TY - JOUR
T1 - A novel en-route filtering scheme against false data injection attacks in cyber-physical networked systems
AU - Yang, Xinyu
AU - Lin, Jie
AU - Yu, Wei
AU - Moulema, Paul Marie
AU - Fu, Xinwen
AU - Zhao, Wei
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2015/1/1
Y1 - 2015/1/1
N2 - In Cyber-Physical Networked Systems (CPNS), the adversary can inject false measurements into the controller through compromised sensor nodes, which not only threaten the security of the system, but also consume network resources. To deal with this issue, a number of en-route filtering schemes have been designed for wireless sensor networks. However, these schemes either lack resilience to the number of compromised nodes or depend on the statically configured routes and node localization, which are not suitable for CPNS. In this paper, we propose a Polynomial-based Compromise-Resilient En-route Filtering scheme (PCREF), which can filter false injected data effectively and achieve a high resilience to the number of compromised nodes without relying on static routes and node localization. PCREF adopts polynomials instead of Message Authentication Codes (MACs) for endorsing measurement reports to achieve resilience to attacks. Each node stores two types of polynomials: authentication polynomial and check polynomial, derived from the primitive polynomial, and used for endorsing and verifying the measurement reports. Through extensive theoretical analysis and experiments, our data shows that PCREF achieves better filtering capacity and resilience to the large number of compromised nodes in comparison to the existing schemes.
AB - In Cyber-Physical Networked Systems (CPNS), the adversary can inject false measurements into the controller through compromised sensor nodes, which not only threaten the security of the system, but also consume network resources. To deal with this issue, a number of en-route filtering schemes have been designed for wireless sensor networks. However, these schemes either lack resilience to the number of compromised nodes or depend on the statically configured routes and node localization, which are not suitable for CPNS. In this paper, we propose a Polynomial-based Compromise-Resilient En-route Filtering scheme (PCREF), which can filter false injected data effectively and achieve a high resilience to the number of compromised nodes without relying on static routes and node localization. PCREF adopts polynomials instead of Message Authentication Codes (MACs) for endorsing measurement reports to achieve resilience to attacks. Each node stores two types of polynomials: authentication polynomial and check polynomial, derived from the primitive polynomial, and used for endorsing and verifying the measurement reports. Through extensive theoretical analysis and experiments, our data shows that PCREF achieves better filtering capacity and resilience to the large number of compromised nodes in comparison to the existing schemes.
KW - Cyber-physical networked system
KW - and polynomial-based en-route filtering
KW - data injection attack
KW - sensor networks
UR - https://www.scopus.com/pages/publications/84919466772
U2 - 10.1109/TC.2013.177
DO - 10.1109/TC.2013.177
M3 - 文章
AN - SCOPUS:84919466772
SN - 0018-9340
VL - 64
SP - 4
EP - 18
JO - IEEE Transactions on Computers
JF - IEEE Transactions on Computers
IS - 1
M1 - 6587034
ER -