A fault diagnosis system for interdependent critical infrastructures based on HMMs
Description
Modern society depends on the smooth functioning of critical infrastructures which provide services of fundamental importance, e.g. telecommunications and water supply. These infrastructures may suffer from faults/malfunctions coming e.g. from aging effects or they may even comprise targets of terrorist attacks. Prompt detection and accommodation of these situations is of paramount significance. This paper proposes a probabilistic modeling scheme for analyzing malicious events appearing in interdependent critical infrastructures. The proposed scheme is based on modeling the relationship between datastreams coming from two network nodes by means of a hidden Markov model (HMM) trained on the parameters of linear time-invariant dynamic systems which estimate the relationships existing among the specific nodes over consecutive time windows. Our study includes an energy network (IEEE 30 model bus) operated via a telecommunications infrastructure. The relationships among the elements of the network of infrastructures are represented by an HMM and the novel data is categorized according to its distance (computed in the probabilistic space) from the training ones. We considered two types of cyber-attacks (denial of service and integrity/replay) and report encouraging results in terms of false positive rate, false negative rate and detection delay. - Highlights: • An HMM-based scheme is proposed for analyzing malicious events in critical infrastructures. • We use the IEEE 30 model bus operated via an emulated ICT infrastructure. • Novel data is categorized based on its probabilistic distance from the training one. • We considered two types of cyber-attacks and report results of extensive experiments
Availability note (English)
Available from http://dx.doi.org/10.1016/j.ress.2015.01.024Additional details
Identifiers
- DOI
- 10.1016/j.ress.2015.01.024;
- PII
- S0951-8320(15)00034-4;
Publishing Information
- Journal Title
- Reliability Engineering and System Safety
- Journal Volume
- 138
- Journal Page Range
- p. 73-81
- ISSN
- 0951-8320
- CODEN
- RESSEP
INIS
- Country of Publication
- United Kingdom
- Country of Input or Organization
- International Atomic Energy Agency (IAEA)
- INIS RN
- 47019563
- Subject category
- S22: GENERAL STUDIES OF NUCLEAR REACTORS; S42: ENGINEERING; S98: NUCLEAR DISARMAMENT, SAFEGUARDS AND PHYSICAL PROTECTION;
- Descriptors DEI
- COMPUTER NETWORKS; CYBERNETICS; FAULT TREE ANALYSIS; MARKOV PROCESS; PROBABILISTIC ESTIMATION; SABOTAGE; SAFETY ANALYSIS; SECRECY PROTECTION; SECURITY; SECURITY VIOLATIONS; SIMULATION; VULNERABILITY; WATER SUPPLY
- Descriptors DEC
- CALCULATION METHODS; STOCHASTIC PROCESSES; SYSTEM FAILURE ANALYSIS; SYSTEMS ANALYSIS; VIOLATIONS
Optional Information
- Copyright
- Copyright (c) 2015 Elsevier Science B.V., Amsterdam, The Netherlands, All rights reserved.