Replay Attack Detection Method and System for Binary Measurement FIR System Identification

By designing a playback attack detection method for binary measurement FIR systems in the quantization system, using components such as FIR subsystem and binary sensors, the problem of the quantization system facing the playback attack detection problem is solved, effectively detecting playback attacks is achieved, and the security and stability of CPSs are improved.

CN118921203BActive Publication Date: 2025-06-20UNIV OF SCI & TECH BEIJING
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411015600.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2025-06-20
Estimated Expiration
2044-07-26

AI Technical Summary

Technical Problem

When the quantitative system faces replay attacks, existing attack detection solutions are difficult to effectively detect, which increases the difficulty of security protection of CPSs.

Method used

A replay attack detection method for binary measurement FIR system identification is proposed. Through the coordinated work of the FIR subsystem, binary sensor, communication network, estimation center and detector, a replay attack detection algorithm is designed, including offline and online detection methods, and the misjudgment rate and misjudgment rate are used as performance metrics of the detection algorithm.

Benefits of technology

It realizes effective detection of playback attacks, improves the robustness of CPSs in the network attack environment, and ensures the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118921203B_ABST
    Figure CN118921203B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and particularly to a replay attack detection method and system for binary measurement FIR system identification. The method includes: the finite impulse response (FIR) subsystem obtains the input of the FIR subsystem, and measures the output of the FIR subsystem through a binary sensor to obtain a measurement result; the communication network transmits the measurement result to the estimation center; the estimation center transmits the received data to the detector; the detector designs a replay attack detection algorithm based on the received data and the subsystem input, and performs replay attack detection on the process of the communication network transmitting the measurement result to the estimation center according to the replay attack detection algorithm, so as to obtain a replay attack detection result for binary measurement FIR system identification. The present invention takes the quantized FIR system as the object, studies the problem of replay attack detectability from the perspective of system identification, and detects replay attacks by increasing the input excitation and combining the designed algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a replay attack detection method and system for binary measurement FIR system identification. Background Art

[0002] With the rapid development of information technology, CPSs (Cyber-Physical Systems) play an increasingly important role in today's society. CPSs are systems that integrate computers, networks, and physical processes, aiming to achieve real-time perception, intelligent control, and real-time response to the physical world. This deep integration provides unprecedented convenience and efficiency for our daily lives and critical infrastructures. Such systems cover various fields from smart energy, intelligent healthcare to industrial automation.

[0003] One of the core characteristics of CPSs is their high dependence on communication networks. Whether it is an industrial control system, an intelligent transportation system, or an intelligent health system, CPSs require real-time and reliable communication to ensure the coordinated operation of various parts of the system. However, it is precisely this communication dependence that makes CPSs potential targets for network attacks. By interfering with or disrupting communication links, attackers may cause CPSs to lose control of the actual physical process, thus triggering major security hazards. With the continuous evolution of network attack technologies, the threats posed by attackers to CPSs have become more concealed and destructive. The number of network attack threat events faced by CPSs is also showing an increasing trend. Against this background, deeply understanding the security issues faced by CPSs and taking practical measures have become an urgent task to ensure the reliability and stability of CPSs systems. In the face of increasingly complex network attack threats, attack detection has become a key link in ensuring the security of CPSs. Timely detecting, locating, and responding to potential network attack events is crucial for preventing losses and ensuring the reliability of the system. Attack detection is not only a means to deal with attacks but also a key component of the overall network security strategy. By continuously improving attack detection algorithms, strengthening log analysis, and implementing real-time monitoring, the overall security of CPSs systems can be effectively improved. This is reflected in the current research status.

[0004] In order to solve the problem of cyber attack detection in distributed parameter cyber-physical systems based on linear parabolic partial differential equation models, the authors developed an attack detection algorithm design framework based on output injection observer, and studied the balance between robustness to uncertainty and sensitivity to abnormal situations. The authors designed a false data injection attack detector using deep reinforcement learning method, and studied the problem of detecting discontinuous false data injection attacks in cyber-physical systems. Aiming at the problem of attack detection and security control for discrete-time nonlinear cyber-physical systems under false data injection attacks, the paper Y. Chen, T. Li, Y. Long, W. Bai, Attacks detection and security control for cyber-physical systems under falsedata injection attacks, Journal of the Franklin Institute, 360(14): 10476--10498, 2023. T-S A fuzzy model with A new robust extended state observer for performance to detect such attacks. Reference: G. Franzè, D. Famularo, W. Lucia, F. Tedesco, Cyber–physical systems subject to false data injections: A model predictive control framework for resilience operations, Automatica, 152, 110957, 2023. Solves the problems of false data injection attack detection and resilient control for constrained cyber-physical systems by adopting a receding horizon philosophy framework. Reference: Y. Li, Y. Yang, T. Chai, T. Chen, Stochastic detection against deception attacks in CPS: Performance evaluation and game-theoretic analysis, Automatica, 144, 110461, 2022. Proposes a stochastic detection mechanism with variable triggering thresholds to counter potential deception attacks and studies the interactive decision-making process between the system and the attacker within a game-theoretic framework.

