A replay attack detection method for information-physical industrial control systems

By establishing a model in the cyber-physical industrial control system and using the equivalent space method to generate detection residuals, quantifying residual changes, and combining passive and active methods, the problem of replay attack detection was solved, achieving accurate detection and differentiation of faults.

CN116820071BActive Publication Date: 2025-12-05BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310801468.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-03
Publication Date
2025-12-05
Estimated Expiration
2043-07-03

AI Technical Summary

Technical Problem

Existing replay attack detection methods in cyber-physical industrial control systems have several drawbacks: they are powerful but require sacrificing control performance, necessitate additional system modifications, struggle to distinguish between attacks and malfunctions, and fail to effectively handle simultaneous replay of inputs and outputs.

Method used

A cyber-physical industrial control system model is established, and the detection residual is generated using the equivalent space method. The residual changes under replay attacks are quantified, and four passive methods for optimal equivalent matrices are established. Based on the passive methods, an active method based on attack event triggering is established, and statistical quantities and detection thresholds and alarm strategies are selected.

Benefits of technology

It achieves accurate detection of replay attacks, distinguishes between faults and attacks, maintains control performance, and has a wide detection range without modifying the system structure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116820071B_ABST
    Figure CN116820071B_ABST
Patent Text Reader

Abstract

The application discloses a replay attack detection method of an information physical industrial control system, and comprises the following contents: an information physical industrial control system model is established; industrial control system input and output data are collected, and an equivalent space method is used to generate detection residual error; the residual error change under attack is quantitatively analyzed; based on the residual error quantitative analysis, four kinds of passive optimal equivalent matrix design methods are given to improve the detection performance; on the basis of passive design, a kind of attack event triggered active design scheme is further given to improve the detection performance; a statistical quantity is selected, a detection threshold and an alarm strategy are set, and detection is completed. The replay attack detection method can accurately detect the replay attack on the information physical industrial control system, and has the advantages of keeping the system control performance, being easy to implement, being capable of distinguishing faults and attacks and the like.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of industrial cyber-physical systems, and particularly relates to a replay attack detection method for an information-physical industrial control system. BACKGROUND

[0002] Cyber-physical systems integrate sensing, computing, communication and control into physical systems, and provide an effective framework for information services, control and real-time perception of complex systems. In recent years, it has been widely applied in the fields of water and electricity, transportation and industrial control. The control system has been greatly transformed and developed in the information-physical framework, but at the same time, it has also caused the vulnerability of network security risks and network attacks. Network attacks on control systems are generally divided into leakage attacks, deception attacks and destruction attacks. Replay attack is a typical deception attack, and its implementation does not depend on the model information of the control system. It can make the control performance deteriorate fatally under the condition of keeping hidden. Therefore, under the strong demand of network security against replay attacks, replay attack detection has become a key technology.

[0003] Most of the detection of replay attacks adopts watermarking method, moving target method and end-to-end encryption. The watermarking method adds authentication noise signals to the system control signals to resist replay attacks. The moving target method adds additional system dynamics, including additional control channels, sensing channels and system states, and introduces time-varying elements unrelated to attackers to detect replay attacks. The end-to-end encryption method based on encryption algorithm is the most commonly used method to ensure data security in communication.

[0004] The existing detection methods are powerful, but need to sacrifice control performance to different degrees, additional modification of the physical architecture of the industrial system, additional investment in intelligent field sensing and execution devices, and the method is difficult to be actually implemented. At the same time, the existing methods do not consider the case of simultaneous input and output replay, and it is difficult to distinguish attacks from faults. Therefore, there is an urgent need for a new detection method to comprehensively solve the problems existing in the existing scheme. SUMMARY

[0005] In order to solve the above problems, the application provides a replay attack detection method for an information-physical industrial control system, which can effectively solve the problems of certain limitations and non-widespread application range of the existing methods.

[0006] To achieve the above purpose, the technical scheme adopted by the application is: a replay attack detection method for an information-physical industrial control system, comprising the steps of:

[0007] S100: establishing a model of an information-physical industrial control system, establishing a state space equation expression, and establishing a description of a replay attack process;

[0008] S200: Collecting control system input and output data, generating detection residual based on information physical industrial control system model using equivalent space method;

[0009] S300: Quantitative analysis of residual change caused by replay attack, including input and output replay and only output replay;

[0010] S400: Based on the results of quantitative analysis of residual, establishing passive method of four optimal equivalent matrices;

[0011] S500: On the basis of passive method, establishing active method based on attack event trigger;

[0012] S600: Selecting statistical quantity, setting detection threshold and alarm strategy, and completing detection.

[0013] Further, in the step S100, an information physical industrial control system model is established, a state space equation expression is established, and a replay attack process description is established, including the steps of:

[0014] S110: Establishing a linear time-invariant information physical industrial control system model with noise:

[0015]

[0016] Wherein, x(k) represents the system state, u(k) represents the system input, y(k) represents the measured output; w(k) and v(k) represent process noise and measurement noise respectively, which are independent of each other and are zero-mean Gaussian white noise, satisfying:

[0017] cov{[w T (k) v T (k)] T}=diag{Q,R}

[0018] Wherein, Q>0, R>0 are known covariance matrices, diag{Q,R} is a block diagonal matrix composed of Q and R; A, B u ,B w ,C are known matrices with preset dimensions;

[0019] S120: Establishing a replay attack process description: in the information physical industrial control system, the controller and the detector are respectively configured to ensure the control performance of the system and the ability of the detector to detect abnormalities, and the control signal and the measurement signal are transmitted through the network;

[0020] In the absence of attack and fault, the signal transmission in the system satisfies:

[0021]

[0022] y is the system output, let y c represents the system output received by the controller, y d represents the system output received by the detector; u is the system input, let u c represents the controller output, u d represents the control signal received by the detector.

