A data-driven replay attack detection method for equivalent space-based industrial control systems
By using a data-driven equivalence space method to detect replay attacks, this method solves the problems of dependence on system model parameters and difficulty in hardware modification in existing technologies, and achieves stable and low-cost detection of industrial control systems, thereby improving detection performance.
Patent Information
- Application Number
- CN202411325086.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-09-23
AI Technical Summary
Existing replay attack detection methods heavily rely on system model parameters that are difficult to obtain, or they face difficulties in hardware modification during deployment. They cannot maintain the performance of the control system in real time and impose a hardware burden, thus failing to effectively detect replay attacks in industrial control systems.
A data-driven replay attack detection method based on equivalence space is adopted. By setting the equivalence space order and the length of historical data groups, input and output data are obtained, equivalence matrices are identified, residuals are generated using chi-square test and generalized likelihood ratio test, and a threshold is set to detect replay attacks. This avoids dependence on system models and maintains low deployment costs and control performance.
It achieves effective detection of replay attacks on industrial control systems, improves detection performance, relies on historical data of equipment operation, does not require system model parameters, maintains stable system operation, and avoids hardware modification and performance loss.
Smart Images

Figure CN119316190B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of industrial process status monitoring technology, and in particular relates to a data-driven method for detecting replay attacks on industrial control systems based on equivalence space. Background Technology
[0002] Industrial processes commonly employ distributed control systems (DCS) or supervisory control and data acquisition and monitoring systems (SCADA). These industrial control systems adopt a multi-level, hierarchical, cooperative, and autonomous structure, and have been widely used in various industries such as power, metallurgy, and petrochemicals.
[0003] With the deepening of intelligent manufacturing and the rapid development of the Industrial Internet, the cybersecurity risks of industrial control systems are becoming increasingly severe. On the one hand, due to their functional importance, industrial control systems have become popular targets for cyberattacks; on the other hand, because the underlying hardware of current industrial control systems is generally low in intelligence and capability, the acceptance of large-scale hardware upgrades is low, and traditional information security encryption and decryption schemes cannot be directly used for the security protection of industrial control systems. This makes some covert cyberattack methods, especially replay attacks, difficult to detect.
[0004] Replay attacks can be achieved by tampering with measurement data during the operation of industrial equipment. Related residual detection techniques detect attacks by determining whether real-time measurement data conforms to the distribution of historical data. However, attackers can use data collected during normal equipment operation, rendering this method ineffective. Currently, replay attack detection can be categorized into model-based and non-model-based methods based on whether system model knowledge is known. Model-based detection techniques, such as watermark-based replay attack detection, require sacrificing control system performance, and the watermark signal places a significant burden on control system actuators, shortening equipment lifespan. Another sliding target replay attack detection method amplifies replay attack features by real-time modification of control system hardware, but this method requires large-scale hardware modifications and has poor physical feasibility. A simple and effective method is equivalence space-based replay attack detection, which uses equivalence space to generate residuals from the system time series and examines these residuals to indirectly verify the replay attack. However, these model-based detection methods heavily rely on accurate model parameters, which are generally difficult to obtain in complex industrial systems. Model-independent replay attack detection schemes, such as dynamic data encryption, are easy to implement but have high requirements for synchronization and encryption functions.
[0005] In summary, existing detection methods heavily rely on system model parameters that are difficult to obtain in practice or face significant challenges in actual deployment. They also suffer from limitations such as the inability to maintain the performance of the control system and the integrity of the hardware in real time, or the inability to escape the constraints of hardware investment and modification in the control system. Summary of the Invention
[0006] To address the aforementioned issues, this invention proposes a data-driven replay attack detection method for industrial control systems based on equivalent space. This method eliminates the dependence on system model parameters, maintains low deployment costs, does not compromise control system performance, and does not shorten the lifespan of control system hardware. It enables the detection of replay attacks on industrial control systems and ensures the continuous and stable operation of industrial control systems.