[0005] Quantized communication, as a new type of communication method, achieves efficient information transmission. The main advantage of this communication method is that it can significantly improve communication efficiency, reduce energy consumption, and transmit more information under the same bandwidth through quantization. This makes the quantized system an important part of the communication link in CPSs. The quantized system brings an improvement in communication efficiency to CPSs, but it introduces new network attack problems. Because attackers can attack it through means different from traditional communication systems. Attackers may utilize quantization errors, quantization noise, or vulnerabilities in the quantization algorithm for attacks, which requires us to re-evaluate and strengthen the security protection of the quantized system. Due to the relatively small number of data types generated by the quantized system, traditional attack detection schemes based on large-scale data training become more difficult in this context. The scarcity of data may lead to insufficient model training and reduce the accuracy of the detection algorithm.

[0006] Due to the special nature of the quantization system, attackers may find it easier to violate the privacy and integrity of data. By analyzing the patterns of quantized signals, attackers may obtain sensitive information or interfere with the normal operation of the system. In particular, by introducing replay attacks into the quantization system, attackers may make attack detection more difficult, increasing the difficulty of security protection for CPSs. Attackers intercept and resend previous communication data in an attempt to deceive the system to carry out malicious behaviors. Replay attacks are easy to implement and have a certain degree of concealment, while causing greater damage to the system. In addition, when faced with sensitive information, attackers are more likely to disclose information and evade detection, making the design of attack detection more difficult. Although existing replay attack detection schemes in CPSs are based on state estimation and non-quantized systems, they can provide us with some ideas to study attack detection schemes under quantized systems. Literature A. Naha, A. Teixeira, A. Ahlen, S. Dey, Sequential Detection of Replay Attacks, IEEE Transactions on Automatic Control, 68(3): 1941--1948, 2023. solves the replay attack detection problem by adding watermarks to the input signal and performing a cumulative sum test to maximize the divergence of the joint distribution before and after the attack. Literature L. Zhai, K. Vamvoudakis, A data-based private learning framework for enhanced security against replay attacks in cyber-physical systems, International Journal of Robust and Nonlinear Control, 31(6): 1817--1833, 2021. proposes a method for detecting replay attacks by adding periodic watermarks and a data-based Neyman-Pearson detector to identify and counter replay attacks, and explores the trade-off between control performance loss and detection performance.The literature M. Zhu, S. Martínez, On the Performance Analysis of Resilient Networked Control Systems Under Replay Attacks, IEEE Transactions on Automatic Control, 59(3): 804--808, 2014. proposed using timestamps to detect replay attacks, dealing with replay attacks through the receding horizon principle, and analyzing the resource consumption when the control system reaches asymptotic stability and exponential stability. The literature M. Hosseinzadeh, B. Sinopoli, E. Garone, Feasibility and Detection of Replay Attack in Networked Constrained Cyber-Physical Systems, In 2019 57th Annual Allerton Conference on Communication, Control, and Computing, Allerton, Monticello, IL, USA, pages 712--717, 2019. detected replay attacks by adding timestamp verification signals to the control input and improved the maximum detection rate and kept the process deterioration limited by optimizing the verification signals. The literature T. Li, Z. Wang, L. Zou, B. Chen, L. Yu, A dynamic encryption–decryption scheme for replay attack detection in cyber–physical systems, Automatica, 151, 110926, 2023. established a new replay attack model and developed a dynamic encryption and decryption scheme to effectively detect replay attacks while ensuring system performance. The literature M. Zhou, Z. Zhang, L. Xie, Permutation entropy based detection scheme of replay attacks in industrial cyber-physical systems, Journal of the Franklin Institute, 358(7): 4058–4076, 2021. proposed a replay attack detection scheme based on permutation entropy and used support vector data description to classify replay attacks.

[0007] When the quantization system faces replay attacks, how to design an effective attack detection scheme is an urgent problem to be solved. Summary of the Invention

[0008] In order to solve the problem that most of the existing studies on the security issues of CPS in the prior art are carried out from the perspectives of state estimation and controller design, and to solve the technical problem of attack detection under replay attacks for binary measurement FIR systems from the perspective of system identification, the embodiments of the present invention provide a replay attack detection method and system for binary measurement FIR system identification. The technical solutions are as follows:

[0009] On the one hand, a replay attack detection method for binary measurement FIR system identification is provided. This method is implemented by a replay attack detection system for binary measurement FIR system identification. The system includes an FIR subsystem, a binary sensor, a communication network, an estimation center, and a detector.

[0010] The method includes:

[0011] S1. The FIR subsystem obtains the input of the FIR subsystem and measures the output of the FIR subsystem through the binary sensor to obtain a measurement result.

[0012] S2. The communication network transmits the measurement result to the estimation center.

[0013] S3. The estimation center transmits the received data to the detector.

[0014] S4. The detector designs a replay attack detection algorithm based on the received data and the input of the FIR subsystem, and performs replay attack detection on the process of the communication network transmitting the measurement result to the estimation center according to the replay attack detection algorithm to obtain a replay attack detection result for binary measurement FIR system identification.

