基于控制性能指标的重放攻击编码检测方案

Coding Detection Scheme for Replay Attack Based on the Control Performance Index

  • 摘要: 针对信息物理系统(cyber-physical systems,CPS)中重放攻击的检测问题,提出一种基于系统性能指标的量测噪声编码方案.首先对重放攻击进行简单描述;其次根据给定的系统性能变化范围计算可容许的最大测量噪声干扰,并将其加到传感器输出端对测量值进行编码,同时在滤波器端对测量值进行解码;采用渐消卡尔曼滤波算法对系统性能进行实时估计.正常情况下系统达到稳态时性能指标值也趋于固定值,当遭受重放攻击时,由于解码信息与编码过程不同步,导致系统遭受超过允许范围之内的量测噪声,并使系统性能指标超出给定范围.采用所提方案在正常情况下不会对系统性能造成影响,通过观察系统实时性能指标的变化可以有效地检测到重放攻击的发生.

     

    Abstract: To detect the replay attack in cyber-physical systems (CPS), we propose a measurement noise coding scheme based on a system performance index. Firstly, we briefly describe a replay attack. Secondly, we obtain the maximum allowable measurement noise disturbance within a given range of performance change, add it to sensors to encode measurements, and decode the measurements at the filter end. Finally, we use a fading Kalman filter to estimate the performance of the system in real time. Under normal circumstances of the performance change, the performance index becomes fixed after the system reaches stability. When a replay attack occurs, the decoding information and the encoding process are not synchronized. As a result, the system encounters additional measurement noise that exceeds the maximum allowable range. Consequently, the system performance index goes beyond the given range. With this scheme, no system performance scarification takes place in normal situations. At the same time, the occurrence of a replay attack can be effectively detected by observing the changes in the real-time control performance index of the system.

     

/

返回文章
返回