[0023] Further, the replay attack process includes the steps of:

[0024] S121: the attacker records the sensor output and / or the control input in the time range [t r1 ,t r2 ] by eavesdropping attack, and t r1 ,t r2 is a long enough time interval;

[0025] S122: when k≥T0, k represents the system running time, T0 represents the attack starting time, the attacker uses the recorded data to replace the sensor output y c (k)=y d (k)=y(τ k ), τ k represents the past system running time recorded by the attacker, wherein t r1 ≤τ k <<t r2 and T0>>t r2 ; a malicious signal u a (k) is added to the system input to destroy the system performance, u(k)=u c (k)+u a (k); the recorded data is used to replace the control signal input of the detector, u d (k)=u(τ k ).

[0026] Further, in the step S200, the control system input and output data are collected, the detection residual is generated based on the information physical industrial control system model using the equivalent space method, including the steps of:

[0027] S210: when k>s, k represents the system running time, and s represents the order of the equivalence relation, the matrix Y s (k), U s (k), W s (k) and V s (k) are generated using s consecutive system data, which are the system measurement output, the system input, the process noise and the measurement noise represented by the equivalent space method, respectively;

[0028] Y s(k) = col {y(k-s), y(k-s+1),..., y(k)} ;

[0029] U s (k) = col {u(k-s), u(k-s+1),..., u(k)} ;

[0030] W s (k) = col {w(k-s), w(k-s+1),..., w(k)} ;

[0031] V s (k) = col {v(k-s), v(k-s+1),..., v(k)} ;

[0032] where col denotes the column vector composed of multiple vectors, i.e. for vectors a and b, col {a, b} = [a T b T ] T ;

[0033] S220: The equivalent relation representation of the system can be obtained:

[0034] Y s (k) = H 0,s x(k-s) + H u,s U s (k) + E s (k) ;

[0035] E s (k) is a composite noise matrix composed of process noise and measurement noise, E s (k) = H w,s W s (k) + H v,s V(k), H u,s , H 0,s , H v,s and H w,s are the corresponding equivalent relation model coefficient matrices generated by the control system model coefficient matrix;

[0036] S230: Define the residual generated based on the equivalent space method:

[0037] r s (k) = Z s (Y s (k) - H u,s U s (k)) ;

[0038] where Z s is the equivalent matrix, the ith row of Z s z s,i is generated from the equivalent space is introduced; further derive r s (k) = Z s E s (k) ~ N(0, Θ s ), N represents Gaussian distribution, Θ s is the covariance matrix of the residual error.

[0039] Further, in the step S300, the residual error change caused by the quantitative analysis of the replay attack, including the residual error change in the input and output replay and only output replay, includes the steps:

[0040] When k ≥ T0, k represents the system running time, T0 represents the attack starting time, the sensor output is replaced by the historical data recorded by the attacker, y c (k) = y d (k) = y(τ k ), τ k represents the past system running time recorded by the attacker, wherein t r1 ≤ τ k << t r2 and T0 > > t r2 ; the control signal is replaced by the historical data recorded by the attacker, u d (k) = u(τ k );

[0041] Use α to represent the number of steps of data replacement; α = 0 represents normal system operation, α > s represents that the data of the system equivalence relation is completely replayed, 0 < α ≤ s represents that the data of the system equivalence relation is partially replayed; Y s α (k, τ k ) and are the measured output of the system under the replay attack and the system input respectively;

[0042] S310: In the case of input and output replay, the equivalence relation of the system is represented as:

[0043]

[0044] Wherein, represents: the system input under α-step replay attack, represents: the influence of α-step replay attack on the equivalence relation representation;

[0045] The residual error under the replay attack is:

[0046]

[0047] Wherein, Y s α (k, τ krepresents: the measurement output under the alpha-step replay attack;

[0048] In the case of alpha > s, that is, complete replay of data, the replay attack has little effect on the residual, so the case of partial data replay is mainly considered; in the case of partial data replay, the expectation of the residual is obtained:

[0049] ε{r s α (k)} = 0, and epsilon represents the expectation of a variable;

[0050] And the covariance matrix:

[0051]

[0052] Wherein, represents the covariance matrix of r s α (k): cov represents the covariance or covariance matrix of a variable;

[0053] S320: Only replay system output case: the system controller is implemented by {A c ,B c ,C c ,D c}, and the state of the controller is , then the residual generated based on the equivalent space method under the replay attack is represented as:

[0054]

[0055] And the covariance matrix is:

[0056] Further, in the step S400, based on the residual quantization analysis result, a passive method for establishing four kinds of optimal equivalent matrix is established, including the steps of:

[0057] Parameterize the equivalent matrix as Z s =M s N s ; wherein, N s is a non-zero equivalent matrix, so that N s H 0,s = 0, and M s is a non-zero weight matrix to be optimized;

[0058] S410: Positive definite partial optimization:

[0059] Select optimization index:

[0060] Wherein, ||X|| i represents the i-norm of X, and The unit weight equivalent space matrix comprehensive quantity under the condition of no attack and the unit weight equivalent space matrix comprehensive quantity under the condition of attack, respectively.

