首篇系统综述,梳理自2013年以来自适应异常检测在工控系统中的研究进展。
Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review
- 构建涵盖攻击类型、应用领域等5维度的新分类体系。
- 发现现有研究多只关注数据或模型单一适应,极少同时兼顾两者。
- 为学术界与工业界提供前沿进展参考及未来研究方向建议。
现代工控系统(CPS)中的网络攻击快速演变,传统方法因聚焦历史威胁而难以应对。自适应异常检测(AAD)因其高效数据处理与模型动态调整能力,成为检测新型攻击的有力手段。尽管已有大量研究,但截至目前尚无系统性文献综述。本文首次开展针对该领域的系统文献回顾(SLR),共收集397篇相关论文,并对其中65篇(47篇研究论文与18篇综述)进行深入分析,时间范围覆盖2013年至2023年11月。我们提出一个包含攻击类型、应用场景、学习范式、数据管理与算法五要素的全新分类框架。分析显示,多数研究仅关注数据处理或模型适应之一,极少实现双重自适应。本文旨在推动技术演进,帮助研究人员把握前沿,助力实践者理解最新进展,并揭示当前局限,提出未来研究建议。
原文摘要 · Abstract (English)
Modern cyberattacks in cyber-physical systems (CPS) rapidly evolve and cannot be deterred effectively with most current methods which focused on characterizing past threats. Adaptive anomaly detection (AAD) is among the most promising techniques to detect evolving cyberattacks focused on fast data processing and model adaptation. AAD has been researched in the literature extensively; however, to the best of our knowledge, our work is the first systematic literature review (SLR) on the current research within this field. We present a comprehensive SLR, gathering 397 relevant papers and systematically analyzing 65 of them (47 research and 18 survey papers) on AAD in CPS studies from 2013 to 2023 (November). We introduce a novel taxonomy considering attack types, CPS application, learning paradigm, data management, and algorithms. Our analysis indicates, among other findings, that reviewed works focused on a single aspect of adaptation (either data processing or model adaptation) but rarely in both at the same time. We aim to help researchers to advance the state of the art and help practitioners to become familiar with recent progress in this field. We identify the limitations of the state of the art and provide recommendations for future research directions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。