[0015] Optionally, the FIR subsystem in S1 is as shown in the following formula (1):

[0016] (1)

[0017] In the formula, is the output of the FIR subsystem; are the unknown parameters of the FIR subsystem, is the input period; is the input of the FIR subsystem, and the period of the FIR subsystem input is equal to the number of FIR subsystem parameters, is the time; is the noise of the FIR subsystem, which is set as an independent and identically distributed Gaussian random variable sequence; is the regression vector composed of the FIR subsystem inputs, is to find the transpose of a vector or matrix.

[0018] The optimal estimation algorithm for the unknown parameters of the FIR subsystem is as shown in the following formula (2):

[0019] (2)

[0020] In the formula, represents the estimated value of the unknown parameter of the FIR subsystem; , is a positive integer; is the inverse function of the FIR subsystem input matrix generated by ; is the threshold of the binary sensor; is the inverse function of the FIR subsystem noise probability distribution function ; is the data received at the estimated center at time.

[0021] Optionally, the measurement result in S1 is represented by an indicator function as shown in the following formula (3):

[0022] (3)

[0023] In the formula, is the measurement result represented by the indicator function; is the output of the FIR subsystem; is the threshold of the binary sensor, and I is the indicator function.

[0024] The relationship between the measurement result and the received data is as shown in the following formula (4):

[0025] (4)

[0026] In the formula, is the data received at the estimated center at time; is an integer constant; is the measurement result at time.

[0027] Optionally, the replay attack detection algorithm in S4 is as shown in the following formula (5):

[0028] (5)

[0029] In the formula, is the estimated value of the replay attack offline detection algorithm, is an integer constant; ; , is the estimated value of the probability that the attacker launches an attack, is the estimated value of the unknown parameter of the FIR subsystem .

[0030] Optionally, the replay attack detection algorithm in S4 includes a replay attack offline detection algorithm.

[0031] The replay attack offline detection algorithm includes:

[0032] S411. Based on the data received at the moment when the estimated center is , calculate , as shown in the following formula (6):

[0033] (6)

[0034] ,,, is a positive integer, is the input period, ;

[0035] S412. According to , calculate the estimated value of the replay attack offline detection algorithm, as shown in the following formula (7):

[0036] (7)

[0037] S413. According to the estimated value of the replay attack offline detection algorithm, determine whether the system is under a replay attack. If , it is determined that the system is under a replay attack; if , it is determined that the system is not under a replay attack.

[0038] Optionally, the replay attack detection algorithm in S4 further includes a replay attack online detection algorithm.

[0039] The replay attack online detection algorithm includes:

[0040] S421. Given an initial value ;

[0041] S422. Based on the data received at the moment when the estimated center is and calculate , as shown in the following formula (8):

[0042] (8)

[0043] In the formula, is the remainder of dividing by

[0044] S423. Calculate the estimated value of the replay attack online detection algorithm according to the as shown in the following formula (9):

[0045] (9)

[0046] S424. Determine whether the system is under a replay attack at the moment according to the estimated value of the replay attack online detection algorithm. If , it is determined that the system is under a replay attack; if , it is determined that the system is not under a replay attack.

[0047] Optionally, the designed replay attack detection algorithm in S4 further includes:

[0048] Analyze and evaluate the replay attack detection algorithm according to the miss detection rate and false detection rate of the replay attack detection algorithm.

[0049] On the other hand, a replay attack detection system for binary measurement FIR system identification is provided. This system is applied to the replay attack detection method for binary measurement FIR system identification. The system includes: an FIR subsystem, a binary sensor, a communication network, an estimation center, and a detector.

[0050] Wherein:

[0051] The FIR subsystem is used to obtain the FIR subsystem input and obtain the FIR subsystem output.

[0052] The binary sensor is used to measure the output of the FIR subsystem to obtain a measurement result.

[0053] The communication network is used to transmit the measurement result to the estimation center.

[0054] The estimation center is used to transmit the received data to the detector.

[0055] The detector is used to design a replay attack detection algorithm according to the received data and the FIR subsystem input, and perform replay attack detection on the process of the communication network transmitting the measurement result to the estimation center to obtain the replay attack detection result for binary measurement FIR system identification.

[0056] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:

[0057] In the embodiments of the present invention, aiming at how to design an effective attack detection scheme for the quantization system facing replay attacks, the present invention aims to propose an innovative security solution to ensure the robustness of CPSs in a cyber attack environment. Taking the quantization FIR system as the object, starting from the perspective of system identification, the present invention studies the detectability problem of replay attacks, and detects replay attacks by increasing the input excitation and combining with the designed algorithm. More specifically, by establishing a replay attack model, the definition of the detectability of replay attacks is given according to the optimal estimation algorithm; according to the impact of replay attacks on system performance, appropriate detection indicators are selected, and algorithms for calculating detection indicators and two forms of detection methods, namely offline and online, are designed. By increasing the input excitation, a calculation method for detection indicators is given, and an implementation scheme for the detection algorithm is designed; taking the false positive rate and the false negative rate as the performance measurement indicators of the detection algorithm, the influencing factors of the detection algorithm effect are studied. Finally, the rationality of the proposed detection algorithm is verified through numerical simulations. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0059] Figure 1 It is a flowchart of a replay attack detection method for binary measurement FIR system identification provided by an embodiment of the present invention;