[0007] To achieve the above objectives, the technical solution adopted by this invention is: a data-driven method for detecting replay attacks on industrial control systems based on equivalence space, comprising the following steps:
[0008] S1: Set the order s of the equivalent space, the group length K of the historical data, and obtain the input and output data for 2 (s+K) consecutive time steps from the industrial control system;
[0009] S2: Select whether to perform partial model information enhancement on the detection scheme; if yes, set the critical model parameters and construct new input and output data based on historical input and output data; if no, there is no need to reconstruct new input and output data, and the original input and output data can be used directly.
[0010] S3: Identify the equivalent matrix based on the input and output data, use the equivalent matrix and the input and output data to obtain the residuals, and obtain the chi-square test and the generalized likelihood ratio test, and determine the residual threshold and the generalized likelihood ratio test threshold respectively.
[0011] S4: Based on the original system identification, some model information is directly introduced to enhance the detection method; the critical stability filter parameters to be introduced are set, and then the equivalent matrix after partial model enhancement and the new residual threshold are calculated according to the equivalent matrix transformation method.
[0012] S5: Deploy the existing detection system, acquire the system's input and output online, generate residuals, and use the chi-square test and generalized likelihood ratio test to judge the system's operating status; when the test value is greater than the residual threshold, it is judged to be under replay attack and an alarm is issued.
[0013] Furthermore, in step S1, the initialization includes: modeling a discrete linear time-invariant system of a general industrial control system, with inputs and outputs u and y; and acquiring input and output data for 2 (s+K) consecutive time steps from the industrial control system based on the selected equivalent space order s and the length of the historical data set K.
[0014] Furthermore, in step S2, if the option is yes, the critical stability filter parameter A is first set. ζ With B ζ Using this model knowledge, new input and output data are constructed based on historical input and output data.
[0015] Furthermore, in step S2, the partial model information enhancement includes the following steps:
[0016] If partial model information enhancement is performed on the detection scheme, then a critically stable filter configuration is selected, requiring A... ζ It is the critical stability matrix, and B ζ Given a full-rank matrix, using the original input and output u and y, generate new input and output as follows:
[0017]
[0018] in: It is the new system input at time k, which is numerically equal to the original system input u(k); The output of the new system at time k is the critically stable filter parameter A. ζ B ζ Construct it from the original system output y(k); It is the output of the new system at time k-1.
[0019] Furthermore, in S3, the nullification matrix N is identified based on the input and output data obtained in S2. s With product N s H u,s Select an optimization index J i The corresponding weight matrix M is estimated using a data-driven approach. s The weight matrix M s With the null matrix N s Multiplying them yields the equivalent matrix Z. s =M s N s The residuals are obtained using the equivalent matrix and the input / output data.
[0020] Remember r s (k) represents the residual generated by the system at time k:
[0021]
[0022] in:
[0023]
[0024] H u,s It is the input transfer matrix, U s (k) is the system input matrix, Ys (k) is the system output matrix. It is the kernel representation of the original system; u(k) is the input vector of the system at time k, and y(k) is the output vector of the system at time k.
[0025] Based on this, a chi-square test was designed. Generalized likelihood ratio test And determine the chi-square test residual thresholds respectively. The threshold J for the generalized likelihood ratio test th,LR .
[0026] Furthermore, in step S3, the nullification matrix identification includes:
[0027] First, obtain the input and output, including the original input and output or the newly constructed input and output, denoted as u and y, and arrange them into a matrix in the following form:
[0028]
[0029] Where: Φ k,s It is the system input and output data matrix at time k, which is obtained by arranging the system input u and system output y obtained in the previous step in a specific way; parameter s is the order of the equivalent space, and parameter K is the group length of the historical data;
[0030] Next, perform SVD decomposition:
[0031]
[0032] in: It is the transpose of the input and output data matrices at time k-ε-1; after SVD decomposition, the left singular matrix [U1 U2] and the right singular matrix are obtained. and singular value matrix
[0033] U1 is the first part of the left singular matrix, and U2 is the second part of the left singular matrix. This is the transpose of the first part of the right singular matrix. ∑1 is the transpose of the latter part of the right singular matrix, ∑2 is the former part of the singular value matrix, and ∑1 is the latter part of the singular value matrix.
