A method for simulating covert attacks on nonlinear networked control systems

By designing an attack strategy based on an interference observer, a covert attack on a nonlinear networked control system is simulated. This solves the problem of the difficulty in detecting highly covert replay attacks in existing technologies, provides guidance for monitoring and defense, and ensures that the attack signal is concealed but the system state is affected.

CN117914610BActive Publication Date: 2025-10-28SHANGHAI JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410107514.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-10-28
Estimated Expiration
2044-01-25

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively detect and defend against covert attacks in nonlinear networked control systems, especially replay attacks, which are highly covert and can potentially damage the system's state without being detected.

Method used

An attack strategy based on interference observers is designed. By simulating network attacks from the sensor to the controller and from the controller to the actuator, the unknown nonlinear terms are estimated using the system's measurement output and control input, thereby achieving the concealment of the attack signal and severely affecting the system state.

Benefits of technology

The simulation of covert attacks on nonlinear networked control systems was realized, providing guidance for subsequent monitoring and defense. This ensures that the attack signals are highly concealed within the system but have a significant impact on the system state, helping defenders to identify and defend against them.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914610B_ABST
    Figure CN117914610B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of network attack and defense of networked control systems, and relates to a method for simulating covert attacks on nonlinear networked control systems and its application. From the attacker's perspective in network attack and defense, this invention designs an interference observer one using the input-output information transmitted in the system network to estimate unknown nonlinear terms in the system under unattacked conditions; simultaneously, an attack signal is injected into the controller-to-actuator network, and another interference observer is designed to estimate the nonlinear terms in the system after the attack; using the estimated output information of the two interference observers, a covert attack model is designed, and its covertness is analyzed, ensuring that the output state of the nonlinear networked control system remains essentially unchanged before and after the attack, thus avoiding the influence of the defender on the controller-to-actuator network. The method of this invention can be widely applied to nonlinear networked control systems in spacecraft, intelligent transportation, and intelligent manufacturing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network attack and defense of networked control systems, and relates to a method for simulating covert attacks on nonlinear networked control systems and its application. Background Technology

[0002] In recent years, due to the rapid development of science and technology and the decline in communication costs, traditional control systems have gradually been replaced by networked control systems. Networked control systems consist of embedded components for detection, computation, control, and communication. These components are tightly connected through shared communication networks (wired or wireless) to perform data sensing, collection, processing, and transmission tasks. Networked control systems integrate the cyberspace and physical worlds by leveraging ubiquitous computing resources and communication capabilities. Due to their advantages such as ease of maintenance, high flexibility, and low cost, networked control systems have permeated modern society and are widely used in power / gas / water production and distribution systems, intelligent transportation networks, advanced manufacturing systems, and the aerospace field. Given their broad application scenarios, networked control systems have received widespread attention from industry and academia. However, networked control systems also possess a high degree of "openness," making them vulnerable to cyberattacks. Any successful attack on a networked control system can lead to catastrophic system failures and cause unbearable losses.

[0003] Attackers' cyberattacks on networked control systems can be broadly categorized into two types: denial-of-service (DoS) attacks and spoofing attacks. DoS attacks aim to consume limited communication resources by sending large amounts of invalid data, thereby hindering the transmission of normal data, i.e., compromising data reachability; they are not based on any model information of the system. Spoofing attacks aim to damage system performance by tampering with normally transmitted data in the communication network, i.e., compromising data reliability. The most representative spoofing attacks are replay attacks and erroneous data injection attacks. Replay attacks refer to malicious attackers eavesdropping on and recording transmitted data in the communication network for a certain period, and subsequently delaying or repeatedly injecting this data to damage system performance. Because the data injected into the system by replay attacks is naturally generated by the system, replay attacks are highly concealed and difficult to detect; therefore, current research on replay attacks focuses more on attack detection mechanisms. Spoofing attacks refer to attackers using restricted tampering models to disrupt normal system data, injecting the tampered data into the system to undermine its stability.