[0060] Figure 2 It is a schematic diagram of an offline detection algorithm provided by an embodiment of the present invention;

[0061] Figure 3 It is a schematic diagram of an online detection algorithm provided by an embodiment of the present invention;

[0062] Figure 4 It is the relationship between the false positive rate and the number of experiments provided by an embodiment of the present invention;

[0063] Figure 5 It is the relationship between the false negative rate and the number of experiments provided by an embodiment of the present invention;

[0064] Figure 6 It is the relationship between the false positive rate and the data length provided by an embodiment of the present invention;

[0065] Figure 7 It is the relationship between the false negative rate and the data length provided by an embodiment of the present invention;

[0066] Figure 8It is the relationship between the false negative rate and the attack strategy provided by the embodiments of the present invention;

[0067] Figure 9 It is a block diagram of a replay attack detection system for binary measurement FIR system identification provided by the embodiments of the present invention;

[0068] Figure 10 It is a schematic structural diagram of a replay attack detection device provided by the embodiments of the present invention. Detailed implementation manners

[0069] The technical solutions in the present invention will be described below with reference to the accompanying drawings.

[0070] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or more advantageous than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either of the two can be selected.

[0071] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.

[0072] In the embodiments of the present invention, sometimes subscripts such as W1 may be expressed in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.

[0073] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0074] The embodiments of the present invention provide a replay attack detection method for binary measurement FIR system identification. This method can be implemented by a replay attack detection system for binary measurement FIR system identification. The system includes an FIR subsystem, a binary sensor, a communication network, an estimation center, and a detector. As Figure 1 shown in the flowchart of the replay attack detection method for binary measurement FIR system identification, the processing flow of this method can include the following steps:

[0075] S1. The FIR (Finite Impulse Response) subsystem obtains the input of the FIR subsystem and measures the output of the FIR subsystem through a binary sensor to obtain the measurement result.

[0076] In a feasible implementation, in S1, a single-input single-output FIR system is considered, as shown in the following formula (1):

[0077] (1)

[0078] In the formula, is the output of the subsystem, measured by a binary sensor with a threshold of ; is the unknown parameter of the subsystem, is the input period; is the input of the subsystem, and the period of the subsystem input is equal to the number of subsystem parameters, is the time; is the subsystem noise, set as a sequence of independent and identically distributed Gaussian random variables; is a regression vector composed of subsystem inputs, is to find the transpose of a vector or matrix.

[0079] Optionally, the measurement result in S1 is represented by an indicator function, as shown in the following formula (2):

[0080] (2)

[0081] In the formula, is the measurement result represented by the indicator function; is the output of the subsystem; is the threshold of the binary sensor.

[0082] Furthermore, is transmitted to the estimation center through a network / communication channel, but it may be subject to data replay attacks during the transmission. The data received by the estimation center at time is denoted as . If an attack occurs at time, then there is ; otherwise, there is , where is an integer constant. Therefore, the relationship between and is as shown in the following formula (3):

[0083] (3)

[0084] Furthermore, at each time, the probability of the attacker launching an attack is , that is, The replay attack described by Equation (3) is briefly denoted as .

[0085] The task of the detector is to design a replay attack detection algorithm based on the system input and the data received by the estimation center to identify the occurrence of a replay attack.

[0086] For system (1), denote . If the system input is periodic with as the period, that is, the input period is equal to the number of system parameters, there is and , and there is also . From , the generated input matrix is:[[]]

[0087] (4)

[0088] For a certain positive integer , the length of the observed data is . Then, the optimal (in the sense of Cramér-Rao) estimation algorithm for the unknown parameter is shown in the following Equation (5):

[0089] (5)

[0090] In the formula, represents the estimated value of the unknown parameter of the subsystem; , is a positive integer; is the inverse function of the FIR subsystem input matrix generated by ; is the threshold of the binary sensor; is the inverse function of the FIR subsystem noise probability distribution function .

[0091] When there is no replay attack on the system, there must be an attack strategy ; when a replay attack occurs on the system, then there is . However, when and ( , represents the set of natural numbers), that is is an integer multiple of the input period , the impact of the attack on the system is very small. The explanation is as follows:

[0092] According to Equation (2) and Equation (3), it can be obtained that:

[0093] (6)

[0094] Among them, represents the mathematical expectation of the random variable .

[0095] Since is a periodic input, then there is:

[0096] (7)

[0097] According to the law of large numbers, it can be obtained that:

[0098] (8)

[0099] Among them, . At this time, in formula (5), that is, the attack will not damage the performance of the estimation algorithm, and in formula (7) is consistent with the result without attack. From a statistical point of view, the impact of the attack on the system is very small or even zero. Based on the above explanation, the definition of the detectability of the replay attack is given as follows.

[0100] Definition 3.1 For the given system (1) and the optimal estimation algorithm (5), a network attack is called detectable or has detectability if, when the amount of data is sufficiently large, the attack can change the mathematical expectation of the output data, or damage in the optimal estimation algorithm (5).

[0101] According to the above analysis, it can be found that has no direct relationship with whether an attack occurs. According to the characteristics of the input period, if the value of is restricted to , then the value of can be used as a basis for judging whether an attack occurs, that is, when , it is considered that there is no replay attack on the system; when , it is considered that a replay attack has occurred on the system. Therefore, is selected as the detection index for judging the occurrence of the replay attack.

