{"title":"检测网络物理攻击的顺序测试灵敏度分析","authors":"Van Long Do, L. Fillatre, I. Nikiforov","doi":"10.1109/EUSIPCO.2015.7362787","DOIUrl":null,"url":null,"abstract":"This paper deals with the problem of detecting cyber-physical attacks on Supervisory Control And Data Acquisition (SCADA) systems. The discrete-time state space model is used to describe the systems. The attacks are modeled as additive signals of short duration on both state evolution and sensor measurement equations. The steady-state Kalman filter is employed to generate the sequence of innovations. Next, these independent random variables are used as entries of the Variable Threshold Window Limited CUmulative SUM (VTWL CUSUM) test. It has been shown that the optimal choice of thresholds with respect to (w.r.t.) the transient change detection criterion leads to the Finite Moving Average (FMA) test. The main contribution of this paper is a sensitivity analysis of the FMA test. This analysis is based on a numerical calculation of the probabilities of wrong decision under the variation of operational parameters. Theoretical results are applied to the detection of an attack scenario on a SCADA water network.","PeriodicalId":401040,"journal":{"name":"2015 23rd European Signal Processing Conference (EUSIPCO)","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-12-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Sensitivity analysis of the sequential test for detecting cyber-physical attacks\",\"authors\":\"Van Long Do, L. Fillatre, I. Nikiforov\",\"doi\":\"10.1109/EUSIPCO.2015.7362787\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper deals with the problem of detecting cyber-physical attacks on Supervisory Control And Data Acquisition (SCADA) systems. The discrete-time state space model is used to describe the systems. The attacks are modeled as additive signals of short duration on both state evolution and sensor measurement equations. The steady-state Kalman filter is employed to generate the sequence of innovations. Next, these independent random variables are used as entries of the Variable Threshold Window Limited CUmulative SUM (VTWL CUSUM) test. It has been shown that the optimal choice of thresholds with respect to (w.r.t.) the transient change detection criterion leads to the Finite Moving Average (FMA) test. The main contribution of this paper is a sensitivity analysis of the FMA test. This analysis is based on a numerical calculation of the probabilities of wrong decision under the variation of operational parameters. Theoretical results are applied to the detection of an attack scenario on a SCADA water network.\",\"PeriodicalId\":401040,\"journal\":{\"name\":\"2015 23rd European Signal Processing Conference (EUSIPCO)\",\"volume\":\"45 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-12-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 23rd European Signal Processing Conference (EUSIPCO)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EUSIPCO.2015.7362787\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 23rd European Signal Processing Conference (EUSIPCO)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EUSIPCO.2015.7362787","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Sensitivity analysis of the sequential test for detecting cyber-physical attacks
This paper deals with the problem of detecting cyber-physical attacks on Supervisory Control And Data Acquisition (SCADA) systems. The discrete-time state space model is used to describe the systems. The attacks are modeled as additive signals of short duration on both state evolution and sensor measurement equations. The steady-state Kalman filter is employed to generate the sequence of innovations. Next, these independent random variables are used as entries of the Variable Threshold Window Limited CUmulative SUM (VTWL CUSUM) test. It has been shown that the optimal choice of thresholds with respect to (w.r.t.) the transient change detection criterion leads to the Finite Moving Average (FMA) test. The main contribution of this paper is a sensitivity analysis of the FMA test. This analysis is based on a numerical calculation of the probabilities of wrong decision under the variation of operational parameters. Theoretical results are applied to the detection of an attack scenario on a SCADA water network.