[0061]

[0062] The positive definite part of the residual covariance variation quantity under the condition of input replay; The difference between the positive definite part of the residual covariance variation quantity under the condition of input replay and the positive definite part of the residual covariance variation quantity under the condition of no input replay;

[0063]

[0064] Q s and R s are the system noise covariance and the measurement noise covariance under the equivalent space representation, respectively.

[0065]

[0066] I s+1 is an s+1-dimensional unit matrix;

[0067] SVD decomposition is performed on :

[0068] U is the left singular matrix of , V is the right singular matrix of , and Λ is the singular value matrix of ;

[0069] The solution of the optimization problem and the maximum value thereof are:

[0070] M s = Λ -1 U T ;

[0071]

[0072] S420: Trace ratio optimization:

[0073] An optimization index is selected:

[0074] wherein tr represents the trace of a matrix, is the inverse of the residual covariance matrix when the system is normally running, Δ α is the variation of the residual covariance matrix under the condition of no attack and the condition of attack, i.e.

[0075] T Δ,Σ is the cumulative sum of the unit weight equivalent space matrix comprehensive quantity under the condition of α-step replay attack, α = 1,..., s;

[0076]

[0077]

[0078] in: This represents the change in residual covariance under the condition of input replay. The difference in the change of residual covariance with and without input playback;

[0079] Optimization problem The solutions and their maximum values ​​are:

[0080]

[0081] Among them, M s,l and λ i yes The i-th largest generalized eigenvector and its corresponding eigenvalue;

[0082] S430: Cumulative Sum Ratio Optimization:

[0083] Select optimization metrics:

[0084] Optimization problem The equivalent matrix solutions and their maximum values ​​are as follows: Maximum generalized eigenvector and its eigenvalue λ;

[0085] S440: Detection rate optimization:

[0086] Select optimization metrics:

[0087] Given a false positive rate γ, the optimization problem can be described as follows:

[0088] The solutions to the optimization problem and their maximum values ​​are:

[0089]

[0090]

[0091] Among them, a i ≠0, diag{a1,…a l} is composed of a i The diagonal matrix formed; p and λ are The largest generalized eigenvalue and the corresponding eigenvector;

[0092] S50: Unified solution form:

[0093] Optimization problem The solution always has the following form:

[0094]

[0095] Λ -1 U T T Δ,Σ Λ -1 corresponding to the largest eigenvalue of Λ ;

[0096] Further, M s = Λ -1 U T is the unified solution of the optimization problem.

[0097] Further, in the step S500, on the basis of the passive method, an active method based on attack event triggering is established, including the steps of:

[0098] A critically stable filter is cascaded at the system output:

[0099] ζ(k+1) = A ζ ζ(k) + B ζ y(k+1)

[0100] where ζ(k) is the filter state, A ζ and B ζ are filter matrices; ζ(k) is used instead of y(k) to send to the monitor and control end, and y(k) is restored from ζ(k);

[0101] The overall dynamics of the monitor are:

[0102]

[0103]

[0104] where, is the new system dynamics, u(k) is the system input, w(k) is the measurement noise, v(k+1) is the system noise, A, B u , B w , C are control system model parameters, and I is a unit matrix with appropriate dimensions.

[0105] Further, in the step S600, statistical quantities are selected, detection thresholds and alarm strategies are set, and detection is completed, including the steps of: based on residual covariance quantization analysis caused by a replay attack, detection quantities are selected, detection thresholds and alarm strategies are set, and replay attack detection is realized; including χ 2 detection and likelihood ratio detection.

[0106] Further, the χ 2 detection:

[0107] Define the detection statistic:

[0108] where r s (k) is the residual generated based on the equivalent space method, Θ s is the residual covariance when the system is running normally, χ 2 (l) is the chi-square distribution with l degrees of freedom; given the false alarm rate γ, the detection threshold is obtained according to χ 2 When the statistic is less than the threshold, it indicates that no attack has occurred, and when the statistic is greater than the threshold, it indicates that a replay attack has occurred.

[0109] Further, the likelihood ratio detection:

[0110] The statistic generated by the generalized likelihood function is defined as:

[0111]

[0112] where, is the residual covariance when the system is running is the maximum likelihood estimate of r n is the number of observations, r s (k-i) is the system residual at time k-i;

[0113]

[0114] The threshold J of the likelihood ratio detection th,LR is learned through stochastic analysis given the false alarm rate γ, when the statistic is less than the threshold J th,LR , it indicates that no attack has occurred, and when the statistic is greater than the threshold J th,LR , it indicates that a replay attack has occurred, achieving detection of attacks.

[0115] The beneficial effects of using the technical solution are:

[0116] ​This invention targets cyber-physical industrial control systems, considering system noise and replay attacks. It establishes a linear time-invariant state-space model of the control system; collects input-output data of the industrial control system and generates detection residuals using the equivalent space method; considers the characteristics of replay attacks and quantitatively analyzes the residual changes under the attack; based on the residual quantification analysis, it proposes four passive optimal equivalent matrix design methods to improve detection performance; building upon the passive design, it further proposes an active design scheme triggered by attack events to further improve detection performance; and selects statistical quantities, sets detection thresholds and alarm strategies to complete the detection. The proposed replay attack detection method based on the equivalent space method can accurately detect replay attacks against cyber-physical industrial control systems, while maintaining system control performance, being easy to implement, and distinguishing between faults and attacks.

