Deep Reinforcement Learning for Penetration Testing of Cyber-Physical Attacks in the Smart Grid

被引:0
|
作者
Li, Yuanliang [1 ,2 ]
Yan, Jun [1 ]
Naili, Mohamed [2 ]
机构
[1] Concordia Univ, Concordia Inst Informat Syst Engn CIISE, Montreal, PQ, Canada
[2] Ericsson, Global Artificial Intelligence Accelerator GAIA, Montreal, PQ, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Cyber-physical security; penetration testing; smart grid; deep reinforcement learning;
D O I
10.1109/IJCNN55064.2022.9892584
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The fast expansion of interconnectivity in cyberphysical critical infrastructures like smart grids has given rise to concerning exposures and vulnerabilities. Although penetration testing (PT) has been an effective approach to searching for vulnerabilities in software, devices, and networks from the attacker's view, the strong cyber-physical coupling in these large-scale infrastructures has made it challenging to manually pinpoint critical vulnerabilities, particularly at system levels due to the complexity, dimensionality, and uncertainty therein. To better protect the security of cyber-physical systems, this paper proposes a deep reinforcement learning (DRL)-based PT framework to efficiently and adaptively identify critical vulnerabilities in smart grids. Using replay attacks as an example, the paper models the attack as a Markov Decision Process with three actions - stop, record, and replay - to learn the optimal timing and ordering of replays in different operating scenarios. A cyber-physical cosimulation platform with dedicated simulators for the physical part, cyber part, control part, and attacker part of a smart distribution grid was developed as a sandbox environment to train the DRL agent. Scenarios with different levels of difficulty are tested to validate the learning capability and performance in finding critical attack paths of the DRL-based PT. The simulation results show that DRL-based PT can learn to find the optimal attack path against system stability when the grid is under high load demand, solar power generation, and weather variation. These results are promising first steps toward a highly customizable framework to pen-test complex cyber-physical systems with automatic DRL agents and various attack schemes.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] A Double-Benefit Moving Target Defense Against Cyber-Physical Attacks in Smart Grid
    Zhang, Zhenyong
    Tian, Youliang
    Deng, Ruilong
    Ma, Jianfeng
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (18) : 17912 - 17925
  • [42] Cyber-physical perspective on smart grid design and operation
    Chen, Bo
    Wang, Jianhui
    Shahidehpour, Mohammad
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2018, 3 (03) : 129 - 141
  • [43] Determining Asset Criticality in Cyber-Physical Smart Grid
    Alrowaili, Yazeed
    Saxena, Neetesh
    Burnap, Pete
    COMPUTER SECURITY - ESORICS 2021, PT II, 2021, 12973 : 770 - 776
  • [44] A Bayesian Deep Learning Approach With Convolutional Feature Engineering to Discriminate Cyber-Physical Intrusions in Smart Grid Systems
    Kaur, Devinder
    Anwar, Adnan
    Kamwa, Innocent
    Islam, Shama
    Muyeen, S. M.
    Hosseinzadeh, Nasser
    IEEE ACCESS, 2023, 11 : 18910 - 18920
  • [45] Adaptive workload adjustment for cyber-physical systems using deep reinforcement learning
    Xu, Shikang
    Koren, Israel
    Krishna, C. Mani
    SUSTAINABLE COMPUTING-INFORMATICS & SYSTEMS, 2021, 30
  • [46] Coordinated cyber-physical attacks of cyber-physical power system
    Yang Y.
    Lan S.
    Qin Z.
    Liu H.
    Dianli Zidonghua Shebei/Electric Power Automation Equipment, 2020, 40 (02): : 97 - 102
  • [47] Statistical machine learning defensive mechanism against cyber intrusion in smart grid cyber-physical network
    Singh, Neeraj Kumar
    Majeed, Mahshooq Abdul
    Mahajan, Vasundhara
    COMPUTERS & SECURITY, 2022, 123
  • [48] Assessing the Severity of Smart Attacks in Industrial Cyber-Physical Systems
    Khaled, Abdelaziz
    Ouchani, Samir
    Tari, Zahir
    Drira, Khalil
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2021, 5 (01)
  • [49] Securing Smart Grids: Deep Reinforcement Learning Approach for Detecting Cyber-Attacks
    El-Toukhy, Ahmed T.
    Elgarhy, Islam
    Badr, Mahmoud M.
    Mahmoud, Mohamed
    Fouda, Mostafa M.
    Ibrahem, Mohamed I.
    Amsaad, Fathi
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [50] Learning-based attacks in cyber-physical systems
    Khojasteh, Mohammad Javad
    Khina, Anatoly
    Franceschetti, Massimo
    Javidi, Tara
    IEEE Transactions on Control of Network Systems, 2021, 8 (01): : 437 - 449