTELLIGENT ENGINEERING SYSTEMS (INES 2018), 2018, : 437 - 440
  • [49] Denial-of-Service in Automation Systems
    Granzer, Wolfgang
    Reinisch, Christian
    Kastner, Wolfgang
    2008 IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, PROCEEDINGS, 2008, : 468 - 471
  • [50] A Counteracting Resilience Strategy for Denial-of-Service Scenarios in Networked Control Systems
    Famularo, D.
    IEEE ACCESS, 2024, 12 : 77336 - 77346