[0117] The replay attack detection method for cyber-physical systems based on the equivalence space method proposed in this invention can capture the replay attack effect on the residuals without any device-side modifications, quantify the impact of the replay attack on the residuals, and then, based on χ², respectively... 2 The method employs likelihood ratio test statistics for detection and performance analysis. Furthermore, it proposes passive and active detection designs to amplify the impact of replay attacks. Compared to existing methods, the replay attack detection method proposed above can handle input / output data replay, distinguish between system faults and replay attacks, maintain control performance, and is convenient, effective, and widely applicable. Attached Figure Description

[0118] Figure 1 This is a schematic flowchart of a replay attack detection method for a cyber-physical industrial control system according to the present invention.

[0119] Figure 2 This is a schematic diagram illustrating the experimental results of replay attack detection rate in an embodiment of the present invention;

[0120] Figure 3 This is a schematic diagram illustrating the experimental results of the detection rate of replay attacks using an actively designed approach in an embodiment of the present invention. Detailed Implementation

[0121] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described below with reference to the accompanying drawings.

[0122] In this embodiment, see Figure 1 As shown, this invention proposes a method for detecting replay attacks on cyber-physical industrial control systems, comprising the following steps:

[0123] S100: Establish a cyber-physical industrial control system model, establish a state-space equation expression, and establish a description of the replay attack process;

[0124] S200: Collecting control system input and output data, generating detection residual based on information physical industrial control system model using equivalent space method;

[0125] S300: Quantitative analysis of residual change caused by replay attack, including input and output replay and only output replay;

[0126] S400: Based on the results of quantitative analysis of residual, establishing passive method of four optimal equivalent matrices;

[0127] S500: On the basis of passive method, establishing active method based on attack event trigger;

[0128] S600: Selecting statistical quantity, setting detection threshold and alarm strategy, and completing detection.

[0129] As an optimization scheme of the above embodiment, in the step S100, the information physical industrial control system model is established, the state space equation expression is established, and the replay attack process description is established, including the steps of:

[0130] S110: Establishing a linear time-invariant information physical industrial control system model with noise:

[0131]

[0132] Wherein, x(k) represents the system state, u(k) represents the system input, y(k) represents the measured output; w(k) and v(k) represent process noise and measurement noise respectively, which are independent of each other and are zero-mean Gaussian white noise, satisfying:

[0133] cov{[w T (k) v T (k)] T}=diag{Q,R}

[0134] Wherein, Q>0, R>0 are known covariance matrices, diag{Q,R} is a block diagonal matrix composed of Q and R; A, B u ,B w ,C are known matrices with a predetermined dimension;

[0135] S120: Establishing replay attack process description: in the information physical industrial control system, the controller and the detector are respectively configured to ensure the control performance of the system and the ability of detecting abnormality, and the control signal and the measurement signal are transmitted through the network;

[0136] In the absence of attack and fault, the signal transmission in the system satisfies:

[0137]

[0138] y is the system output, let y c represent the system output received by the controller, y d represent the system output received by the detector; u is the system input, let u c represent the controller output, u d represent the control signal received by the detector.

[0139] As an optimization of the above embodiment, the replay attack process comprises the steps of:

[0140] S121: the attacker records the sensor output and / or the control input in the time range [t r1 ,t r2 ] by eavesdropping attack, and t r1 ,t r2 is a time interval long enough;

[0141] S122: when k≥T0, k represents the system running time, T0 represents the attack starting time, the attacker uses the recorded data to replace the sensor output y c (k) = y d (k) = y(τ k ), τ k represents the past system running time recorded by the attacker, wherein t r1 ≤τ k <<t r2 and T0>>t r2 ; a malicious signal u a (k) is added to the system input to destroy the system performance, u(k) = u c (k) + u a (k); the recorded data is used to replace the control signal input of the detector, u d (k) = u(τ k ).

[0142] As an optimization of the above embodiment, in the step S200, the control system input and output data are collected, the detection residual is generated based on the information physical industrial control system model using the equivalent space method, comprising the steps of:

[0143] S210: when k>s, k represents the system running time, s represents the order of the equivalence relation, the matrix Y s (k), U s (k), W s (k) and V s (k) are generated using s consecutive system data, which are the system measurement output, the system input, the process noise and the measurement noise represented by the equivalent space method, respectively;

[0144] Y s(k) = col{y(k-s), y(k-s+1),..., y(k)};

[0145] U s (k) = col{u(k-s), u(k-s+1),..., u(k)};

[0146] W s (k) = col{w(k-s), w(k-s+1),..., w(k)};

[0147] V s (k) = col{v(k-s), v(k-s+1),..., v(k)};

[0148] where col denotes the column vector composed of multiple vectors, i.e. for vectors a and b, col{a, b} = [a T b T ] T ;

[0149] S220: The equivalent relation expression of the system can be obtained:

[0150] Y s (k) = H 0,s x(k-s) + H u,s U s (k) + E s (k);

[0151] E s (k) is a composite noise matrix composed of process noise and measurement noise, E s (k) = H w,s W s (k) + H v,s V(k), H u,s , H 0,s , H v,s and H w,s are corresponding equivalent relation model coefficient matrices generated by the control system model coefficient matrix;

[0152] Specifically:

[0153]

[0154]

[0155]

[0156]

[0157] S230: Define the residual generated based on the equivalent space method:

[0158] rs (k)=Z s (Y s (k)-H u,s U s (k));

[0159] Among them, Z s It is an equivalent matrix, Z s The i-th row z s,i From equivalent space Introduced in the middle; further derived r s (k)=Z s E s (k)~N(0,Θ s ), where N represents a Gaussian distribution, Θ s Let be the covariance matrix of the residuals.