[0102] S2. The communication network transmits the measurement results to the estimation center.

[0103] S3. The estimation center transmits the received data to the detector.

[0104] S4. The detector designs a replay attack detection algorithm according to the received data and the subsystem input, and performs replay attack detection on the process of the communication network transmitting the measurement results to the estimation center according to the replay attack detection algorithm, and obtains the replay attack detection result for the identification of the binary measurement FIR system.

[0105] In a feasible implementation, according to the analysis, if the detector can know 's value, then it can judge the occurrence of a replay attack. In practice, however, the detector often does not know the attacker's attack strategy. Changing the perspective, if the detector obtains an estimated value of through designing relevant schemes, and uses as a detection index, the detection of replay attacks can also be carried out. Next, research is carried out around this problem to give 's acquisition method.

[0106] Specifically, increase the minimum positive period of the system input sequence to , that is, there is ( , represents the set of integers). Denote , and there is also .

[0107] Let be unknowns, and denote , and consider the following system of equations:

[0108] (9)

[0109] Hypothesis 3.1 There exists a compact set such that is an interior point of it, where:

[0110] (10)

[0111] For any , the system of equations (9) has a unique solution, which is denoted as . Moreover, is bounded and continuous at the point .

[0112] Given the data length , design an algorithm for estimating the attack strategy and the unknown parameters of the system as follows:

[0113] (11)

[0114] where, ; represents the estimated value of ; represents the estimated value of ; represents the estimated value of .

[0115] Theorem 3.1 For system (1) and binary measurement (2), if it is subject to the data replay attack described by (3) , and assuming that Assumption 2.1 and Assumption 3.1 hold, then in algorithm (11) .

[0116] Proof: Let . According to (2) and (3), we have

[0117] (12)

[0118] According to the periodicity of the input period and the law of large numbers, we know that

[0119] (13)

[0120] From equation (9), we get

[0121] (14)

[0122] Under the condition of Assumption 3.1 .

[0123] The theorem is proved.

[0124] According to Theorem 3.1, the attack detection algorithm is established as follows

[0125] (15)

[0126] where is the estimated value of , is an integer constant ; , , , is a positive integer , is the input period is the data received at the estimated center at time is to find the transpose of a vector or matrix

[0127] Optionally, the replay attack detection algorithm in S4 includes an offline replay attack detection algorithm

[0128] As Figure 2 shown, for the data length , the detector designs an attack detection algorithm based on the available information of the estimated center :

[0129]

[0130] Optionally, the replay attack detection algorithm in S4 further includes an online replay attack detection algorithm.

[0131] As Figure 3 shown, the online replay attack detection algorithm includes:

[0132]

[0133] Optionally, the designed replay attack detection algorithm in S4 further includes:

[0134] Analyze and evaluate the replay attack detection algorithm according to the miss detection rate and false detection rate of the replay attack detection algorithm.

[0135] In a feasible implementation, ideally the probability of detecting a replay attack is 1. However, affected by the highly non-linear binary quantization, the attack detection rate will be reduced accordingly. To effectively measure the effectiveness of the attack detection algorithm, the present invention calculates the miss rate and false rate according to the asymptotic normality of parameter estimation and uses them as indicators to measure the effectiveness of the detection algorithm.

[0136] Specifically, Lemma 4.1 If d-dimensional random variable obeys the normal distribution , then obeys the normal distribution , where is d-dimensional constant matrix, is k-dimensional constant vector.

[0137] The judgment results of the detection scheme can be divided into two categories. One is that the results given by the detection index are in line with the actual situation; the other is not in line with the actual situation, that is, false judgment and miss judgment. The false judgment rate can be understood as that the system is not actually attacked, but the results given by the detection index think there is an attack; the miss judgment rate is that the system is actually attacked, but the results given by the detection index think there is no attack.

[0138] Definition 4.1 Given the data length , the false judgment rate of an attack detection algorithm refers to the probability that the system is not attacked, but the algorithm judges that the system is attacked, denoted as ; the miss judgment rate refers to the probability that the system is attacked, but the algorithm judges that the system is not attacked, denoted as .

[0139] To calculate and , first discuss 's asymptotic normality.

[0140] Theorem 4.1 Under the conditions of Theorem 3.1, the given by algorithm (11) Estimated value is asymptotically normal, specifically:

[0141] Ⅰ. If the system is not under a data replay attack, then:

[0142] (20)

[0143] ; ; ; represents a diagonal matrix; ; represents the value of the derivative function of the vector function at ; represents convergence in distribution, .

[0144] Ⅱ. If the system is under a replay attack , then:

[0145] (21)

[0146] ; , .

[0147] Proof: When the system is under a replay attack, according to the law of large numbers, we have:

[0148] (22)

[0149] Note that is distribution, then . By the central limit theorem, we get:

[0150] (23)

[0151] According to the properties of the normal distribution, we have:

[0152] (24)

[0153] From Theorem 3.1 and the differential mean value theorem, we can obtain:

[0154] (25)

[0155] where the vector is between and .

