为解决日趋严重的工业控制系统(industrial control system,ICS)信息安全问题,提出一种针对工业控制网络的非参数累积和(cumulative sum,CUSUM)入侵检测方法.利用ICS输入决定输出的特性,建立ICS的数学模型预测系统的输出,一旦控制系统...为解决日趋严重的工业控制系统(industrial control system,ICS)信息安全问题,提出一种针对工业控制网络的非参数累积和(cumulative sum,CUSUM)入侵检测方法.利用ICS输入决定输出的特性,建立ICS的数学模型预测系统的输出,一旦控制系统的传感器遭受攻击,实际输出信号将发生改变.在每个时刻,计算工业控制模型的预测输出与传感器测量信号的差值,形成基于时间的统计序列,采用非参数CUSUM算法,实现在线检测入侵并报警.仿真检测实验证明,该方法具有良好的实时性和低误报率.选择适当的非参数CUSUM算法参数τ和β,该入侵检测方法不但能在攻击对控制系统造成实质伤害前检测出攻击,还对监测ICS中的误操作有一定帮助.展开更多
The adaptive algorithm used for echo cancellation(EC) system needs to provide 1) low misadjustment and 2) high convergence rate. The affine projection algorithm(APA) is a better alternative than normalized least mean ...The adaptive algorithm used for echo cancellation(EC) system needs to provide 1) low misadjustment and 2) high convergence rate. The affine projection algorithm(APA) is a better alternative than normalized least mean square(NLMS) algorithm in EC applications where the input signal is highly correlated. Since the APA with a constant step-size has to make compromise between the performance criteria 1) and 2), a variable step-size APA(VSS-APA) provides a more reliable solution. A nonparametric VSS-APA(NPVSS-APA) is proposed by recovering the background noise within the error signal instead of cancelling the a posteriori errors. The most problematic term of its variable step-size formula is the value of background noise power(BNP). The power difference between the desired signal and output signal, which equals the power of error signal statistically, has been considered the BNP estimate in a rough manner. Considering that the error signal consists of background noise and misalignment noise, a precise BNP estimate is achieved by multiplying the rough estimate with a corrective factor. After the analysis on the power ratio of misalignment noise to background noise of APA, the corrective factor is formulated depending on the projection order and the latest value of variable step-size. The new algorithm which does not require any a priori knowledge of EC environment has the advantage of easier controllability in practical application. The simulation results in the EC context indicate the accuracy of the proposed BNP estimate and the more effective behavior of the proposed algorithm compared with other versions of APA class.展开更多
文摘为解决日趋严重的工业控制系统(industrial control system,ICS)信息安全问题,提出一种针对工业控制网络的非参数累积和(cumulative sum,CUSUM)入侵检测方法.利用ICS输入决定输出的特性,建立ICS的数学模型预测系统的输出,一旦控制系统的传感器遭受攻击,实际输出信号将发生改变.在每个时刻,计算工业控制模型的预测输出与传感器测量信号的差值,形成基于时间的统计序列,采用非参数CUSUM算法,实现在线检测入侵并报警.仿真检测实验证明,该方法具有良好的实时性和低误报率.选择适当的非参数CUSUM算法参数τ和β,该入侵检测方法不但能在攻击对控制系统造成实质伤害前检测出攻击,还对监测ICS中的误操作有一定帮助.
文摘The adaptive algorithm used for echo cancellation(EC) system needs to provide 1) low misadjustment and 2) high convergence rate. The affine projection algorithm(APA) is a better alternative than normalized least mean square(NLMS) algorithm in EC applications where the input signal is highly correlated. Since the APA with a constant step-size has to make compromise between the performance criteria 1) and 2), a variable step-size APA(VSS-APA) provides a more reliable solution. A nonparametric VSS-APA(NPVSS-APA) is proposed by recovering the background noise within the error signal instead of cancelling the a posteriori errors. The most problematic term of its variable step-size formula is the value of background noise power(BNP). The power difference between the desired signal and output signal, which equals the power of error signal statistically, has been considered the BNP estimate in a rough manner. Considering that the error signal consists of background noise and misalignment noise, a precise BNP estimate is achieved by multiplying the rough estimate with a corrective factor. After the analysis on the power ratio of misalignment noise to background noise of APA, the corrective factor is formulated depending on the projection order and the latest value of variable step-size. The new algorithm which does not require any a priori knowledge of EC environment has the advantage of easier controllability in practical application. The simulation results in the EC context indicate the accuracy of the proposed BNP estimate and the more effective behavior of the proposed algorithm compared with other versions of APA class.