[0160] Specifically:

[0161]

[0162]

[0163]

[0164] As an optimization of the above embodiment, in step S300, the residual change caused by the replay attack is quantitatively analyzed, including the residual change in two cases: replay of both input and output, and replay of only output. This includes the following steps:

[0165] When k ≥ T0, k represents the system running time, T0 represents the attack start time, and the sensor output is replaced by historical data recorded by the attacker. c (k)=y d (k)=y(τ k ), τ k This indicates that the attacker has recorded past system runtimes, where t r1 ≤τ k <<t r2 And T0 >> t r2 Control signals were replaced by historical data recorded by the attacker. d (k)=u(τ k );

[0166] Let α represent the number of steps in which data is replaced; α = 0 indicates that the system is running normally, α > s indicates that the data of the system's equivalence relation is completely replayed, and 0 < α ≤ s indicates that the data of the system's equivalence relation is partially replayed; Y s α (k,τ k )and These represent the system's measured output and system input under a replay attack, respectively.

[0167] S310: In the case of input and output replay, the equivalence relation of the system is represented as:

[0168]

[0169] wherein, represents: the system input under α-step replay attack, represents: the influence of α-step replay attack on the equivalence relation representation;

[0170] Specifically,

[0171]

[0172]

[0173]

[0174] with 0 p×q representing a zero matrix of size p x q, * representing a symmetric block in the matrix; the corresponding parameter matrix is represented as:

[0175]

[0176]

[0177]

[0178]

[0179] The residual under replay attack is:

[0180]

[0181] wherein Y s α (k, τ k ) represents: the measurement output under α-step replay attack;

[0182] In the case of α > s, that is, complete data replay, the influence of replay attack on the residual is small, so the case of partial data replay is mainly considered; in the case of partial data replay, the expectation of the residual is obtained:

[0183] ε{r s α (k)} = 0, and ε represents the expectation of a variable;

[0184] and the covariance matrix:

[0185]

[0186] wherein, denotes r s α (k) the covariance matrix: cov denotes the covariance or covariance matrix of the variables;

[0187] In particular,

[0188]

[0189]

[0190] Further obtainable

[0191] wherein,

[0192] P x = cov{x(k)},

[0193] P wx,α = cov{W s-α (k- a), x(k - a + 1)},

[0194] P vx,α = cov{V s-α (k- a), x(k - a + 1)}.

[0195] S320: In case of a playback-only system: the system controller is implemented by {A c , B c , C c , D c}, the controller state is x(k), then the residual generated based on the equivalent space method under a replay attack is:

[0196] In particular,

[0197]

[0198]

[0199]

[0200] and the covariance matrix is:

[0201] In particular,

[0202]

[0203]

[0204]

[0205]

[0206]

[0207]

[0208]

[0209] H w21,α-1 is H w,s The lower-left block of the left block, including p(s+1-a) to p(s+1) rows, and 1 to q(s+1-a) columns.

[0210] As an optimization scheme of the above embodiment, in the step S400, a passive method of establishing four kinds of optimal equivalent matrix is established based on the residual quantization analysis result, including the steps of:

[0211] The equivalent matrix is parameterized as Z s =M s N s ; wherein N s is a non-zero equivalent matrix, so that N s H 0,s =0, N s H 0,s =0, N s ≠0 and M s is a non-zero weight matrix to be optimized;

[0212] S410: Positive definite part optimization:

[0213] Select optimization index:

[0214] Wherein, ||X|| i represents the i-norm of X, and are the equivalent space matrix comprehensive quantities under the unit weight with and without attack, respectively.

[0215]

[0216] is the positive definite part of the residual covariance change amount with input replay; is the difference between the positive definite part of the residual covariance change amount with and without input replay;

[0217]

[0218] Q s and R s are the system noise and measurement noise covariances under the equivalent space representation, respectively.

[0219]

[0220] I s+1 is a s+1 dimensional identity matrix;

[0221] Specifically,

[0222]

[0223]

[0224] For SVD decomposition:

[0225] U is the left singular matrix of V is the right singular matrix of Λ is the singular value matrix of ;

[0226] The solution of the optimization problem and its maximum value are:

[0227] M s = Λ -1 U T ;

[0228]

[0229] S420: Trace ratio optimization:

[0230] Select the optimization index:

[0231] Where: tr represents the trace of the matrix, is the inverse of the residual covariance matrix when the system is running normally, Δ α is the change in the residual covariance matrix with and without attacks, that is

[0232] T Δ,Σ is the cumulative sum of the unit weight equivalent space matrix comprehensive quantity under α step replay attack, α = 1,..., s;

[0233]

[0234]

[0235] Where: is the residual covariance change amount with input replay, is the difference in residual covariance change amount with and without input replay;

[0236] The solution of the optimization problem and its maximum value are:

[0237]

[0238] where M s,l and λ i are the i-th largest generalized eigenvector and corresponding eigenvalue of M , respectively.