[0156] When When . From (24), we can obtain:

[0157] (26)

[0158] From equation (25) and Lemma 4.1, equation (21) is proven.

[0159] When the system is not under attack, in (21), let , and (20) is proven.

[0160] Since is an integer, in order to better reflect 's probability distribution, further processing of in the formula and the normal distribution is required. In the following analysis, take as an integer.

[0161] Definition 4.2 For and , the discrete Gaussian distribution with mean and variance is denoted as , which is a discrete distribution obtained by shrinking the normal distribution to all integer values, and has the probability:

[0162] (27)

[0163] where is the probability density of the standard normal distribution.

[0164] Definition 4.3 Definition of the probability density of the truncated normal distribution: If follows the normal distribution , when , 's probability density is:

[0165] (28)

[0166] where is the probability density of the standard normal distribution.

[0167] According to Definition 4.1, and 's calculation methods are respectively:

[0168] (29)

[0169] At , , considering , according to the characteristics of the input period, Theorem 4.1, Definition 4.2 and Definition 4.3, and can be expressed as:

[0170] (30)

[0171] The magnitudes of the false positive rate and the false negative rate determine the actual effectiveness of the detection algorithm. According to the calculation formulas for the false positive rate and the false negative rate, it can be found that their magnitudes are determined by multiple factors. This invention focuses on discussing the influence of factors such as data length and attack strategy on the false positive rate and the false negative rate of the detection algorithm.

[0172] Specifically, the influence of data length on the detection effect:

[0173] First, discuss the influence of data length on the false positive rate. From (30), it can be known that:

[0174] (31)

[0175] Let , according to the derivative of the variable limit integral function, thus there is:

[0176] (32)

[0177] Among them, ; ; . For the function , when is sufficiently large, there is , so there is , and because , so . Therefore, when , the false positive rate decreases as the data length increases.

[0178] Next, discuss the influence of data length on the false negative rate. From (30), it can be known that:

[0179] (33)

[0180] Let , thus there is:

[0181] (34)

[0182] Among them, ; ; . For the function , when is sufficiently large, there is , so there is , and because , so . Therefore, when When it is, the false negative rate decreases as the data length $N$ increases.

[0183] Furthermore, the attacker hopes that the attacks launched against the system can avoid the detection algorithm as much as possible. When setting the attack strategy it is necessary to make the false negative rate of the detection algorithm as large as possible. Therefore, the relationship between the false negative rate and the attack strategy will be discussed next.

[0184] Fix , from Equation (34), we get

[0185] (35)

[0186] Since , so and have the same sign, that is, the false negative rate and have the same monotonicity with respect to .

[0187] From (21), we can get:

[0188] (36)

[0189] Among them, is the element in the second row and the th column of the matrix . Take , at this time, it can be considered that , so we have:

[0190] (37)

[0191] That is:

[0192] (38)

[0193] Then:

[0194] (39)

[0195] There is also:

[0196] (40)

[0197] Since always holds, so is a monotonically decreasing function. Therefore, the monotonicity of with respect to is mainly determined by the values of and . At the same time, the value of also determines For the symbols, according to the above analysis, the conclusion 1 can be obtained:

[0198] Conclusion 1 The attack strategy for and the false negative rate has the following impacts:

[0199] If makes always hold, then and the false negative rate are increasing functions of ;

[0200] If makes always hold, then and the false negative rate are decreasing functions of ;

[0201] If makes always hold, then and the false negative rate are convex functions of and reach the maximum value at ;

[0202] If makes , then and the false negative rate are independent of the attack strategy .

[0203] Since the false negative rate and have the same monotonicity with respect to , therefore, when changes, the maximum value of the false negative rate, denoted as , can be calculated by the following formula:

[0204] (41)

[0205] Since , denote when, the maximum value of the false negative rate is , and the attack strategy corresponding to the maximum value is denoted as , which is calculated from (41). Therefore, and when, the maximum value of the false negative rate is:

[0206] (42)

[0207] Among them, represents The one corresponding to the maximum value in . Obtained when the attacker sets the attack strategy .

[0208] Numerical simulation:

[0209] Consider a single-input single-output third-order discrete-time system:

[0210] (43)

[0211] where the system input is periodic with a minimum positive period of 3, and the values within one period are ; the unknown parameter ; the binary sensor threshold ; the noise and satisfies Assumption 2.1. Subject to replay attack during transmission to the estimation center .

[0212] Calculation of false positive rate and missed detection rate:

[0213] Increase the minimum positive period of the system input to 5, and the values within one period are . Take the data length . Conduct trials on the detection algorithm. The -th obtained estimation sequence is denoted as: , considering the case where the system is not subject to replay attack, i.e., , use to approximate the false positive rate; then, set the attack strategy , use to approximate the missed detection rate. The results are as shown in Figure 4 and Figure 5 . It can be seen from the figure that as the number of experiments increases, at the given data length , the false positive rate and missed detection rate of the detection algorithm approach the values calculated by (30).

[0214] Factors affecting the performance of the detection algorithm:

[0215] Effect of data length on the detection effect:

[0216] First, consider the case where the system is not attacked, i.e., ; then, set the attack strategy . Conduct one trial on the detection algorithm to obtain the estimation sequence as , and use and to represent the false positive rate and false positive rate The experimental results are as Figure 6 and Figure 7 shown. It can be seen from the figure that as the data length increases, both the false positive rate and the false negative rate of the detection algorithm gradually decrease.

