kth.sePublikationer KTH
Ändra sökning
Länk till posten
Permanent länk

Direktlänk
Publikationer (10 of 16) Visa alla publikationer
Milosevic, J., Dahan, M., Amin, S. & Sandberg, H. (2024). Strategic Monitoring of Networked Systems with Heterogeneous Security Levels. IEEE Transactions on Control of Network Systems, 11(3), 1165-1176
Öppna denna publikation i ny flik eller fönster >>Strategic Monitoring of Networked Systems with Heterogeneous Security Levels
2024 (Engelska)Ingår i: IEEE Transactions on Control of Network Systems, E-ISSN 2325-5870, Vol. 11, nr 3, s. 1165-1176Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

We consider a strategic network monitoring problem involving the operator of a networked system and an attacker. The operator aims to randomize the placement of multiple protected sensors to monitor and protect components that are vulnerable to attacks. We account for the heterogeneity in the components' security levels and formulate a large-scale maximin optimization problem. After analyzing its structure, we propose a three-step approach to approximately solve the problem. First, we solve a generalized covering set problem and run a combinatorial algorithm to compute an approximate solution. Then, we compute approximation bounds by solving a nonlinear set packing problem. To evaluate our solution approach, we implement two classical solution methods based on column generation and multiplicative weights updates, and test them on real-world water distribution and power systems. Our numerical analysis shows that our solution method outperforms the classical methods on large-scale networks, as it efficiently generates solutions that achieve a close to optimal performance and that are simple to implement in practice.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2024
Nyckelord
Computational modeling, Game Theory, Games, Monitoring, Network systems, Networked Control Systems, Optimization, Other Applications, Security, Sensor systems, Sensors, Strategic Network Monitoring
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-350306 (URN)10.1109/TCNS.2023.3333392 (DOI)001322535500016 ()2-s2.0-85171683507 (Scopus ID)
Anmärkning

QC 20241014

Tillgänglig från: 2024-07-11 Skapad: 2024-07-11 Senast uppdaterad: 2025-01-07Bibliografiskt granskad
Gracy, S., Milosevic, J. & Sandberg, H. (2021). Security index based on perfectly undetectable attacks: Graph-theoretic conditions. Automatica, 134, Article ID 109925.
Öppna denna publikation i ny flik eller fönster >>Security index based on perfectly undetectable attacks: Graph-theoretic conditions
2021 (Engelska)Ingår i: Automatica, ISSN 0005-1098, E-ISSN 1873-2836, Vol. 134, artikel-id 109925Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

The notion of security index quantifies the least effort involved in conducting perfectly undetectable attacks. Thus, the security index enables a systems operator to assess the vulnerability of a component, informs sensor placement strategies, and helps in deciding the feasibility of secure estimators and fault detectors. In this paper, we investigate the (possible) variation in this index as a consequence of variation in the system parameters. To this end, we adopt a structured systems approach, typically represented by a directed graph, with the edges of the said graph being in one-to-one correspondence with the system parameters. We first show that the security index is generic. That is, for almost all choices of edge weights, the security index of a component remains the same. We refer to such an index as the generic security index. Secondly, we derive graph-theoretic conditions (and based on those an algorithm) for computing the generic security index. Third, we provide graph-theoretic conditions for computing lower (resp. upper) bounds on the values that the security index of a component can take for all nonzero choices of the edge weights of the directed graph. Finally, we provide a brute force search method for calculating the said bounds.

Ort, förlag, år, upplaga, sidor
Elsevier BV, 2021
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-304180 (URN)10.1016/j.automatica.2021.109925 (DOI)000707897700010 ()2-s2.0-85116025760 (Scopus ID)
Anmärkning

QC 20211105

Tillgänglig från: 2021-11-05 Skapad: 2021-11-05 Senast uppdaterad: 2022-12-12Bibliografiskt granskad
Gracy, S., Milosevic, J. & Sandberg, H. (2021). Security index based on perfectly undetectable attacks: Graph-theoretic conditions- Supplementary Material.
Öppna denna publikation i ny flik eller fönster >>Security index based on perfectly undetectable attacks: Graph-theoretic conditions- Supplementary Material
2021 (Engelska)Övrigt (Refereegranskat)
Förlag
s. 4
Nationell ämneskategori
Teknik och teknologier
Identifikatorer
urn:nbn:se:kth:diva-299442 (URN)
Anmärkning