[0004] With the increased observability and estimability of system models and advancements in attack strategy implementation methods, attackers have begun to combine their own conditions with the target system model to design attack patterns that can evade monitoring mechanisms. Therefore, focusing on covert attacks that subtly affect the estimation and control performance of networked control systems has greater strategic significance. Covert attacks inject model-related attack signals simultaneously into the forward and feedback network channels. While altering the original system state, they ensure that the measured output of the attacked system remains unchanged; that is, the system state is severely affected imperceptibly, ultimately leading to the collapse of the entire system without being detected. In 2015, Sean Weerakkody et al. proposed a covert attack model for linear networked control systems. However, real systems are all nonlinear systems; therefore, applying covert attack models suitable for linear systems to real systems has significant limitations.

[0005] In network attack and defense, when faced with various attack patterns of the attacker, the defender should try to understand the attack pattern and master the attack methods through monitoring. Only on this basis can the defender make corresponding defense strategies and achieve the effect of "knowing yourself and your enemy". Summary of the Invention

[0006] This invention simulates a stealthy attack strategy for networked control systems with unknown nonlinear terms, providing guidance and testing methods for setting corresponding monitoring and defense strategies against such stealthy attacks.

[0007] The technical problem solved by this invention is: from the attacker's perspective, how to design an attack strategy based on the dynamic model of the nonlinear networked control system and the control input and output information in the public network transmission process, so that the measurement information transmitted from the system sensor to the controller network remains basically unchanged before and after the attack, that is, for the controller, the attacker's attack signal has a certain degree of concealment.

[0008] The technical solution of this invention is as follows: Based on the concept of active anti-interference, a simulated attack strategy with a certain degree of concealment but with severe destructive power to the system is designed. The specific implementation steps are as follows:

[0009] Step 1: Establish a nonlinear networked control system model under covert attacks

[0010] In practice, nonlinear networked control systems that are not under attack can all be constructed as state-space expressions of the following form.

[0011]

[0012] In the formula, x k =[x 1,k x 2,k… x n,k ] T For system state, u k and y k These are the system control input and output, respectively, f(x) k ,d k ) represents the unknown nonlinear term of the system, and A0, B0, C0 represent the known coefficient matrix of the system.

[0013] When the sensor-to-controller network and the controller-to-actuator network in the above nonlinear networked control system are simultaneously subjected to a spoofing attack, the system model becomes:

[0014]

[0015] In the formula, This represents the system state after an attack has been launched from the system controller to the actuator end. For unknown nonlinear terms in the system after an attack, This refers to the system's output state after both the sensor-to-controller and controller-to-actuator networks in the system are simultaneously subjected to spoofing attacks. These are the attack signals injected by the attacker into the communication networks from the system controller to the actuator and from the sensor to the controller, respectively. Their specific forms will be given in subsequent steps.

[0016] Step 2: Before launching an attack, the attacker establishes a jamming observer on the system.

[0017] Considering the nonlinear networked control system under unattacked conditions from the attacker's perspective (1), the unknown nonlinear term f(x) is... k ,d k Set as the new state x n+1,k That is, f(x) k ,d k )=x n+1,k Then the original nonlinear networked control system (1) can be expanded as follows:

[0018]

[0019] In the formula, The state of the expanded system. For the unknown nonlinear term f(x) k ,d k The rate of change of T t The sampling period is denoted by A1, B1, C1, and D1, which represent known coefficient matrices.

[0020] For the extended nonlinear networked control system (3), the attacker designs a disturbance observer of the following form:

[0021]

[0022] In the formula, System status The estimated value of To estimate the error, Λ is the adjustable gain parameter of the interference observer (4).

[0023] Step 3: After launching the attack, the attacker establishes a second interference observer on the system.

[0024] When the controller to actuator of a nonlinear networked system is subjected to a network attack, the original nonlinear networked control system (1) can be rewritten as:

[0025]

[0026] In the formula, This represents the true output state of the system after the network from the system controller to the actuator has been subjected to a spoofing attack.

[0027] For system (5), the attacker will introduce unknown nonlinear terms. Set as new state Right now Then equation (5) can be expanded to the following form:

[0028]

[0029] In the formula, The state of the expanded system. For unknown nonlinear terms The rate of change, where A1, B1, C1, D1 represent known coefficient matrices.

