Model-based autonomic security management for cyber-physical infrastructures
Qian Chen, Madhulika Trivedi, Sherif Abdelwahed, Thomas H. Morris, Frederick T. Sheldon · International Journal of Critical Infrastructures · 2016
Supervisory control and data acquisition (SCADA) systems, widely used in monitoring and controlling critical infrastructure systems, are highly vulnerable to cyber attacks. Current security solutions can protect SCADA systems from known cyber assaults, but most require human intervention. This paper presents a model-based autonomic security management (ASM) approach that monitors SCADA system performance and proactively predicts upcoming cyber attacks that may disrupt physical processes. We also discuss the feasibility of intrusion detection systems for laboratory-scale known and unknown attack detection. The ASM approach provides the most appropriate countermeasure recommendations, which may be deployed (semi-) autonomously based on an adaptive feedback mechanism. We present a gas pipeline case study and carry out function code scanning and malicious parameter injection attacks to validate the self-protection feature. Experimental results show that the ASM approach strengthens the SCADA system security, reduces protection time delays and toward achieving normal operations with little or no human intervention.