,NIPAD:a non-invasive power-based anomaly detection scheme for programmable logic controllers

来源 :信息与电子工程前沿(英文版) | 被引量 : 0次 | 上传用户:zhouyueying
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Industrial control systems (ICSs) are widely used in critical infrastructures, making them popular targets for attacks to cause catastrophic physical damage. As one of the most critical components in ICSs, the programmable logic controller (PLC) controls the actuators directly. A PLC executing a malicious program can cause significant property loss or even casualties. The number of attacks targeted at PLCs has increased noticeably over the last few years, exposing the vulnerability of the PLC and the importance of PLC protection. Unfortunately, PLCs cannot be protected by traditional intrusion detection systems or antivirus software. Thus, an effective method for PLC protection is yet to be designed. Motivated by these conces, we propose a non-invasive power-based anomaly detection scheme for PLCs. The basic idea is to detect malicious software execution in a PLC through analyzing its power consumption, which is measured by inserting a shunt resistor in series with the CPU in a PLC while it is executing instructions. To analyze the power measurements, we extract a discriminative feature set from the power trace, and then train a long short-term memory (LSTM) neural network with the features of normal samples to predict the next time step of a normal sample. Finally, an abnormal sample is identified through comparing the predicted sample and the actual sample. The advantages of our method are that it requires no software modification on the original system and is able to detect unknown attacks effectively. The method is evaluated on a lab testbed, and for a trojan attack whose difference from the normal program is around 0.63%, the detection accuracy reaches 99.83%.
其他文献
A new model for three-dimensional processes based on the trinion algebra is introduced for the fi rst time. Compared to the pure quateion model, the trinion mod
笔者有机会接触过河南省古籍地方文献整理的有关资料,现用工作之余,对河南古籍地方文献中部分“稿本地方文献”及“乡邦稀见书”予以评介.
The special characteristics of slowly moving infrared targets, such as containing only a few pixels,shapeless edge, low signal-to-clutter ratio, and low speed,
目的:评估HSD3B1基因1245位点突变在去势抵抗型前列腺癌(castration-resistant prostate cancer,CRPC)发生中的作用。方法:回顾性分析2004年1月~2011年1月在我院行睾丸切除术
该文对当前广东省生产上应用的21个籼型优质稻品种、品系的茎、叶、穗性状、茎叶解剖结构性状及部分生理指标等进行研究.
细胞质雄性不育三种杂种的选育是油菜杂种优势利用主要途径.目前,生产上得到大面积应用的油菜细胞质雄性不育类型主要有Pol CMS、陕2A CMS和MI CMS.对于前两者的研究较为
Cascaded regression has been recently applied to reconstruct 3D faces from single 2D images directly in shape space, and has achieved state-of-the-art performan
该文以热带种(Badila)为材料,利用茎尖和心叶愈伤组织培养进行脱毒研究.探讨茎尖离体微培养和快速繁殖技术,分析脱毒效果,考察脱毒苗的田间表现和遗传稳定性.初步结果如下:1.