SAIN: Improving ICS Attack Detection Sensitivity via State-Aware Invariants
Syed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan, Z. Berkay Celik, Dongyan Xu
摘要
Industrial Control Systems (ICSs) rely on Programmable Logic Controllers (PLCs) to operate within a set of states. The states are composed of variables that determine how sensor data is interpreted, configuration parameters are applied, and actuator commands are issued. Recent works have shown that attackers can manipulate these variables to compromise ICS safety and security. To detect such attacks, previous approaches have leveraged invariants—a set of rules defining the correct behavior of an ICS. However, these invariants suffer from a critical limitation: they are state-agnostic. This means they define variable ranges across all possible ICS states, leading to loosely bounded detection thresholds. Unfortunately, attackers can exploit these loose bounds and launch stealthy attacks that evade detection without violating such invariants. In this paper, we introduce SAIN, an automated method to derive state-aware ICS invariants with tighter bounds and enforce them through a PLC-based monitor. SAIN first generates invariant templates by identifying the PLC program states, state transitions, and the inter-dependencies among sensing, actuation, and configuration variables within each state through program analysis. It then partitions the ICS data traces into state-specific sub-traces and quantifies the invariant templates with concrete, tighter bounds, as system-specific knowledge about the subject ICS. Lastly, it enforces the state-aware invariants through a run-time monitor. We evaluate SAIN on a Fischertechnik manufacturing plant and a chemical plant simulator against 17 attacks. SAIN protects the plants, on average, with a false positive rate of 2% and a run-time overhead of 3%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine RecoveryFangzhou Dong, Arvind S. Raj, Efrén López-Morales, Siyu Liu 等NDSS 2026 · 被引用 1 次
- Recovering Process Variables from Industrial Network Traffic via Search-Based OptimizationChuan Sheng, Shan Jiang, Jianming Zhao, Yu YaoCCS 2026
它引用的顶会 Paper7
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer 等CCS 2016 · 被引用 351 次
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 被引用 135 次
- Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control SystemsWissam Aoudi, Mikel Iturbe, Magnus AlmgrenCCS 2018 · 被引用 110 次
- Towards Automated Safety Vetting of PLC Code in Real-World PlantsMu Zhang, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane 等S&P 2019 · 被引用 64 次
- SoK: Security of Programmable Logic ControllersEfrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi 等USENIX Security 2024 · 被引用 10 次
相关 Paper
- Scaphy: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsicalMoses Ike, Kandy Phan, Keaton Sadoski, Romuald Valme 等S&P 2023
- CoToRu: Automatic Generation of Network Intrusion Detection Rules from CodeHeng Chuan Tan, Carmen Cheh, Binbin ChenINFOCOM 2022 · 被引用 12 次
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 被引用 90 次
- Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic EmanationsYi Han, Sriharsha Etigowni, Hua Liu, Saman A. Zonouz 等CCS 2017 · 被引用 110 次
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 被引用 135 次