[0030] The attacker designed the following form of interference observer two for the expanded system (6):

[0031]

[0032] In the formula, z k =[z 1,k z 2,k … z n+1,k ] T System status The estimated value of To estimate the error, Γ is the adjustable gain parameter of the interference observer (7).

[0033] Step 4: Establish an attacker model based on the interference observer.

[0034] Based on the interference observers (4) and (7), the attacker model is set in the following form:

[0035]

[0036] In the formula, For the state in the attacker's model, This outputs the status of the attacker's system.

[0037] Step 5: Analyze the stealth of the attack strategy

[0038] From the original nonlinear networked control system (1), it can be seen that the system output y k The expression is

[0039]

[0040] According to equations (2) and (8), the system outputs after being attacked. The expression is

[0041]

[0042] In the formula, and Let be the estimation error of the unknown nonlinear term at time i.

[0043] Analysis of equation (10) shows that if the system matrix A0 is Hurwitz, when k→∞, If an initial state is defined and Furthermore, when the estimates of the unknown nonlinear term by the interference observers (4) and (7) are approximately zero, the same can be obtained. Therefore, it can be said that under the action of the attack system model (8), attack information is simultaneously injected into the sensor-to-controller and controller-to-actuator networks of the nonlinear networked control system (1). and System output status Compared with the original system output state y k The basic principles remain the same, meaning that the attacker has a certain degree of concealment from the original system.

[0044] As can be seen from system (5), while the attacker's malicious attack behavior has a certain degree of concealment from the original system, it will seriously change the state information x of the original system. k .

[0045] The advantages of this invention compared to the prior art are as follows:

[0046] (1) For networked control systems, the present invention considers both the sensor-to-controller and controller-to-sensor networks being attacked by malicious attackers.

[0047] (2) The attacker uses the measurement output and control input of the system before and after the attack to design two interference observations to estimate the unknown nonlinear terms in the system;

[0048] (3) From the attacker's perspective, a stealthy attack strategy is designed for nonlinear networked control systems to avoid the influence of the defender on the network from the controller to the actuator, ultimately causing the defender's system to collapse.

[0049] (4) From the perspective of network attack and defense, this invention provides a method to simulate covert attacks on nonlinear networked control systems, providing guidance and testing means for setting corresponding monitoring and defense strategies against such covert attacks. Attached Figure Description

[0050] Figure 1 A flowchart illustrating the design of a method for simulating covert attacks on nonlinear networked control systems.

[0051] Figure 2 A block diagram illustrating a method for simulating covert attacks on nonlinear networked control systems.

[0052] Figure 3 This is a graph showing the error curve of the attacker's estimation of the system state before the attack.

[0053] Figure 4 This is a graph showing the error in the attacker's estimation of the system state after the attack.

[0054] Figure 5 The output status curves of the system before and after the attack are shown. Detailed Implementation

[0055] The method of simulating covert attacks on nonlinear networked control systems of the present invention is as follows: Figure 1 and Figure 2 As shown, a covert attack on a nonlinear networked control system is achieved through the following steps:

[0056] Step 1: Establish a nonlinear networked control system model under covert attacks

[0057] In practice, nonlinear networked control systems that are not under attack can all be constructed as state-space expressions of the following form.

[0058]

[0059] In the formula, x k =[x 1,k x 2,k … x n,k ] T For system state, u k and y k These are the system control input and output, respectively, f(x) k ,d kThe system state x represents the unknown nonlinear term, and A0, B0, C0 represent the known coefficient matrices of the system. This example considers a second-order nonlinear networked control system model; therefore, the system state x... k =[x 1,k x 2,k ] T Unknown nonlinear term f(x) k ,d k ) = 0.5 + 0.2x 1,k ·x 2,k +0.4e -0.6k ·arctan k, the coefficient matrices A0, B0, C0 of the system are respectively chosen as

[0060] When the sensor-to-controller network and the controller-to-actuator network in the above nonlinear networked control system are simultaneously subjected to a spoofing attack, the system model becomes:

[0061] In this example This represents the system state after an attack has been launched from the system controller to the actuator end. For unknown nonlinear terms in the system after an attack, This refers to the system's output state after both the sensor-to-controller and controller-to-actuator networks in the system are simultaneously subjected to spoofing attacks. These are the attack signals injected by the attacker into the communication networks from the system controller to the actuator and from the sensor to the controller, respectively. Their specific forms will be given in subsequent steps.