[0034] Finally, after decomposition, taking ∑2 approximately as 0, we obtain the corresponding U2, then:
[0035]
[0036] When splitting: Then the null matrix
[0037] in, The intersection of the state transfer matrices To output the equivalent matrix, The input is an equivalent matrix.
[0038] Furthermore, in step S3, the data-driven weight matrix includes...
[0039] Different weight matrix designs are used for different optimization metrics.
[0040] Positive definite part optimization, corresponding weight matrix M s For: M s =Λ -1 U T ;
[0041] Among them, Λ and U are derived from SVD decomposition. Let V be the covariance matrix of the residuals under normal conditions, U be the left singular matrix, Λ be the non-zero singular value matrix, and V be the non-zero singular value matrix. T This is the transpose of a right singular matrix;
[0042] The cumulative total ratio is optimized to yes The maximum generalized eigenvector; therefore, the parameter T is solved. Δ,Σ and Then various weight matrices can be calculated;
[0043] in, It is the weight matrix M s = covariance of residuals when I; while T Δ,∑ The weight matrix M is the result of a replay attack. s =I represents the change in the residual covariance;
[0044] remember For the system in k i The residual at each time step when subjected to a replay attack, where the replay attack occurs at the α-th time step of the detection window, i.e.
[0045] This is the input matrix for a replay attack. This is the output matrix during a replay attack;
[0046] in:
[0047] Where: τ is the time of data replay, and s is the order of the equivalent space;
[0048] Repeat this replay attack n t Wheel, calculation:
[0049]
[0050] in: Is the system in k i The residual when constantly subjected to replay attacks It is the covariance of the system residuals when no replay attack is received, n t It is the number of observations of the residuals in the generalized likelihood ratio test;
[0051] Further statistics:
[0052]
[0053] in: The change in residual covariance is caused by the replay attack occurring at time α within the detection window. It is the average change of the residual covariance over the s time points in the detection window.
[0054] Furthermore, in step S3, the residual detection method includes:
[0055] Chi-square test Generalized likelihood ratio test To enable the detection of residuals;
[0056] Based on weight matrix M s The statistical properties of the system residuals are as follows:
[0057] Where, Θ s It is the covariance matrix of the system residuals. The representative value is 0, and the covariance is Θ. s Gaussian distribution;
[0058] Define the chi-square test:
[0059]
[0060] Define the generalized likelihood ratio test:
[0061]
[0062] in
[0063] Where, n r It represents the number of observations of the residuals in the generalized likelihood ratio test, det is the determinant operation, and r s (ki) represents the residual at time ki.
[0064] Furthermore, in step S4: if the original system identification was performed (i.e., no new input / output data was constructed in S2, and the original input / output data was used for identification in S3), then through this step, some model information can be directly introduced to enhance the detection method based on the original system identification, without repeating the identification work, thus maintaining low computational load. First, the critically stable filter parameter A to be introduced is set. ζ With B ζ Then, the nullification matrix after partial model enhancement is calculated using the equivalent matrix transformation method. The new residual covariance is calculated based on the residual relationship, and the new weight matrix is derived. And calculate the new equivalent matrix. With the new residual threshold;
[0065] In step S4, enhancing the original system with partial model information includes the following steps:
[0066] Select the critical stability matrix A ζ With full-rank matrix B ζ And construct the following matrix:
[0067]
[0068] Solving the equation yields matrix D: The new nullification matrix is then: The residual generation of a partial model information augmentation system can then be expressed as: in Furthermore, for the estimated values of the residual covariance of the partially enhanced system model, we have: This is the new weight matrix.
