• DocumentCode
    28350
  • Title

    Detection of Integrity Attacks in Cyber-Physical Critical Infrastructures Using Ensemble Modeling

  • Author

    Ntalampiras, Stavros

  • Author_Institution
    Joint Res. Center, Eur. Comm., Varese, Italy
  • Volume
    11
  • Issue
    1
  • fYear
    2015
  • fDate
    Feb. 2015
  • Firstpage
    104
  • Lastpage
    111
  • Abstract
    This paper presents an anomaly-based methodology for reliable detection of integrity attacks in cyber-physical critical infrastructures. Such malicious events compromise the smooth operation of the infrastructure while the attacker is able to exploit the respective resources according to his/her purposes. Even though the operator may not understand the attack, since the overall system appears to remain in a steady state, the consequences may be of catastrophic nature with a huge negative impact. Here, we apply a computational intelligent technique which incorporates the merits of two of the heterogeneous modeling approaches (linear time-invariant and neural networks), while considering both temporal and functional dependencies existing among the elements of an infrastructure. The experimental platform includes a power grid simulator of the IEEE 30 bus model and a cyber network emulator. Subsequently, we implemented a wide range of integrity attacks (replay, ramp, pulse, scaling, and random) with different intensity levels. A thorough evaluation procedure is carried out while the results demonstrate the ability of the proposed method to produce a desired result in terms of false positive rate, false negative rate, and detection delay.
  • Keywords
    computer network security; fault diagnosis; neural nets; power grids; power system faults; power system security; power system simulation; IEEE 30 bus model; anomaly-based methodology; computational intelligent technique; cyber network emulator; cyber-physical critical infrastructures; detection delay; ensemble modeling; false positive rate; fault diagnosis; functional dependencies; heterogeneous modeling approach; integrity attack detection; intensity levels; linear time-invariant; malicious events; neural networks; power grid simulator; pulse attack; ramp attack; random attack; replay attack; scaling attack; temporal dependencies; Computational modeling; Estimation; Informatics; Mathematical model; Predictive models; Redundancy; Reservoirs; Cyber-physical critical infrastructures (CIs); Ensemble modeling; cyberphysical critical infrastructures; ensemble modeling; fault diagnosis;
  • fLanguage
    English
  • Journal_Title
    Industrial Informatics, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1551-3203
  • Type

    jour

  • DOI
    10.1109/TII.2014.2367322
  • Filename
    6948272