QC 20210811

Tillgänglig från: 2021-08-09 Skapad: 2021-08-09 Senast uppdaterad: 2022-12-12Bibliografiskt granskad
Gracy, S., Milosevic, J. & Sandberg, H. (2020). Actuator Security Index for Structured Systems. In: Proceedings 2020 American Control Conference, ACC 2020, Denver, CO, USA, July 1-3, 2020: . Paper presented at 2020 American Control Conference, ACC 2020, Denver, CO, USA, July 1-3, 2020 (pp. 2993-2998). Institute of Electrical and Electronics Engineers (IEEE)
Öppna denna publikation i ny flik eller fönster >>Actuator Security Index for Structured Systems
2020 (Engelska)Ingår i: Proceedings 2020 American Control Conference, ACC 2020, Denver, CO, USA, July 1-3, 2020, Institute of Electrical and Electronics Engineers (IEEE) , 2020, s. 2993-2998Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Given a network with a set of vulnerable actuators (and sensors), the security index of an actuator equals the minimum number of sensors and actuators that needs to be compromised so as to conduct a perfectly undetectable attack using the said actuator. This paper deals with the problem of computing actuator security indices for discrete-time LTI network systems, using a structured systems framework. We show that the actuator security index is generic, that is for almost all realizations the actuator security index remains the same. We refer to such an index as generic security index (generic index) of an actuator. Given that the security index quantifies the vulnerability of a network, the generic index is quite valuable for large scale energy systems. Our second contribution is to provide graph-theoretic conditions for computing the generic index. The said conditions are in terms of existence of linkings on appropriately-defined directed (sub)graphs. Based on these conditions, we present an algorithm for computing the generic index.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2020
Serie
Proceedings of the American Control Conference, ISSN 0743-1619
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-292719 (URN)10.23919/ACC45564.2020.9147483 (DOI)000618079802149 ()2-s2.0-85089568799 (Scopus ID)
Konferens
2020 American Control Conference, ACC 2020, Denver, CO, USA, July 1-3, 2020
Anmärkning

QC 20210413

Tillgänglig från: 2021-04-13 Skapad: 2021-04-13 Senast uppdaterad: 2022-12-12Bibliografiskt granskad
Milosevic, J., Teixeira, A., Johansson, K. H. & Sandberg, H. (2020). Actuator Security Indices Based on Perfect Undetectability: Computation, Robustness, and Sensor Placement. IEEE Transactions on Automatic Control, 65(9), 3816-3831
Öppna denna publikation i ny flik eller fönster >>Actuator Security Indices Based on Perfect Undetectability: Computation, Robustness, and Sensor Placement
2020 (Engelska)Ingår i: IEEE Transactions on Automatic Control, ISSN 0018-9286, E-ISSN 1558-2523, Vol. 65, nr 9, s. 3816-3831Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

We propose an actuator security index that can be used to localize and protect vulnerable actuators in a networked control system. Particularly, the security index of an actuator equals to the minimum number of sensors and actuators that need to be compromised, such that a perfectly undetectable attack against that actuator can be conducted. We derive a method for computing the index in small-scale systems and show that the index can potentially be increased by placing additional sensors. The difficulties that appear once the system is of a large-scale are then outlined: The index is NP-hard to compute, sensitive with respect to system variations, and based on the assumption that the attacker knows the entire system model. To overcome these difficulties, a robust security index is introduced. The robust index can characterize actuators vulnerable in any system realization, can be calculated in polynomial time, and can be related to limited model knowledge attackers. Additionally, we analyze two sensor placement problems with the objective to increase the robust indices. We show that the problems have submodular structures, so their suboptimal solutions with performance guarantees can be computed in polynomial time. Finally, we illustrate the theoretical developments through examples.

Ort, förlag, år, upplaga, sidor
IEEE, 2020
Nyckelord
Indexes, Actuators, Security, Particle separators, Computational modeling, Networked control systems, Control systems analysis, cyber-physical systems, large-scale systems, linear systems, networks
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-281480 (URN)10.1109/TAC.2020.2981392 (DOI)000565140400008 ()2-s2.0-85090925750 (Scopus ID)
Anmärkning

QC 20201019

Tillgänglig från: 2020-10-19 Skapad: 2020-10-19 Senast uppdaterad: 2022-06-25Bibliografiskt granskad
Milosevic, J., Sandberg, H. & Johansson, K. H. (2020). Estimating the impact of cyber-attack strategies for stochastic networked control systems. IEEE Transactions on Control of Network Systems, 7(2), 747-757, Article ID 8827641.
Öppna denna publikation i ny flik eller fönster >>Estimating the impact of cyber-attack strategies for stochastic networked control systems
2020 (Engelska)Ingår i: IEEE Transactions on Control of Network Systems, E-ISSN 2325-5870, Vol. 7, nr 2, s. 747-757, artikel-id 8827641Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