[0069] Furthermore, in step S5, the equivalent space residual sensing alarm strategy includes the following steps:
[0070] The M involved in the original equivalent space replay attack detection scheme s , U s (k) and Y s (k), and the schemes involving partial model information enhancement. and Unified as M s , U s (k) and Y s (k);
[0071] Deploying this method in a real industrial control system involves acquiring system inputs and outputs online and generating residuals. The residual test values are generated by chi-square test and generalized likelihood ratio test. If the test value is greater than its corresponding test threshold, it is judged that a replay attack has been performed and an alarm is issued.
[0072] The beneficial effects of adopting this technical solution are:
[0073] This invention presents a data-driven replay attack detection method based on equivalence space, encompassing residual generation, residual evaluation, and detection performance optimization. It generates residuals using the equivalence space method based on the system's input and output data, and identifies the system's dynamic internal characteristics through residual verification and detection performance optimization. This effectively detects whether the system is under replay attack, thus improving detection performance. Compared to existing technologies, this method primarily relies on historical data from device operation, eliminating the need for system model parameters that are difficult to obtain in practice. It also maintains ease of deployment, does not sacrifice system control performance, and requires no external equipment, contributing to solving the replay attack detection problem in industrial systems. Attached Figure Description
[0074] Figure 1 This is a schematic diagram of a data-driven replay attack detection method for industrial control systems based on equivalence space, according to the present invention.
[0075] Figure 2 This is a residual change diagram when the system is subjected to a replay attack in an embodiment of the present invention;
[0076] Figure 3 This is a typical original system replay attack detection rate graph in this embodiment of the invention;
[0077] Figure 4 This is a comparison chart of the enhanced system replay attack detection rate in embodiments of the present invention; Detailed Implementation
[0078] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described below with reference to the accompanying drawings.
[0079] In this embodiment, see Figure 1 As shown, this invention proposes a data-driven replay attack detection method for industrial control systems based on equivalence space, including equivalence space identification and optimization (steps S1-S3), a replay attack detection enhancement scheme that fuses model information and data information (S4), and an equivalence space residual perception alarm strategy (S5). Specifically, it includes the following operational steps:
[0080] S1: Set the order s of the equivalent space, the group length K of the historical data, and obtain the input and output data for 2 (s+K) consecutive time steps from the industrial control system;
[0081] S2: To further enhance detection performance, you can choose whether to perform partial model information enhancement on the detection scheme. If you choose yes, first set the critical stability filter parameter A. ζ With B ζ Using this model knowledge, new input and output data can be constructed based on historical input and output data. If no is selected, there is no need to reconstruct new input and output data, and the original data can be used directly.
[0082] S3: Identify the equivalent matrix based on the input and output data, use the equivalent matrix and the input and output data to obtain the residuals, and obtain the chi-square test and the generalized likelihood ratio test, and determine the residual threshold and the generalized likelihood ratio test threshold respectively.
[0083] Specifically, the nullification matrix N is identified based on the input and output data obtained from S2. s With product N s H u,s Select an optimization index J i The corresponding weight matrix M is estimated using a data-driven approach. s The weight matrix M s With the null matrix N s Multiplying them yields the equivalent matrix Z. s =M s N s The residuals are obtained using the equivalent matrix and the input / output data.
[0084] Remember r s (k) represents the residual generated by the system at time k:
[0085]
[0086] in:
[0087]
[0088] H u,s It is the input transfer matrix, U s (k) is the system input matrix, Y s (k) is the system output matrix. It is the kernel representation of the original system; u(k) is the input vector of the system at time k, and y(k) is the output vector of the system at time k.
[0089] Based on this, a chi-square test was designed. General Likelihood Test And determine the chi-square test residual thresholds respectively. The threshold J for the generalized likelihood ratio test th,LR .
[0090] S4: Based on the original system identification, some model information is directly introduced to enhance the detection method; the critical stability filter parameters to be introduced are set, and then the equivalent matrix after partial model enhancement and the new residual threshold are calculated according to the equivalent matrix transformation method.