[0217] Influence of attack strategy on detection effect:

[0218] Take respectively and at the same time take to make vary from to 1. Draw the curve of the false negative rate with respect to the attack strategy as Figure 8 . It can be seen from Figure 8 that when , the false negative rate is a convex function with respect to and reaches the maximum value at ; when and , the false negative rate is a decreasing function with respect to ; when , the false negative rate is approximately independent of the attack strategy . This is consistent with Conclusion 1. When , the false negative rate reaches the maximum value.

[0219] When the quantization system faces replay attacks, how to design an effective attack detection scheme is an urgent problem to be solved. The present invention takes the quantized FIR system as the object, starts from the perspective of system identification, gives the definition of the detectability of replay attacks, selects appropriate detection metrics according to the impact of replay attacks on system performance, and at the same time designs the calculation scheme of the detection metrics. Using the false positive rate and the false negative rate as the performance metrics of the detection algorithm, the influence of data length and attack strategy on the detection effect is studied.

[0220] The attack detection algorithm proposed by the present invention is based on the replay attack model and the characteristics of the quantization system, and has certain practicality and feasibility. In CPSs, the quantized communication system is a very important part, so the present invention can be applied to practical systems to improve the security and stability of the systems.

[0221] In the embodiments of the present invention, aiming at how to design an effective attack detection scheme for the quantization system in the face of replay attacks, the present invention aims to propose an innovative security solution to ensure the robustness of CPSs in a cyber attack environment. Taking the quantized FIR system as the object, starting from the perspective of system identification, the present invention studies the detectability of replay attacks, and combines the designed algorithm by increasing the input excitation to detect replay attacks. More specifically, by establishing a replay attack model, the definition of the detectability of replay attacks is given according to the optimal estimation algorithm; according to the impact of replay attacks on system performance, appropriate detection metrics are selected, and algorithms for calculating detection metrics and two forms of detection methods, namely offline and online, are designed. By increasing the input excitation, a method for calculating detection metrics is given, and an implementation scheme of the detection algorithm is designed; taking the false positive rate and the false negative rate as the performance metrics of the detection algorithm, the influencing factors of the detection algorithm effect are studied. Finally, the rationality of the proposed detection algorithm is verified through numerical simulations.

[0222] Figure 9 FIG. 4 is a block diagram of a replay attack detection system for binary measurement FIR system identification shown according to an exemplary embodiment. This system is used for the replay attack detection method for binary measurement FIR system identification. Referring to Figure 9 FIG. 4, the system includes: an FIR subsystem, a binary sensor, a communication network, an estimation center, and a detector. Among them:

[0223] The FIR subsystem is used to obtain the input of the FIR subsystem and obtain the output of the FIR subsystem.

[0224] The binary sensor is used to measure the output of the FIR subsystem to obtain a measurement result.

[0225] The communication network is used to transmit the measurement result to the estimation center.

[0226] The estimation center is used to transmit the received data to the detector.

[0227] The detector is used to design a replay attack detection algorithm according to the received data and the input of the FIR subsystem, and according to the replay attack detection algorithm, perform replay attack detection on the process of the communication network transmitting the measurement result to the estimation center, and obtain the replay attack detection result for binary measurement FIR system identification.

[0228] In the embodiments of the present invention, aiming at how to design an effective attack detection scheme for the quantization system in the face of replay attacks, the present invention aims to propose an innovative security solution to ensure the robustness of CPSs in a cyber attack environment. Taking the quantization FIR system as the object, starting from the perspective of system identification, the present invention studies the detectability problem of replay attacks, and detects replay attacks by increasing the input excitation and combining with the designed algorithm. More specifically, by establishing a replay attack model, a definition of the detectability of replay attacks is given according to the optimal estimation algorithm; according to the impact of replay attacks on system performance, appropriate detection metrics are selected, and an algorithm for calculating the detection metrics and two forms of detection methods, namely offline and online, are designed. By increasing the input excitation, a calculation method for the detection metrics is given, and an implementation scheme of the detection algorithm is designed; taking the false positive rate and the false negative rate as the performance metrics of the detection algorithm, the influencing factors of the detection algorithm effect are studied. Finally, the rationality of the proposed detection algorithm is verified by numerical simulation.

[0229] Figure 10 FIG. is a schematic structural diagram of a replay attack detection device provided by an embodiment of the present invention. As Figure 10 shown, the replay attack detection device may include the above Figure 9 shown replay attack detection system for binary measurement FIR system identification. Optionally, the replay attack detection device 1010 may include a first processor 2001.

[0230] Optionally, the replay attack detection device 1010 may further include a memory 2002 and a transceiver 2003.

[0231] Among them, the first processor 2001, the memory 2002, and the transceiver 2003 may be connected through a communication bus, for example.

