• DocumentCode
    183915
  • Title

    A statistical method for detecting cyber/physical attacks on SCADA systems

  • Author

    Do, Van Long ; Fillatre, Lionel ; Nikiforov, Igor

  • Author_Institution
    UTT/ICD/LM2S, Univ. of Technol. of Troyes, Troyes, France
  • fYear
    2014
  • fDate
    8-10 Oct. 2014
  • Firstpage
    364
  • Lastpage
    369
  • Abstract
    This paper addresses the problem of detecting cyber/physical attacks on Supervisory Control And Data Acquisition (SCADA) systems. The detection of cyber/physical attacks is formulated as the problem of detecting transient changes in stochastic-dynamical systems in the presence of unknown system states (often regarded as the nuisance parameter). The Variable Threshold Window Limited CUmulative SUM (VTWL CUSUM) test is adapted to the detection of transient changes of known profiles in the presence of nuisance parameter. Taking into account the performance criterion of the transient change detection problem, which minimizes the worst-case probability of missed detection for a given value of the worst-case probability of false alarm, the thresholds are tuned for optimizing the VTWL CUSUM algorithm. The optimal choice of thresholds leads to the simple Finite Moving Average (FMA) algorithm. The proposed algorithms are utilized for detecting the covert attack on a simple water distribution system, targeting at stealing water from the reservoir without being detected.
  • Keywords
    SCADA systems; fault diagnosis; moving average processes; probability; security of data; statistical analysis; stochastic systems; transient response; FMA algorithm; SCADA systems; VTWL CUSUM algorithm; VTWL CUSUM test; cyber-physical attack detection; finite moving average algorithm; nuisance parameter; reservoir water stealing; statistical method; stochastic-dynamical systems; supervisory control and data acquisition systems; transient change detection problem; variable threshold window limited cumulative sum test; water distribution system; worst-case probability; Pressure measurement; Reservoirs; SCADA systems; Time measurement; Transient analysis; Vectors; SCADA systems; cyber attacks; fault diagnosis; transient change detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Control Applications (CCA), 2014 IEEE Conference on
  • Conference_Location
    Juan Les Antibes
  • Type

    conf

  • DOI
    10.1109/CCA.2014.6981373
  • Filename
    6981373