Visible to the public Distributed Detection of Single-Stage Multipoint Cyber Attacks in a Water Treatment Plant

TitleDistributed Detection of Single-Stage Multipoint Cyber Attacks in a Water Treatment Plant
Publication TypeConference Paper
Year of Publication2016
AuthorsAdepu, Sridhar, Mathur, Aditya
Conference NameProceedings of the 11th ACM on Asia Conference on Computer and Communications Security
Date PublishedMay 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4233-9
Keywordsactuator security, composability, compositionality, Cyber Attacks, cyber physical systems, cyber security, distributed detection, Human Behavior, invariants, Metrics, pubcrawl, Resiliency, SCADA, SCADA Systems Security, security by design, water treatment
Abstract

A distributed detection method is proposed to detect single stage multi-point (SSMP) attacks on a Cyber Physical System (CPS). Such attacks aim at compromising two or more sensors or actuators at any one stage of a CPS and could totally compromise a controller and prevent it from detecting the attack. However, as demonstrated in this work, using the flow properties of water from one stage to the other, a neighboring controller was found effective in detecting such attacks. The method is based on physical invariants derived for each stage of the CPS from its design. The attack detection effectiveness of the method was evaluated experimentally against an operational water treatment testbed containing 42 sensors and actuators. Results from the experiments point to high effectiveness of the method in detecting a variety of SSMP attacks but also point to its limitations. Distributing the attack detection code among various controllers adds to the scalability of the proposed method.

URLhttps://dl.acm.org/doi/10.1145/2897845.2897855
DOI10.1145/2897845.2897855
Citation Keyadepu_distributed_2016