ARTINALI plus plus : Multi-dimensional Specification Mining for Complex Cyber-Physical System Security

被引:4
|
作者
Aliabadi, Maryam Raiyat [1 ]
Asl, Mojtaba Vahidi [1 ]
Ghavamizadeh, Ramak [1 ]
机构
[1] Shahid Beheshti Univ, Fac Comp Sci & Engn, Tehran, Iran
基金
加拿大自然科学与工程研究理事会;
关键词
Program analysis; Specification mining; Intrusion Detection Systems; Cyber-Physical Systems; Security; Safety; INTRUSION DETECTION; INVARIANTS;
D O I
10.1016/j.jss.2021.111016
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyber-Physical Systems (CPSes) have been investigated as a key area of research since they are the core of Internet of Things. CPSs integrate computing and communication with control and monitoring of entities in the physical world. Due to the tight coupling of cyber and physical domains, and to the possible catastrophic consequences of the malicious attacks on critical infrastructures, security is one of the key concerns. However, the exponential growth of IoT has led to deployment of CPSes without support for enforcing important security properties. Specification-based Intrusion Detection Systems (IDS) have been shown to be effective for securing these systems. Mining the specifications of CPSes by experts is a cumbersome and error-prone task. Therefore, it is essential to dynamically monitor the CPS to learn its common behaviors and formulate specifications for detecting malicious bugs and security attacks. Existing solutions for specification mining only combine data and events, but not time. However, time is a semantic property in CPS systems, and hence incorporating time in addition to data and events, is essential for obtaining high accuracy. This paper proposes ARTINALI++, which dynamically mines specifications in CPS systems with arbitrary size and complexity. ARTINALI++ captures the security properties by incorporating time as a substantial property of the system, and generate a multi-dimensional model for the general CPS systems. Moreover, it enhances the model through discovering invariants that represent the physical motions and distinct operational modes in complex CPS systems. We build Intrusion Detection Systems based on ARTINALI++ for three CPSes with various levels of complexity including smart meter, smart artificial pancreas and unmanned aerial vehicle, and measure their detection accuracy. We find that the ARTINALI++ significantly reduces the ratio of false positives and false negatives by 23.45% and 73.6% on average, respectively, over other dynamic specification mining tools on the three CPS platforms. (C) 2021 Elsevier Inc. All rights reserved.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] ARTINALI: Dynamic Invariant Detection for Cyber-Physical System Security
    Aliabadi, Maryam Raiyat
    Kamath, Amita Ajith
    Gascon-Samson, Julien
    Pattabiraman, Karthik
    ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 349 - 361
  • [2] Multi-Dimensional Analysis and Design Method for Aerospace Cyber-Physical Systems
    Zhang, Lichen
    2013 12TH INTERNATIONAL SYMPOSIUM ON DISTRIBUTED COMPUTING AND APPLICATIONS TO BUSINESS, ENGINEERING & SCIENCE (DCABES), 2013, : 197 - 201
  • [3] Reliability Assessment of Cyber-Physical Distribution System Using Multi-Dimensional Information Network Model
    He, Ruiwen
    Liang, Huiyu
    Wu, Jianshuang
    Xie, Haijun
    Shahidehpour, Mohammad
    IEEE TRANSACTIONS ON SMART GRID, 2023, 14 (06) : 4683 - 4692
  • [4] The Importance Of Security In Cyber-Physical System
    alrefaei, Faisal
    2020 IEEE 6TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2020,
  • [5] Security Analysis of Cyber-Physical System
    Li, Bo
    Zhang, Lichen
    MATERIALS SCIENCE, ENERGY TECHNOLOGY, AND POWER ENGINEERING I, 2017, 1839
  • [6] Boosting Cyber-Physical System Security
    Kutzler, Tobias
    Wolter, Alexandra
    Kenner, Andy
    Dassow, Stephan
    IFAC PAPERSONLINE, 2021, 54 (01): : 976 - 981
  • [7] Towards Heterogeneous Multi-Dimensional Variability Modeling in Cyber-Physical Production Systems
    Fadhlillah, Hafiyyan Sayyid
    Feichtinger, Kevin
    Sonnleithner, Lisa
    Rabiser, Rick
    Zoitl, Alois
    SPLC '21 - PROCEEDINGS OF THE 25TH ACM INTERNATIONAL SYSTEMS AND SOFTWARE PRODUCT LINE CONFERENCE, VOL B, 2021, : 123 - 129
  • [8] ICE plus plus : Improving Security, QoS, and High Availability of Medical Cyber-Physical Systems through Mobile Edge Computing
    Huertas Celdran, Alberto
    Garcia Clemente, Felix J.
    Weimer, James
    Lee, Insup
    2018 IEEE 20TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2018,
  • [9] Cyber-physical system homeostatic security management
    Zegzhda D.P.
    Pavlenko E.Y.
    Automatic Control and Computer Sciences, 2017, 51 (8) : 805 - 816
  • [10] Security of Autonomous Vehicle as a Cyber-Physical System
    Chattopadhyay, Anupam
    Lam, Kwok-Yan
    2017 7TH INTERNATIONAL SYMPOSIUM ON EMBEDDED COMPUTING AND SYSTEM DESIGN (ISED), 2017,