TY - JOUR
T1 - A Reflection-Based Channel Fingerprint to Locate Physically Intrusive Devices in ICS
AU - Liu, Pengfei
AU - Liu, Yang
AU - Wang, Xiangming
AU - Bao, Yuanyi
AU - Yang, Dong
AU - Wang, Wenqing
AU - Wu, Tong
AU - Lv, Zhuo
AU - Liu, Ting
N1 - Publisher Copyright:
© 2005-2012 IEEE.
PY - 2023/4/1
Y1 - 2023/4/1
N2 - It is hard to conduct cyberattacks in industrial control systems (ICSs) because most underlying networks of ICS like the field bus network are isolated from the internet. However, attackers can physically connect the intrusive device into the target network to launch various attacks, which bypasses the security protection mechanisms between the ICS and the internet. Currently, no effective measures could defend against such unauthorized physical access attacks. In this article, a reflection-based channel fingerprint is proposed to detect and locate these physically intrusive devices in the field bus network. We theoretically analyze the signal reflection characteristics and utilize inevitable changes in the channel fingerprint to detect the intrusive device. Besides, the detected anomaly features could be used to accurately estimate the intrusive device's location. In the end, the proposed method's effectiveness is validated through extensive simulation experiments.
AB - It is hard to conduct cyberattacks in industrial control systems (ICSs) because most underlying networks of ICS like the field bus network are isolated from the internet. However, attackers can physically connect the intrusive device into the target network to launch various attacks, which bypasses the security protection mechanisms between the ICS and the internet. Currently, no effective measures could defend against such unauthorized physical access attacks. In this article, a reflection-based channel fingerprint is proposed to detect and locate these physically intrusive devices in the field bus network. We theoretically analyze the signal reflection characteristics and utilize inevitable changes in the channel fingerprint to detect the intrusive device. Besides, the detected anomaly features could be used to accurately estimate the intrusive device's location. In the end, the proposed method's effectiveness is validated through extensive simulation experiments.
KW - Intrusive device localization
KW - reflection-based channel fingerprint
KW - security of field bus network
UR - https://www.scopus.com/pages/publications/85136863718
U2 - 10.1109/TII.2022.3198676
DO - 10.1109/TII.2022.3198676
M3 - 文章
AN - SCOPUS:85136863718
SN - 1551-3203
VL - 19
SP - 5495
EP - 5505
JO - IEEE Transactions on Industrial Informatics
JF - IEEE Transactions on Industrial Informatics
IS - 4
ER -