Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical System
arXiv:1801.00903 · doi:10.1109/SP.2018.00016
Abstract
Cyber-physical systems (CPS) consist of sensors, actuators, and controllers all communicating over a network; if any subset becomes compromised, an attacker could cause significant damage. With access to data logs and a model of the CPS, the physical effects of an attack could potentially be detected before any damage is done. Manually building a model that is accurate enough in practice, however, is extremely difficult. In this paper, we propose a novel approach for constructing models of CPS automatically, by applying supervised machine learning to data traces obtained after systematically seeding their software components with faults ("mutants"). We demonstrate the efficacy of this approach on the simulator of a real-world water purification plant, presenting a framework that automatically generates mutants, collects data traces, and learns an SVM-based model. Using cross-validation and statistical model checking, we show that the learnt model characterises an invariant physical property of the system. Furthermore, we demonstrate the usefulness of the invariant by subjecting the system to 55 network and code-modification attacks, and showing that it can detect 85% of them from the data logs generated at runtime.
Accepted by IEEE S&P 2018
References in corpus (2)
Cited by in corpus (12)
- A Survey on Industrial Control System Testbeds and Datasets for Security Research
- Time Series Anomaly Detection for Cyber-Physical Systems via Neural System Identification and Bayesian Filtering
- Learning-Guided Network Fuzzing for Testing Cyber-Physical System Defences
- IPAL: Breaking up Silos of Protocol-dependent and Domain-specific Industrial Intrusion Detection Systems
- Active Fuzzing for Testing and Securing Cyber-Physical Systems
- The best laid plans or lack thereof: Security decision-making of different stakeholder groups
- Code Integrity Attestation for PLCs using Black Box Neural Network Predictions
- Diagnosis-guided Attack Recovery for Securing Robotic Vehicles from Sensor Deception Attacks
- Finding Causally Different Tests for an Industrial Control System
- Runtime Anomaly Detection for Drones: An Integrated Rule-Mining and Unsupervised-Learning Approach
- Towards Systematically Deriving Defence Mechanisms from Functional Requirements of Cyber-Physical Systems
- Developing a Strong CPS Defender: An Evolutionary Approach