Font Size: a A A

Research On Sinusoidal Attack Modeling And Detection Of Industrial Control System Based On MSPCA And Its Improved Algorithm

Posted on:2019-01-07Degree:MasterType:Thesis
Country:ChinaCandidate:D L LiuFull Text:PDF
GTID:2348330545993374Subject:Control Science and Engineering
Abstract/Summary:PDF Full Text Request
Industrial control systems are widely used in many key infrastructure fields,such as electricity,oil,chemicals and transportation and so on.They are of great significance to ensuring the stable operation of industrial production and national economic security.However,with the deep integration of industrialization and informatization,more and more Internet technologies are applied to industrial control systems,leading to the widespread occurrence of security incidents in industrial control systems as well as in IT systems.The industrial control system interacts with the physical devices through many field equipments such as sensors and actuators.The attack on the industrial control system will eventually have an impact on the physical world,such as equipment failure,production interruption,casualties and other serious consequences.Therefore,studying the attack detection algorithm of industrial control system will be a necessary and effective way to protect the safety of industrial control system.In this paper,the following work has been done i n the industrial control system security research:(1)Firstly,the difference between industrial control system security and traditional information is analyzed.Secondly,the typical hierarchical structure of industrial control system is given,combined with the security features of industrial control system,putting forward the production control layer.Then the linear mathematical model of production control layer is established,and uses it to make threat analysis.Lastly,taking the sensor variables as the research object,the attack modes existing in the control layer are mathematically modeled and analyzed.(2)The characteristics of process monitoring methods commonly used in industrial control system which are based on knowledge,mathematical models and data driven are described in detail,and the feasibility of data driven method for deceptive attack detection is analyzed.After studying the similarities and differences between failure and deceptive attack,the principal component analysis(PCA)method is proposed to detect deceptive attack and an online monitoring algorithm is established.(3)Simulations on the TE platform show that the attacks of general deceptive attacks such as bias attack are limited and the PCA method can detect three types of general deceptive attacks in real time,which makes the general deceptive attack may fail to achieve the purpose of the attacker.Based on the above deficiencies,this paper puts forward the sinusoidal deception attack.First of all,the mathematical model is established using a typical loop of the control system,and the Fourier transform and wavelet analysisare used to prove the different characteristics of it in the aspect of attack ability and concealment,and then verify the sinusoidal attack ability and concealment in TE platform.(4)Multi-scale principal component analysis(MSPCA)uses wavelet transform to decompose data in multiple scales,and carries out PC A on different scales.Therefore,the multi-scale principal component analysis method is proposed for the detection of sinusoidal attack and then online detection algorithm is established.Due to the real timeliness of industrial control system,the time complexity of the algorithm is analyzed,and the relationship between the real-time detection and the window size of the algorithm is analyzed,and how to balance the real-time and window size selection is analyzed.In addition,taking into account the nonlinear,time-varying,dynamic and other characteristics of modern chemical processes,the multi-scale principal component analysis method may have higher false positive rate and false negative rate when detecting sinusoidal attacks.Therefore,a sinusoidal attack detection algorithm based on multi-scale dynamic principal component analysis(MSDKPCA)method is proposed to solve the nonlinear and dynamic existing in the process data.
Keywords/Search Tags:industrial control system, attack detection, sinusoidal attack, multi-scale principal component analysis, multi-scale dynamic kernel principal component analysis
PDF Full Text Request
Related items