Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control Systems
Wissam Aoudi, Mikel Iturbe, Magnus Almgren
Abstract
Recent incidents have shown that Industrial Control Systems (ICS) are becoming increasingly susceptible to sophisticated and targeted attacks initiated by adversaries with high motivation, domain knowledge, and resources. Although traditional security mechanisms can be implemented at the IT-infrastructure level of such cyber-physical systems, the community has acknowledged that it is imperative to also monitor the process-level activity, as attacks on ICS may very well in uence the physical process. In this paper, we present pasad, a novel stealthy-attack detection mechanism that monitors time series of sensor measurements in real time for structural changes in the process behavior. We demonstrate the e ectiveness of our approach through simulations and experiments on data from real systems. Experimental results show that pasad is capable of detecting not only signi cant deviations in the process behavior, but also subtle attack-indicating changes, signi cantly raising the bar for strategic adversaries who may attempt to maintain their malicious manipulation within the noise level.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez et al.CCS 2019 · 87 citations
- Active fuzzing for testing and securing cyber-physical systemsYuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun et al.ISSTA 2020 · 25 citations
- Code integrity attestation for PLCs using black box neural network predictionsYuqi Chen, Christopher M. Poskitt, Jun SunFSE 2021 · 16 citations
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan et al.USENIX Security 2024 · 9 citations
- Finding Causally Different Tests for an Industrial Control SystemChristopher M. Poskitt, Yuqi Chen, Jun Sun, Yu JiangICSE 2023 · 6 citations
Builds on1
Related papers
- Fail-Safe: Securing Cyber-Physical Systems against Hidden Sensor AttacksMengyu Liu, Lin Zhang, Pengyuan Lu, Kaustubh Sridhar et al.RTSS 2022 · 15 citations
- Hiding in Plain Sight? On the Efficacy of Power Side Channel-Based Control Flow MonitoringYi Han, Matthew Chan, Zahra Aref, Nils Ole Tippenhauer et al.USENIX Security 2022
- Query-Based Black-Box Stealthy Sensor Attacks on Cyber-Physical SystemsShixiong Jiang, Weizhe Xu, Mengyu Liu, Fanxin KongDAC 2025
- Scaphy: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsicalMoses Ike, Kandy Phan, Keaton Sadoski, Romuald Valme et al.S&P 2023
- Catch You if Pay Attention: Temporal Sensor Attack Diagnosis Using Attention Mechanisms for Cyber-Physical SystemsZifan Wang, Lin Zhang, Qinru Qiu, Fanxin KongRTSS 2023 · 9 citations
