Modern society depends on the smooth functioning of critical infrastructures which provide services of fundamental importance, e.g. telecommunications and water supply. These infrastructures may suffer from faults/malfunctions coming e.g. from aging effects or they may even comprise targets of terrorist attacks. Prompt detection and accommodation of these situations is of paramount significance. This paper proposes a probabilistic modeling scheme for analyzing malicious events appearing in interdependent critical infrastructures. The proposed scheme is based on modeling the relationship between datastreams coming from two network nodes by means of a hidden Markov model (HMM) trained on the parameters of linear time-invariant dynamic systems which estimate the relationships existing among the specific nodes over consecutive time windows. Our study includes an energy network (IEEE 30 model bus) operated via a telecommunications infrastructure. The relationships among the elements of the network of infrastructures are represented by an HMM and the novel data is categorized according to its distance (computed in the probabilistic space) from the training ones. We considered two types of cyber-attacks (denial of service and integrity/replay) and report encouraging results in terms of false positive rate, false negative rate and detection delay.
A fault diagnosis system for interdependent critical infrastructures based on HMMs / S. Ntalampiras, Y. Soupionis, G. Giannopoulos. - In: RELIABILITY ENGINEERING & SYSTEM SAFETY. - ISSN 0951-8320. - 138(2015), pp. 73-81.
|Titolo:||A fault diagnosis system for interdependent critical infrastructures based on HMMs|
NTALAMPIRAS, STAVROS (Corresponding)
|Parole Chiave:||Critical infrastructure protection; Cyber security; Cyber-attacks; Fault diagnosis; Hidden Markov model; Linear time invariant modeling; Safety, Risk, Reliability and Quality; Industrial and Manufacturing Engineering|
|Settore Scientifico Disciplinare:||Settore INF/01 - Informatica|
|Data di pubblicazione:||2015|
|Digital Object Identifier (DOI):||http://dx.doi.org/10.1016/j.ress.2015.01.024|
|Appare nelle tipologie:||01 - Articolo su periodico|