ATTACK IDENTIFICATION IN I&C SYSTEMS BASED ON PHYSICAL DATA
Wen Si, Jianghai Li, Xiaojin Huang · The Proceedings of the International Conference on Nuclear Engineering (ICONE) · 2019
In digital instrumentation and control (I&C) systems of nuclear power plants (NPPs), cybersecurity is significant to the normal operation of the systems, because if the I&C system is under attack, physical equipment and processes controlled by the I&C system are all at risk. Different types of attacks may affect different components of I&C system and cause different consequences. Thus, once an attack is detected, an assessment of the range and the extent of the attack is essential to predict the consequences. Attack identification is the first priority step of the attack assessment. Correct determination of the attack type not only helps to assess the attributes and characteristics of the attack, but also is the basis of making appropriate response to avoid the spread of attack effects. Previous work is about attack detection using network data of packets based on replicator neural network method. The packets are recorded from an industry control system (ICS) testbed. The data include normal data and attack data. The attack data are generated on the real ICS testbed attacked by an attack server. Further than attack detection, this paper analyzes network packets deeper and extracts physical data from packets for attack identification. Data parts are separated from packets and physical data are extracted by packet processing according to industrial control protocols. For identification, three typical types of attack, including denial of service (DoS) attack, command injection attack, and data tampering attack, are considered. Features of different types of attack are extracted by analyzing physical data.