Log-based Anomaly Detection of CPS Using a Statistical Method
arXiv:1701.03249 · doi:10.1109/IWESEP.2017.12
Abstract
Detecting anomalies of a cyber physical system (CPS), which is a complex system consisting of both physical and software parts, is important because a CPS often operates autonomously in an unpredictable environment. However, because of the ever-changing nature and lack of a precise model for a CPS, detecting anomalies is still a challenging task. To address this problem, we propose applying an outlier detection method to a CPS log. By using a log obtained from an actual aquarium management system, we evaluated the effectiveness of our proposed method by analyzing outliers that it detected. By investigating the outliers with the developer of the system, we confirmed that some outliers indicate actual faults in the system. For example, our method detected failures of mutual exclusion in the control system that were unknown to the developer. Our method also detected transient losses of functionalities and unexpected reboots. On the other hand, our method did not detect anomalies that were too many and similar. In addition, our method reported rare but unproblematic concurrent combinations of operations as anomalies. Thus, our approach is effective at finding anomalies, but there is still room for improvement.
References in corpus (1)
Cited by in corpus (10)
- Anomaly Detection for a Water Treatment System Using Unsupervised Machine Learning
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical System
- Learning-Guided Network Fuzzing for Testing Cyber-Physical System Defences
- Active Fuzzing for Testing and Securing Cyber-Physical Systems
- Code Integrity Attestation for PLCs using Black Box Neural Network Predictions
- Reusing Model Validation Methods for the Continuous Validation of Digital Twins of Cyber-Physical Systems
- Runtime Anomaly Detection for Drones: An Integrated Rule-Mining and Unsupervised-Learning Approach
- Towards Systematically Deriving Defence Mechanisms from Functional Requirements of Cyber-Physical Systems
- Outlier Detection and Data Clustering via Innovation Search
- Developing a Strong CPS Defender: An Evolutionary Approach