arXiv:2503.01229cs.LGcs.CR2025-03

用因子分解机分析水系统传感器与执行器关系,精准定位网络攻击源头。

Enhancing Network Security Management in Water Systems using FM-based Attack Attribution

  • 基于因子分解机建模传感器-执行器交互,捕捉线性与二次效应。
  • 在真实水系统数据集上,攻击根源排序准确率比SHAP和LEMNA高约20%。
  • 适合需要精确定位工业控制系统攻击源的水务安全团队使用。

供水系统是现代基础设施的关键组成部分,但正面临日益复杂的网络攻击威胁,可能对公共健康与安全造成严重后果。尽管先进机器学习技术能有效检测异常,但现有模型无关的攻击归因方法(如LIME、SHAP、LEMNA)在大规模、相互关联的供水系统中效果不佳,因其主要关注单个特征重要性,忽视了系统中关键的传感器-执行器交互。为此,我们提出一种新型模型无关的因子分解机(FM)方法,利用传感器-执行器间的交互关系,为网络攻击提供细粒度解释。例如,执行器泵活动异常可被归因于一组水压传感器,该结果来自方法捕获的线性与二次效应。我们在两个真实供水系统数据集SWaT和WADI上验证了该方法,结果表明,在涉及复杂传感器-执行器交互的多特征攻击场景中,其攻击根源排序性能优于传统方法,平均提升约20%。

原文摘要 · Abstract (English)

Water systems are vital components of modern infrastructure, yet they are increasingly susceptible to sophisticated cyber attacks with potentially dire consequences on public health and safety. While state-of-the-art machine learning techniques effectively detect anomalies, contemporary model-agnostic attack attribution methods using LIME, SHAP, and LEMNA are deemed impractical for large-scale, interdependent water systems. This is due to the intricate interconnectivity and dynamic interactions that define these complex environments. Such methods primarily emphasize individual feature importance while falling short of addressing the crucial sensor-actuator interactions in water systems, which limits their effectiveness in identifying root cause attacks. To this end, we propose a novel model-agnostic Factorization Machines (FM)-based approach that capitalizes on water system sensor-actuator interactions to provide granular explanations and attributions for cyber attacks. For instance, an anomaly in an actuator pump activity can be attributed to a top root cause attack candidates, a list of water pressure sensors, which is derived from the underlying linear and quadratic effects captured by our approach. We validate our method using two real-world water system specific datasets, SWaT and WADI, demonstrating its superior performance over traditional attribution methods. In multi-feature cyber attack scenarios involving intricate sensor-actuator interactions, our FM-based attack attribution method effectively ranks attack root causes, achieving approximately 20% average improvement over SHAP and LEMNA.

攻击归因水系统安全因子分解机工业控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。