[0091] Specifically, if the original system identification is performed (i.e., no new input / output data is constructed in S2, and the original input / output data is used for identification in S3), then this step allows for the direct introduction of some model information to enhance the detection method based on the original system identification, without requiring repeated identification work and maintaining low computational load. First, the critically stable filter parameter A to be introduced is set. ζ With B ζ Then, the nullification matrix after partial model enhancement is calculated using the equivalent matrix transformation method. The new residual covariance is calculated based on the residual relationship, and the new weight matrix is derived. And calculate the new equivalent matrix. With the new residual threshold.
[0092] S5: Deploy the existing detection system, acquire the system's input and output online, generate residuals, and use the chi-square test and generalized likelihood ratio test to judge the system's operating status; when the test value is greater than the residual threshold, it is judged to be under replay attack and an alarm is issued.
[0093] As an optimization of the above embodiment, in step S1, the initialization includes: modeling a discrete linear time-invariant system of a general industrial control system, with its input and output being u and y; and acquiring input and output data for 2 (s+K) consecutive time steps from the industrial control system based on the selected equivalent space order s and the length of the historical data set K.
[0094] Specifically, a discrete linear time-invariant system model is performed for a general industrial control system, with inputs and outputs u and y. An equivalent space order s = 8 and a historical data set length K = 300 are selected. Input and output data for 2(s + K) = 616 consecutive time points are obtained from a normally operating industrial control system. The replay attack on this system is implemented by replacing the input and output data from time t = 500 to t = 550 with historical input and output data from time t = 300 to t = 350.
[0095] As an optimization of the above embodiment, in step S2, to enhance detection performance, partial model information enhancement includes the following steps:
[0096] If partial model information enhancement is performed on the detection scheme, then a critically stable filter configuration is selected, requiring A... ζ It is the critical stability matrix, and B ζ For a full-rank matrix, A is typically chosen.ζ =B ζ =I, simultaneously satisfying simplicity and accuracy; using the original input and output u and y to generate new input and output:
[0097]
[0098] in: It is the new system input at time k, which is numerically equal to the original system input u(k); The output of the new system at time k is the critically stable filter parameter A. ζ B ζ Construct it from the original system output y(k); It is the output of the new system at time k-1.
[0099] As an optimized solution of the above embodiment, step S3, the nullification matrix identification, weight matrix design, and residual detection include the following steps:
[0100] (1) Identification of the null matrix:
[0101] First, obtain the input and output, including the original input and output or the newly constructed input and output, denoted as u and y, and arrange them into a matrix in the following form:
[0102]
[0103] Where: Φ k,s It is the system input and output data matrix at time k, which is obtained by arranging the system input u and system output y obtained in the previous step in a specific way; parameter s is the order of the equivalent space, and parameter K is the group length of the historical data;
[0104] Next, perform SVD decomposition:
[0105]
[0106] in: It is the transpose of the input and output data matrices at time ks-1; after SVD decomposition, the left singular matrix [U1 U2] and the right singular matrix are obtained. and singular value matrix
[0107] U1 is the first part of the left singular matrix, corresponding to the non-zero singular values; U2 is the second part of the left singular matrix, corresponding to the approximately zero singular values. This is the transpose of the first part of the right singular matrix, corresponding to the non-zero singular values. ∑1 is the transpose of the latter part of the right singular matrix, corresponding to singular values that are approximately 0; ∑2 is the former part of the singular value matrix, containing non-zero singular values; and ∑1 is the latter part of the singular value matrix, which is approximately 0.
[0108] Finally, after decomposition, taking ∑2 approximately as 0, we obtain the corresponding U2, then:
[0109]
[0110] When splitting: Then the null matrix
[0111] in, The intersection of the state transfer matrices To output the equivalent matrix, The input is an equivalent matrix.