[0239] S430: Accumulation and ratio optimization:

[0240] The optimization index is chosen as:

[0241] The optimization problem is whose solution and maximum value are the maximum generalized eigenvector of M and its eigenvalue λ.

[0242] S440: Detection rate optimization:

[0243] The optimization index is chosen as:

[0244] Given the false alarm rate γ, the optimization problem is described as:

[0245] The solution of the optimization problem and its maximum value are:

[0246]

[0247]

[0248] where a i ≠ 0, diag{a1,…a l} is a diagonal matrix composed of a i ; p and λ are the maximum generalized eigenvalue and corresponding eigenvector of M , respectively.

[0249] S50: Unified solution form:

[0250] The solution of the optimization problem is always of the following form:

[0251]

[0252] is the maximum eigenvalue of Λ -1 U T T Δ,Σ UΛ -1 corresponding to the eigenvector; Λ and U are obtained from

[0253] Further, M s = Λ​​-1 U T as a unified solution to the optimization problem.

[0254] As an optimization scheme of the above embodiment, in the step S500, an active method triggered based on attack events is established on the basis of the passive method, including the steps of:

[0255] concatenating a critically stable filter at the system output:

[0256] ζ(k+1) = A ζ ζ(k) + B ζ y(k+1)

[0257] where ζ(k) is the filter state, A ζ and B ζ are filter matrices; ζ(k) is used instead of y(k) to send to the monitor and control end, and y(k) is restored from ζ(k);

[0258] The overall dynamics of the monitor are:

[0259]

[0260]

[0261] where, is the new system dynamics, u(k) is the system input, w(k) is the measurement noise, v(k+1) is the system noise, A, B u , B w , C are control system model parameters, and I is a unit matrix with appropriate dimensions.

[0262] As an optimization scheme of the above embodiment, in the step S600, a statistical quantity is selected, a detection threshold and an alarm strategy are set, and detection is completed, including the steps of: based on residual covariance quantization analysis caused by a replay attack, a detection quantity is selected, a detection threshold and an alarm strategy are set, and replay attack detection is realized; including χ 2 detection and likelihood ratio detection.

[0263] The χ 2 detection:

[0264] The detection statistic is defined as:

[0265] where r s (k) is the residual generated based on the equivalent space method, Θ s is the residual covariance when the system is normally running, χ 2 (l) is a chi-square distribution with degree of freedom l; given the false alarm rate γ, the detection threshold is obtained according to the χ 2 data table When the statistical quantity is less than the threshold value, it indicates that no attack occurs, and when the statistical quantity is greater than the threshold value, it indicates that a replay attack occurs.

[0266] The likelihood ratio detection is:

[0267] The statistical quantity generated by the generalized likelihood function is defined as:

[0268]

[0269] Wherein, is the residual covariance of the system during operation The maximum likelihood estimation of r r is the number of observation values, n s (k-i) is the system residual error at k-i moment;

[0270]

[0271] The threshold value J of the likelihood ratio detection th,LR is learned through random analysis under a given false positive rate γ, and when the statistical quantity is less than the threshold value J th,LR , it indicates that no attack occurs, and when the statistical quantity is greater than the threshold value J th,LR , it indicates that a replay attack occurs, thereby realizing detection of the attack.

[0272] Examples:

[0273] Consider an information physical system with the following parameters:

[0274]

[0275] In the case of unified solution optimization, the detection rate results are as shown in Figure 2 . By using the active design method, A ζ =B ζ =1, and the rest are unchanged, the test is performed, and the detection rate results are as shown in Figure 3 . From Figure 2 and Figure 3 , when the detection rate corresponding to the original control system dynamics is low, the passive design improves the replay attack detection rate, but the overall detection performance is still poor. Application of the active design can greatly improve the replay attack detection rate, thereby verifying the effectiveness of the active design.

[0276] The above shows and describes the basic principles and main features of the present application and the advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above embodiments, and the above embodiments and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.

Claims

1. A method for detecting replay attacks in a cyber-physical industrial control system, characterized in that, Including the following steps: S100: Establish a cyber-physical industrial control system model, establish a state-space equation expression, and establish a description of the replay attack process; S200: Collects input and output data from the control system, generates detection residuals based on a cyber-physical industrial control system model using the equivalent space method, including the following steps: S210: When k > s, k represents the system running time, s represents the order of the equivalence relation, and s consecutive system data are used to generate a matrix including the system measurement output, system input, process noise and measurement noise, respectively represented by the equivalence space method; S220: Obtain the equivalence relation representation of the system; S230: Define the residuals generated based on the equivalent space method; S300: Quantitative analysis of residual changes caused by replay attacks, including residual changes in two cases: replaying both input and output, and replaying only the output. The steps include: When k≥T0, k represents the system running time and T0 represents the attack start time, the sensor output is replaced by the historical data recorded by the attacker; S310: When both input and output are replayed, establish the equivalence relation of the system and obtain the residual under the replay attack; When the data is completely replayed, the replay attack has little impact on the residuals, so we mainly consider the case of partial data replay; in the case of partial data replay, we obtain the expected value and covariance matrix of the residuals. S320: In the case of replaying system output only: Obtain the residual and covariance matrix generated based on the equivalent space method under replay attack; S400: Based on the results of residual quantization analysis, a passive method for establishing four optimal equivalent matrices is proposed, including the following steps: S410: Optimize the positive definite portion; S420: Perform trace ratio optimization; S430: Perform cumulative sum ratio optimization; S440: Optimize detection rate; S450: Unified solution form; S500: Based on the passive method, establish an active method triggered by attack events; S600: Select statistics, set detection thresholds and alarm strategies, and complete the detection.