[0062] Step 2: Before launching an attack, the attacker establishes a jamming observer on the system.

[0063] Considering the nonlinear networked control system under no-attack conditions from the attacker's perspective (11), the unknown nonlinear term f(x) is... k ,d k Set as the new state x 3,k That is, f(x) k ,d k )=x 3,k Then the original nonlinear networked control system (11) can be expanded as follows:

[0064] In this example The state of the expanded system. For the unknown nonlinear term f(x) k ,d k The rate of change of ) and the sampling period is selected as T. t =0.01, A1, B1, C1, D1 represent known coefficient matrices, whose expressions are as follows:

[0065]

[0066] For the extended nonlinear networked control system (13), the attacker designs a disturbance observer of the following form:

[0067] In this example System status The estimated value of To estimate the error, Λ is the adjustable gain parameter of the interference observer (14), which is selected as in this example.

[0068] The estimation error system of the interference observer (14) for the system before the attack is as follows:

[0069]

[0070] In the formula, To estimate the error, where In this example, the attacker uses interference observer (14) to estimate the system state error curve before the attack, as shown in the figure. Figure 3 As shown.

[0071] Step 3: After launching the attack, the attacker establishes a second interference observer on the system.

[0072] When the nonlinear networked system controller to actuator end suffers a network attack, the original nonlinear networked control system (11) can be rewritten as:

[0073]

[0074] In the formula, This represents the true output state of the system after the network from the system controller to the actuator has been subjected to a spoofing attack.

[0075] For system (16), the attacker will introduce unknown nonlinear terms. Set as new state Right now Then equation (16) can be expanded to the following form:

[0076] In this example The state of the expanded system. For unknown nonlinear terms The rate of change, where A1, B1, C1, D1 represent known coefficient matrices.

[0077] The attacker designed the following form of interference observer two for the expanded system (17):

[0078]

[0079] In this example, z k =[z 1,k z 2,k z 3,k ] T System status The estimated value of To estimate the error, Γ is the adjustable gain parameter of the interference observer (18), and in this example, it is selected as Γ.

[0080] The estimation error system of the interference observer (18) for the attacked system is as follows:

[0081] e k+1 =A1e k -Γe 1,k +D1g k (19)

[0082] In the formula, e k+1 =[e 1,k e 2,k e 3,k ] represents the estimated error, where

[0083] In this example, after the attacker launches an attack on the system, they use the interference observer (18) to estimate the error curve of the system state, as shown in the figure. Figure 4 As shown.

[0084] Step 4: Establish an attacker model based on the interference observer.

[0085] Based on the interference observers (14) and (18), the attacker model in this example is set as follows:

[0086]

[0087] In the formula, For the state in the attacker's model, This represents the attacker's system output status. In this example, the attack signal selected from the controller to the actuator is...

[0088] Step 5: Analyze the stealth of the attack strategy

[0089] As can be seen from the original nonlinear networked control system (11), the system output y k The expression is

[0090]

[0091] According to equations (12) and (18), the system outputs after being attacked. The expression is

[0092]

[0093] In the formula, and Let be the estimation error of the unknown nonlinear term at time i.

[0094] Analysis of equation (22) shows that if the system matrix A0 is Hurwitz, when k→∞, If an initial state is defined and Furthermore, when the estimates of the unknown nonlinear term by the interference observers (14) and (18) are approximately zero, the same can be obtained. Therefore, it can be said that under the action of the attack system model (20), attack information is simultaneously injected into the sensor-to-controller and controller-to-actuator networks of the nonlinear networked control system (1). and System output status Compared with the original system output state y k The overall structure remains largely consistent, meaning the attacker maintains a certain degree of stealth from the original system. In this example, after the attacker launches a stealthy attack on the system, the output state curves of the system before and after the attack are as follows: Figure 5 As shown.