[0112] (2) Data-driven weight matrix:
[0113] Different weight matrix designs are used for different optimization metrics.
[0114] Positive definite part optimization, corresponding weight matrix M s For: M s =Λ -1 U T ;
[0115] Among them, Λ and U are derived from SVD decomposition. Let V be the covariance matrix of the residuals under normal conditions, U be the left singular matrix, Λ be the non-zero singular value matrix, and V be the non-zero singular value matrix. T This is the transpose of a right singular matrix;
[0116] The cumulative total ratio is optimized to yes The maximum generalized eigenvector; therefore, the parameter T is solved. Δ,∑ and Then various weight matrices can be calculated;
[0117] in, It is the weight matrix M s =I, the covariance of the residuals, using To make an estimate; while T Δ,∑ The weight matrix M is the result of a replay attack. s =I generates changes in residual covariance using a data-driven approach, achieved by autonomously simulating replay attacks and calculating the changes in their residual covariance:
[0118] remember For the system in k i The residual at each time step when subjected to a replay attack, where the replay attack occurs at the α-th time step of the detection window, i.e.
[0119] This is the input matrix for a replay attack. This is the output matrix during a replay attack;
[0120] in:
[0121] Where: τ is the time of data replay, and s is the order of the equivalent space;
[0122] Repeat this replay attack n t Wheel, calculation:
[0123]
[0124] in: Is the system in k i The residual when constantly subjected to replay attacks It is the covariance of the system residuals when no replay attack is received, n t It is the number of observations of the residuals in the generalized likelihood ratio test;
[0125] Further statistics:
[0126]
[0127] in: The change in residual covariance is caused by the replay attack occurring at time α within the detection window. It is the average change of the residual covariance over the s time points in the detection window.
[0128] (3) Residual detection method:
[0129] Chi-square test Generalized likelihood ratio test To enable the detection of residuals;
[0130] Based on weight matrix M s The statistical properties of the system residuals are as follows:
[0131] Where, Θ s It is the covariance matrix of the system residuals. The representative value is 0, and the covariance is Θ. s Gaussian distribution;
[0132] Define the chi-square test:
[0133] Its threshold It is obtained by querying the chi-square distribution table;
[0134] Define the generalized likelihood ratio test:
[0135]
[0136] in Its threshold can be calculated numerically;
[0137] Where, n r It represents the number of observations of the residuals in the generalized likelihood ratio test, det is the determinant operation, and r s (ki) represents the residual at time ki.
[0138] As an optimization of the above embodiment, step S4, which enhances the original system with partial model information, includes the following steps:
[0139] Select the critical stability matrix A ζ With full-rank matrix B ζ (A is usually selected) ζ =B ζ =I), and construct the following matrix:
[0140]
[0141] Solving the equation yields matrix D: The new nullification matrix is then: The residual generation of a partial model information augmentation system can then be expressed as: in Furthermore, for the estimated values of the residual covariance of the partially enhanced system model, we have: This is the new weight matrix.
[0142] As an optimization of the above embodiment, in step S5, the equivalent space residual sensing alarm strategy includes the following steps:
[0143] For ease of representation, the M involved in the original equivalent space replay attack detection scheme will be represented as... s , U s (k) and Y s (k), and the schemes involving partial model information enhancement. and Unified as M s , U s (k) and Y s (k). Deploying this method in a real industrial control system involves acquiring system inputs and outputs online and generating residuals: The residual test values are generated by chi-square test and generalized likelihood ratio test. The false alarm rate deviation is less than 5%. If the test value is greater than its corresponding test threshold, it is judged to be a replay attack and an alarm is issued.
[0144] like Figure 2 As shown, the changes in system residuals under the chi-square test and the generalized likelihood ratio test can be observed, with the system suffering a replay attack between times 500 and 550. The experiment was repeated 500 times, and the detection rate was statistically analyzed. The results are as follows. Figure 3 As can be seen, this method has high detection accuracy. By modifying system parameters and constructing a special system to make it more difficult to detect replay attacks, we tested it using both the original replay attack detection method and a partially model-enhanced replay attack detection method. The experiment was repeated 500 times, and the detection rate was statistically analyzed as follows: Figure 4 As can be seen, the replay attack detection performance of some enhanced models has been significantly improved.
