Return
A method for testing distributed anomaly detectors
DOI:10.1016/j.ijcip.2019.100324.png)
Abstract
En 中文
Distributed anomaly detectors are deployed in critical infrastructure to raise alerts when the underlying plant deviates from its expected behaviour. A novel method, referred to as SCM, that uses well defined state and command mutation operators, is proposed to test such detectors prior to their deployment. Cyber-attacks, each modelled as a timed-automaton, serve as reference attacks. A potentially large set of attacks is then created by systematically applying the mutation operators to each reference attack. In a case study, SCM was applied to a timed-automata model of a water treatment plant to assess its effectiveness in testing a distributed anomaly detector. Results attest to the value of SCM in identifying weaknesses in an anomaly detector, prior to its deployment, and improving its effectiveness in detecting process anomalies. (C) 2019 Elsevier B.V. All rights reserved.
Keywords:
Attack model
Distributed anomaly detector
Critical infrastructure
Cyber-attacks
Cyber-physical systems
Industrial control systems
Testing
Timed-automata
Water treatment plant
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
5.3
Papers:
618
Citations:
1.3K