2. The replay attack detection method for a cyber-physical industrial control system according to claim 1, characterized in that, In step S100, a cyber-physical industrial control system model is established, a state-space equation expression is established, and a description of the replay attack process is established, including the following steps: S110: Establish a linear time-invariant cyber-physical industrial control system model with noise: Where x(k) represents the system state, u(k) represents the system input, and y(k) represents the measurement output; w(k) and v(k) represent the process noise and measurement noise, respectively, which are independent of each other and are both zero-mean Gaussian white noise, satisfying: those T (k) v T (k)] T }=diag{Q,R} Where Q > 0, R > 0 are known covariance matrices, and diag{Q,R} is a block diagonal matrix composed of Q and R; A,B u B w C is a known matrix with a predetermined dimension; S120: Description of the replay attack process: In a cyber-physical industrial control system, controllers and detectors are configured to ensure the system's control performance and ability to detect anomalies, and control signals and measurement signals are transmitted over a network; In the absence of attacks and faults, the signal transmission in the system satisfies: y is the system output, let y c This represents the system output received by the controller, y d This represents the system output received by the detector; u is the system input, which makes u c Indicates the controller output, u d This indicates the control signal received by the detector.

3. The replay attack detection method for a cyber-physical industrial control system according to claim 2, characterized in that, The replay attack process includes the following steps: S121: Attackers record time range [t] through eavesdropping attacks r1 ,t r2 [t] sensor output, and / or control input, [t] r1 ,t r2 [This is] a sufficiently long time interval; S122: When k ≥ T0, k represents the system running time, T0 represents the attack start time, and the attacker uses the recorded data to replace the sensor output, y c (k)=y d (k)=y(τ k ), τ k This indicates that the attacker has recorded past system runtimes, where t r1 ≤τ k <<t r2 And T0 >> t r2 ; Add a malicious signal u to the system input a (k) to disrupt system performance, u(k) = u c (k)+u a (k); Use the recorded data to replace the detector's control signal input, u d (k)=u(τ k ).

4. A replay attack detection method for a cyber-physical industrial control system according to claim 2 or 3, characterized in that, In step S200, input and output data of the control system are collected, and detection residuals are generated using the equivalent space method based on the cyber-physical industrial control system model, including the following steps: S210: When k > s, k represents the system running time, and s represents the order of the equivalence relation. Generate matrix Y using s consecutive system data. s (k), U s (k), W s (k) and V s (k) represent the system measurement output, system input, process noise, and measurement noise, respectively, expressed using the equivalent space method; AND s (k)=col{y(ks),y(k-s+1),…,y(k)}; YOU s (k)=col{u(ks),u(k-s+1),…,u(k)}; W s (k)=col{w(k-s),w(k-s+1),…,w(k)}; In s (k)=col{v(ks),v(k-s+1),…,v(k)}; Where col represents a column vector composed of multiple vectors; S220: Obtain the equivalent relation representation of the system: Y s (k)=H 0,s x(k-s)+H u,s U s (k)+E s (k); E s (k) is a composite noise matrix consisting of process noise and measurement noise, E s (k)=H w,s W s (k)+H v,s V(k), H u,s H 0,s H v,s and H w,s The corresponding equivalent relation model coefficient matrices generated from the control system model coefficient matrix; S230: Define the residuals generated based on the equivalent space method: r s (k)=Z s (Y s (k)-H u,s U s (k)); Among them, Z s It is an equivalent matrix, Z s The i-th row z s,i From equivalent space Introduced in the middle; further derived r s (k)=Z s E s (k)~N(0,Θ s ), where N represents a Gaussian distribution, Θ s Let be the covariance matrix of the residuals.

5. The replay attack detection method for a cyber-physical industrial control system according to claim 4, characterized in that, In step S300, the residual changes caused by the replay attack are quantitatively analyzed, including residual changes in two cases: replaying both input and output, and replaying only the output. This includes the following steps: When k ≥ T0, k represents the system running time, T0 represents the attack start time, and the sensor output is replaced by historical data recorded by the attacker. c (k)=y d (k)=y(τ k ), τ k This indicates that the attacker has recorded past system runtimes, where t r1 ≤τ k <<t r2 And T0 >> t r2 Control signals were replaced by historical data recorded by the attacker. d (k)=u(τ k ); Let α represent the number of steps in which data is replaced; α = 0 indicates that the system is running normally, α > s indicates that the data of the system equivalence relation is completely replayed, and 0 < α ≤ s indicates that the data of the system equivalence relation is partially replayed. and These represent the system's measured output and system input under a replay attack, respectively. S310: When both input and output are replayed, the equivalence relation of the system is expressed as: in, This represents the system input under an alpha-step replay attack. This indicates the impact of the α-step replay attack on the equivalence relation representation; The residual under a replay attack is: in, This represents the measurement output under an alpha-step replay attack. When α > s, i.e., the data is completely replayed, the impact of a replay attack on the residuals is small. Therefore, we mainly consider the case of partial data replay. In the case of partial data replay, we obtain the expected value of the residuals: ε represents the expected value of the variable; Sum of covariance matrix: in, express The covariance matrix: cov represents the covariance of the variables or the covariance matrix; S320: In the case of only replaying the system output: the system controller is controlled by {A} c B c C c D c }accomplish, In the controller state, the residual generated by the equivalent space method under a replay attack is represented as: The sum and covariance matrix are:

6. The replay attack detection method for a cyber-physical industrial control system according to claim 5, characterized in that, In step S400, based on the residual quantization analysis results, a passive method for establishing four optimal equivalent matrices is established, including the following steps: The equivalent matrix is ​​parameterized as Z. s =M s N s ; where N s Let N be a non-zero equivalent matrix, such that N s H 0,s =0, M s Here is the non-zero weight matrix to be optimized; S410: Positive Deterministic Optimization: Select optimization metrics: Among them, ||X|| i Denotes the i-norm of X, and These represent the total equivalent space matrix under unit weight, with and without attack conditions; The positive definite portion of the change in residual covariance with input is given. This represents the difference in the positive definite portion of the residual covariance variation with and without input replay. Q s and R s These are the system noise and measurement noise covariances in the equivalent space representation, respectively. I s+1 It is an s+1 dimensional identity matrix; right Perform SVD decomposition: U is The left singular matrix, V is The right singular matrix, Λ is The singular value matrix; Optimization problem The solutions and their maximum values ​​are: M s =L -1 U T ; S420: Trace Ratio Optimization: Select optimization metrics: Where: tr represents the trace of the matrix. Δ is the inverse of the residual covariance matrix when the system is running normally. α The change in the residual covariance matrix with and without attack, i.e. T Δ,Σ Let α be the cumulative sum of the unit weight equivalent space matrix under an α-step replay attack, where α = 1,...,s; in: This represents the change in residual covariance under the condition of input replay. The difference in the change of residual covariance with and without input playback; Optimization problem The solutions and their maximum values ​​are: Among them, M s,l and λ i yes The i-th largest generalized eigenvector and its corresponding eigenvalue; S430: Cumulative Sum Ratio Optimization: Select optimization metrics: Optimization problem The equivalent matrix solutions and their maximum values ​​are as follows: Maximum generalized eigenvector and its eigenvalue λ; S440: Detection rate optimization: Select optimization metrics: Given a false positive rate γ, the optimization problem can be described as follows: The solutions to the optimization problem and their maximum values ​​are: Among them, a i ≠0, diag{a1,…a l } is composed of a i The diagonal matrix formed; p and λ are The largest generalized eigenvalue and the corresponding eigenvector; S450: Unified solution form: Optimization problem The solution always has the following form: For Λ -1 U T T Δ,Σ UΛ -1 The eigenvector corresponding to the largest eigenvalue; Λ and U are derived from... get; Further M s =Λ -1 U T As a unified solution to optimization problems.

7. The replay attack detection method for a cyber-physical industrial control system according to claim 6, characterized in that, In step S500, based on the passive method, an active method triggered by an attack event is established, including the following steps: A critically stable filter is cascaded at the system output: ζ(k+1)=A ζ g(k)+B ζ y(k+1) Where ζ(k) is the filter state, A ζ and B ζ It is a filter matrix; ζ(k) is used to replace y(k) and sent to the monitor and control terminal, and y(k) is restored from ζ(k); The overall dynamics of the monitor are as follows: in, For the new system dynamics, u(k) is the system input, w(k) is the measurement noise, v(k+1) is the system noise, and A and B are... u B w C represents the control system model parameters, and I represents the identity matrix with appropriate dimensions.

8. The replay attack detection method for a cyber-physical industrial control system according to claim 7, characterized in that, In step S600, a statistical quantity is selected, a detection threshold and an alarm strategy are set to complete the detection. This includes the following steps: selecting a detection quantity and setting a detection threshold and alarm strategy based on the quantitative analysis of the residual covariance caused by the replay attack, thereby realizing replay attack detection; including χ² 2 Detection and likelihood ratio detection.

9. The replay attack detection method for a cyber-physical industrial control system according to claim 8, characterized in that, The χ 2 Detection: Define the detection statistic: Where, r s (k) is the residual generated based on the equivalent space method, Θ s It is the residual covariance when the system is running normally, χ 2 (l) is a chi-square distribution with l degrees of freedom; given the false alarm rate γ, according to χ 2 Data table to obtain detection threshold When the statistic When the value is less than the threshold, it indicates that no attack has occurred; when the value is greater than the threshold, it indicates that a replay attack has occurred.

10. A method for detecting replay attacks in a cyber-physical industrial control system according to claim 8, characterized in that, The likelihood ratio detection: The statistic generated by the generalized likelihood function is defined as: in, It is the residual covariance during system operation. The maximum likelihood estimate, n r r represents the number of observations. s (ki) represents the system residual at time ki; Threshold J for likelihood ratio detection th,LR Given a false alarm rate γ, it is learned through random analysis, when the statistic J is... nr,LR (k) is less than the threshold J th,LR When the statistic J is in a certain state, it indicates that no attack has occurred. nr,LR (k) is greater than the threshold J th,LR This indicates that a replay attack has occurred, enabling the detection of the attack.

Citation Information

Patent Citations

  • Industrial control system communication network anomaly classification method based on statistical learning and deep learning

    CN112202736A

  • Active attack detection method for improving detection rate

    CN114063602A