[0145] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A data-driven replay attack detection method for equivalent space-based industrial control systems, characterized in that, The method comprises the steps of: S1: setting the order s of the equivalent space, the group length K of the historical data, and obtaining the input and output data of 2(s+K) continuous time points from the industrial control system; S2: selecting whether to enhance the detection scheme with partial model information; if yes, setting the critical model parameters and constructing new input and output data according to the historical input and output data; if no, no new input and output data needs to be constructed, and the original input and output data is directly used; In the step S2, if the selection is yes, first set the critical stable filter parameter A ζ With B ζ , using this part of the model knowledge, according to the historical input and output data to construct new input and output data; The partial model information enhancement comprises the steps of: If partial model information is augmented to the detection scheme, the critical stable filter configuration is selected, requiring A ζ is a critical stable matrix, and B ζ is a full rank matrix, the new input output is generated using the original input output u and y as: wherein: is the new system input at time k, which is numerically equal to the original system input u(k); is the new system output at time k, constructed from the original system output y(k) through the critical stability filter parameters A ζ , B ζ ; is the new system output at time k-1; S3: identifying the equivalent matrix according to the input and output data, obtaining the residual error by using the equivalent matrix and the input and output data, and obtaining the chi-square test and the generalized likelihood ratio test, and determining the residual error threshold and the generalized likelihood ratio test threshold respectively; S4: directly introducing the partial model information to enhance the detection method on the basis of the original system identification; setting the critical stable filter parameters to be introduced, and then calculating the equivalent matrix after the partial model enhancement and the new residual error threshold according to the equivalent matrix transformation method; S5: deploying the obtained detection system, obtaining the input and output of the system online, generating the residual error, and using the chi-square test and the generalized likelihood ratio test to judge the operation of the system; when the test value is greater than the residual error threshold, it is judged that the system is subjected to a replay attack, and an alarm is issued.
2. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 1, characterized in that, In the step S1, the initialization comprises: modeling a general industrial control system discrete linear time-invariant system, the input and output of which are u and y; according to the selected equivalent space order s and the historical data group length K, the input and output data of 2(s+K) continuous time points are obtained from the industrial control system.
3. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 1, characterized in that, In the S3, the input-output data obtained from the S2 is used to identify the zeroing matrix N s and the product N s H u,s , an optimization index J i is selected and a data-driven method is used to estimate the corresponding weight matrix M s , the weight matrix M s is multiplied by the zeroing matrix N s to obtain the equivalent matrix Z s =M s N s ; the residual error is obtained by using the equivalent matrix and the input-output data; Recall r s (k) is the residual generated by the system at time k. Wherein: H u,s is the input transfer matrix, U s (k) is the system input matrix, Y s (k) is the system output matrix, is the kernel representation of the original system; u(k) is the input vector of the system at time k, and y(k) is the output vector of the system at time k. Accordingly, a chi-square test is designed and a generalized likelihood ratio test and a chi-square test residual threshold is determined and a generalized likelihood ratio test threshold J th,LR .
4. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 3, characterized in that, In the step S3, the nullification matrix identification comprises: First, the input and output, including the original input and output or the newly constructed input and output, are obtained, denoted as u and y, and arranged into a matrix in the following form: wherein: Φ k,s is the system input-output data matrix at time k, obtained by a specific arrangement of the system input u and system output y from the previous step; the parameter s is the order of the equivalent space, and the parameter K is the group length of the historical data; Secondly, SVD decomposition is performed: wherein: is the transpose of the input-output data matrix at time k-s-1; after SVD decomposition, the left singular matrix [U1 U2] and the right singular matrix and the singular value matrix U1is the front part of the left-singular matrix, U2is the back part of the left-singular matrix, is the transpose of the front part of the right-singular matrix, is the transpose of the back part of the right-singular matrix, ∑1is the front part of the singular value matrix, ∑2is the back part of the singular value matrix; Finally, ∑2 is approximated to 0 after decomposition, and the corresponding U2 is obtained, so that: When performing the splitting: then the nulling matrix where is the intersection of the state transition matrices, is the output equivalence matrix, is the input equivalence matrix.
5. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 4, characterized in that, In the step S3, the data-driven weight matrix comprises Different weight matrix designs are used for different optimization indicators, positive definite part optimization, corresponding weight matrix M s is: M s = Λ -1 U T ; where Λ and U are derived from SVD decomposition is the covariance matrix of the residuals under normal conditions, U is the left singular matrix, Λ is the non-zero singular value matrix, V T is the right singular matrix transpose; The cumulative sum ratio is optimized as is the maximum generalized eigenvector; thus solving the parameter T Δ,∑ with the various weight matrices are then calculated; wherein is the weight matrix M s = I; and T Δ,∑ is the change in the residual covariance generated under the weight matrix M s = I when a replay attack occurs; Recall the residual of the system at the k i th moment when a replay attack occurs at the a is the input matrix at replay attack, is the output matrix at replay attack; wherein: Wherein: τ is the time of the replay data, and s is the order of the equivalent space; Repeat this replay attack n t Rounds, compute: where: is the residual of the system at k i when it is subject to a replay attack, is the covariance of the system residual when not subject to a replay attack, n t is the number of observations of the residual in the generalized likelihood ratio test; Further statistics: wherein: is the residual covariance variation caused by the replay attack at the ath time instant of the detection window, is the average variation value of the residual covariance over s time instants of the detection window.
6. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 5, characterized in that, In the step S3, the residual error detection method comprises: Using a chi-squared test With a generalized likelihood ratio test To enable detection of the residual; Based on the weight matrix M s The statistical properties of the system residuals are where Θ s is the covariance matrix of the system residuals, represents a Gaussian distribution with mean 0 and covariance Θ s . The chi-square test is defined as: The generalized likelihood ratio test is defined as: wherein where n r is the number of observations of the residual in the generalized likelihood ratio test, det is the determinant operation, r s (k-i) is the residual at time k-i.
7. The data-driven, equivalence space method-based industrial control system replay attack detection method of claim 2, wherein, In the step S4: if the original system identification is performed, i.e. no new input-output data is constructed in S2, the original input-output data is used for identification in S3; first set the critical stable filter parameter A needed to be introduced ζ With B ζ Then calculate the annihilating matrix of the enhanced partial model according to the equivalent matrix transformation method And calculate the new residual covariance and derive the new weight matrix according to the residual relationship And calculate the new equivalent matrix And the new residual threshold; In the step S4, the partial model information enhances the original system, which comprises the following steps: Selecting a critical stable matrix A ζ with full rank matrix B ζ and construct the following matrix: Solving the equation, we obtain the matrix D: The new annihilating matrix is then: The residual generating representation of the partially model-informed augmentation system is then: where and for the estimate of the system residual covariance of the partially model-informed augmentation, we have: is the new weight matrix.
8. The data-driven replay attack detection method for equivalent space-based industrial control system according to claim 7, characterized in that, In the step S5, the equivalent space residual error perception alarm strategy comprises the steps of: M s 、 U s (k) with Y s (k), and with M s 、 U s (k) with Y s (k); In the actual industrial control system, the method is deployed, the system input and output are obtained online, and the residual error is generated: And the test value of the residual error is generated by chi-square test and generalized likelihood ratio test, if the test value is greater than the corresponding test threshold value, it is judged that it is subjected to replay attack, and an alarm is issued.
Citation Information
Patent Citations
Replay attack detection method for cyber-physical industrial control system
CN116820071A