[0095] As can be seen from system (16), the attacker's malicious attack behavior has a certain degree of concealment from the original system, while seriously changing the state information x of the original system. k .

[0096] The parts of this invention not described in detail are common knowledge to those skilled in the art.

Claims

1. A method for simulating covert attacks on nonlinear networked control systems, characterized in that: For nonlinear networked control systems, a disturbance observer 1 is established to estimate unknown nonlinear terms in the system under unattacked conditions, and a disturbance observer 2 is established to estimate unknown nonlinear terms in the system under attack conditions. An attacker model is established based on the estimation output information of disturbance observer 1 and disturbance observer 2. The following steps are involved: Step S1: Establish a nonlinear networked control system model under covert attacks; Step S2: Before launching an attack, the attacker establishes an interference observer on the system; Step S3: After launching the attack, the attacker establishes a second interference observer on the system; Step S4: Establish an attacker model based on the interference observer; The interference observer established in step S2 is used to estimate the unknown nonlinear terms in the system under unattacked conditions; The interference observer established in step S3 is used to estimate the nonlinear terms in the system after the attack. The attacker model established in step S4 is based on the estimated output information of interference observer one and interference observer two. In step S1, the following nonlinear networked control system model under covert attack is established: The nonlinear networked control system under unattacked conditions is constructed as a state-space expression of the following form. In the formula, x k =[x 1,k x 2,k …x n,k ] T For system state, u k and y k These are the system control input and output, respectively, f(x) k ,d k ) represents the unknown nonlinear term of the system, and A0, B0, C0 represent the known coefficient matrix of the system; When the sensor-to-controller network and the controller-to-actuator network in the above nonlinear networked control system are simultaneously subjected to a spoofing attack, the system model becomes: In the formula, This represents the system state after an attack has been launched from the system controller to the actuator end. For unknown nonlinear terms in the system after an attack, This refers to the system's output state after both the sensor-to-controller and controller-to-actuator networks in the system are simultaneously subjected to spoofing attacks. These are attack signals injected by the attacker into the communication networks from the system controller to the actuator and from the sensor to the controller, respectively. In step S2, for the nonlinear networked control system (1), the unknown nonlinear term f(x) is... k ,d k Set as the new state x n+1,k That is, f(x) k ,d k )=x n+1,k The original nonlinear networked control system (1) is expanded to: In the formula, The state of the expanded system. For the unknown nonlinear term f(x) k ,d k The rate of change of T t The sampling period is A1, B1, C1, and D1, which represent known coefficient matrices. For the extended nonlinear networked control system (3), the attacker designs a disturbance observer of the following form: In the formula, System status The estimated value of To estimate the error, Λ is the adjustable gain parameter of the interference observer (4); In step S3, when the nonlinear networked system controller to the actuator is subjected to a network attack, the original nonlinear networked control system (1) is rewritten as follows: In the formula, This represents the true output state of the system after the network from the system controller to the actuator has been subjected to a spoofing attack. For system (5), the attacker will introduce unknown nonlinear terms. Set as new state Right now Equation (5) is expanded to the following form: In the formula, The state of the expanded system. For unknown nonlinear terms The rate of change, where A1, B1, C1, D1 represent known coefficient matrices; The attacker designed the following form of interference observer two for the expanded system (6): In the formula, z k =[z 1,k z 2,k …z n+1,k ] T System status The estimated value of To estimate the error, Γ is the adjustable gain parameter of the interference observer (7); In step S4, based on interference observer one shown in equation (4) and interference observer two shown in equation (7), the attacker model is set as follows: In the formula, For the state in the attacker's model, This outputs the status of the attacker's system.

2. The application of the method for simulating covert attacks on nonlinear networked control systems according to claim 1, characterized in that: Used to simulate attacker behavior in network attack and defense.

3. The application of the method for simulating covert attacks on nonlinear networked control systems according to claim 1, characterized in that: Used to provide the defender with testing or security assessment tools in network attack and defense.

Citation Information

Patent Citations

  • Attitude control method for spacecraft networked system based on event trigger

    CN109189085A

  • Anti-network attack graph game control method for multi-satellite communication network

    CN112291800A