[0232] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A replay attack detection method for binary measurement FIR system identification, characterized in that: The method is implemented by a replay attack detection system for binary measurement FIR system identification, the system comprising an FIR subsystem, a binary sensor, a communication network, an estimation center and a detector; The method comprises: S1, the FIR subsystem obtains the FIR subsystem input, and measures the FIR subsystem output through the binary sensor to obtain a measurement result; S2, the communication network transmits the measurement result to the estimation center; S3, the estimation center transmits the received data to the detector; S4, the detector designs a replay attack detection algorithm according to the received data and the FIR subsystem input, and performs replay attack detection on the process of the communication network transmitting the measurement result to the estimation center according to the replay attack detection algorithm, to obtain a replay attack detection result for binary measurement FIR system identification; The replay attack detection algorithm in S4 is shown in the following formula (5): In the formula, is the estimated value of the replay attack offline detection algorithm; G = [0, 1, 0, ..., 0] T ; T is the transpose of a vector or matrix; is the estimated value of the probability that the attacker launches an attack, is the estimated value of the unknown parameter θ of the FIR subsystem.

2. The replay attack detection method for binary measurement FIR system identification according to claim 1 is characterized in that: The FIR subsystem in S1 is shown in the following equation (1): In the formula, y k is the output of the FIR subsystem; θ = [θ1, θ2, ..., θ n ] T is the unknown parameter of the FIR subsystem, n is the input period; u k is the input of the FIR subsystem, the period of the FIR subsystem input is equal to the number of FIR subsystem parameters, k is the time; d k is the FIR subsystem noise, which is set as an independent and identically distributed Gaussian random variable sequence; φ k =[u k , ..., u k-b+1 ] T is the regression vector composed of the input of the FIR subsystem, T is the transpose of the vector or matrix to be sought; The optimal estimation algorithm for the unknown parameters of the FIR subsystem is shown in the following formula (2): Where, N = nL, L→∞ is a positive integer; Φ -1 Because {u k } is the inverse function of the FIR subsystem input matrix generated; C is the threshold of the binary sensor; Ψ -1 is the inverse function of the FIR subsystem noise probability distribution function Ψ(·); s (k-1)n+i is the data received by the estimation center at time (l-1)n+i.

3. The replay attack detection method for binary measurement FIR system identification according to claim 1, characterized in that: The measurement result in S1 is represented by an indicative function, as shown in the following formula (3): In the formula, is the measurement result represented by the indicative function; k is the output of the FIR subsystem; C is the threshold of the binary sensor, and I is the indicative function; The relationship between the measurement result and the received data is shown in the following formula (4): In the formula, s k is the data received by the estimation center at time k; τ is an integer constant; is the measurement result at the k-τ moment.

4. The replay attack detection method for binary measurement FIR system identification according to claim 1, characterized in that: The replay attack detection algorithm in S4 includes a replay attack offline detection algorithm; The replay attack offline detection algorithm includes: S411, based on the data s received by the estimation center at time k k , calculate ζ N,i , as shown in the following formula (6): N=nL, L→∞ is a positive integer, n is the input period, S412, according to the N,i , calculate the estimated value of the replay attack offline detection algorithm As shown in the following formula (7): S413: Estimating a value based on the replay attack offline detection algorithm Determine whether the system has been attacked by a replay attack. If The system is judged to be under replay attack; if It is determined that the system has not been attacked by replay.

5. The replay attack detection method for binary measurement FIR system identification according to claim 1, characterized in that: The replay attack detection algorithm in S4 also includes a replay attack online detection algorithm; The replay attack online detection algorithm includes: S421, given initial value n is the input cycle; S422, based on the data s received by the estimation center at time k k and χ k-1,i Calculate χ k,i , as shown in the following formula (8): In the formula, k divided by The remainder of , I is the characteristic function; S423, according to the x k,i , calculate the estimated value of the replay attack online detection algorithm As shown in the following formula (9): S424: Estimating a value based on the replay attack online detection algorithm Determine whether the system is under replay attack at time k. If The system is judged to be under replay attack; if It is determined that the system has not been attacked by replay.

6. The replay attack detection method for binary measurement FIR system identification according to claim 1, characterized in that: The design replay attack detection algorithm in S4 further includes: The replay attack detection algorithm is analyzed and evaluated based on its missed detection rate and false detection rate.

7. A replay attack detection system for binary measurement FIR system identification, the replay attack detection system for binary measurement FIR system identification is used to implement the replay attack detection method for binary measurement FIR system identification as claimed in any one of claims 1 to 6, characterized in that: The system comprises: a FIR subsystem, a binary sensor, a communication network, an estimation center and a detector; in: The FIR subsystem is used to obtain the FIR subsystem input and obtain the FIR subsystem output; The binary sensor is used to measure the output of the FIR subsystem to obtain a measurement result; The communication network is used to transmit the measurement result to the estimation center; The estimation center is used to transmit the received data to the detector; The detector is used to design a replay attack detection algorithm based on the received data and the FIR subsystem input, and based on the replay attack detection algorithm, perform replay attack detection on the process of the communication network transmitting the measurement result to the estimation center to obtain a replay attack detection result for binary measurement FIR system identification.

8. A replay attack detection device, characterized in that: The replay attack detection device comprises: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, which can be called by a processor to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data tampering attack detection method and system for binary quantization FIR (Finite Impulse Response) system

    CN114741687A