Risk assessment is an inevitable step in implementation of a cyber-defense strategy. An important part of this assessment is to reason about the impact of possible attacks. In this paper, we study the problem of estimating the impact of cyber-attacks in stochastic linear networked control systems. For the stealthiness constraint, we adopt the Kullback-Leibler divergence between attacked and nonattacked residual sequences. Two impact metrics are considered: the probability that some of the critical states leave a safety region and the expected value of the infinity norm of the critical states. For the first metric, we prove that the optimal value of the impact estimation problem can be calculated by solving a set of convex problems. For the second, we derive efficiency to calculate lower and upper bounds. Finally, we show compatibility of our framework with a number of attack strategies proposed in the literature and demonstrate how it can be used for risk assessment in an example.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers Inc., 2020
Nyckelord
Cyber-physical systems, network security, networked control systems, risk analysis, security management, Accident prevention, Covariance matrix, Detectors, Estimation, Measurement, Risk assessment, Safety engineering, Stochastic systems, Attack strategies, Convex problems, Covariance matrices, Estimation problem, Expected values, IP networks, Kullback Leibler divergence, Lower and upper bounds
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-281237 (URN)10.1109/TCNS.2019.2940253 (DOI)000549872800019 ()2-s2.0-85072536001 (Scopus ID)
Anmärkning

QC 20200916

Tillgänglig från: 2020-09-16 Skapad: 2020-09-16 Senast uppdaterad: 2024-03-18Bibliografiskt granskad
Milosevic, J., Gracy, S. & Sandberg, H. (2020). On actuator security indices. In: 14th International Conference on Critical Information Infrastructures Security, CRITIS 2019: . Paper presented at Critical Information Infrastructures Security - 14th International Conference, CRITIS 2019, Linköping, Sweden, September 23-25, 2019 (pp. 182-187). Springer Nature
Öppna denna publikation i ny flik eller fönster >>On actuator security indices
2020 (Engelska)Ingår i: 14th International Conference on Critical Information Infrastructures Security, CRITIS 2019, Springer Nature , 2020, s. 182-187Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Actuator security indices are developed for risk assessment purposes. Particularly, these indices can tell a system operator which of the actuators in a critical infrastructure network are the most vulnerable to cyber-attacks. Once the operator has this information, he/she can focus the security budget to protect these actuators. In this short paper, we first revisit one existing definition of an actuator security index, and then discuss possible directions for future research.

Ort, förlag, år, upplaga, sidor
Springer Nature, 2020
Nyckelord
Cyber-attacks, Cyber-physical systems, Risk assessment, Actuators, Budget control, Computer crime, Cyber Physical System, Embedded systems, Network security, Security budget, Security indices, System operator, Critical infrastructures
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-267997 (URN)10.1007/978-3-030-37670-3_16 (DOI)000612959400016 ()2-s2.0-85077509323 (Scopus ID)
Konferens
Critical Information Infrastructures Security - 14th International Conference, CRITIS 2019, Linköping, Sweden, September 23-25, 2019
Anmärkning

QC 20200328.

QC 20210408.

Tillgänglig från: 2020-03-28 Skapad: 2020-03-28 Senast uppdaterad: 2022-12-12Bibliografiskt granskad
Miloševiç, J., Teixeira, A., Tanaka, T., Johansson, K. H. & Sandberg, H. (2020). Security Measure Allocation for Industrial Control Systems: Exploiting Systematic Search Techniques and Submodularity. International Journal of Robust and Nonlinear Control, 30(11), 4278-4302
Öppna denna publikation i ny flik eller fönster >>Security Measure Allocation for Industrial Control Systems: Exploiting Systematic Search Techniques and Submodularity
Visa övriga...
2020 (Engelska)Ingår i: International Journal of Robust and Nonlinear Control, ISSN 1049-8923, E-ISSN 1099-1239, Vol. 30, nr 11, s. 4278-4302Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

To protect industrial control systems from cyberattacks, multiple layers of security measures need to be allocated to prevent critical security vulnerabilities. However, both finding the critical vulnerabilities and then allocating security measures in a cost‐efficient way become challenging when the number of vulnerabilities and measures is large. This paper proposes a framework that can be used once this is the case. In our framework, the attacker exploits security vulnerabilities to gain control over some of the sensors and actuators. The critical vulnerabilities are those that are not complex to exploit and can lead to a large impact on the physical world through the compromised sensors and actuators. To find these vulnerabilities efficiently, we propose an algorithm that uses the nondecreasing properties of the impact and complexity functions and properties of the security measure allocation problem to speed up the search. Once the critical vulnerabilities are located, the security measure allocation problem reduces to an integer linear program. Since integer linear programs are NP‐hard in general, we reformulate this problem as a problem of minimizing a linear set function subject to a submodular constraint. A polynomial time greedy algorithm can then be applied to obtain a solution with guaranteed approximation bound. The applicability of our framework is demonstrated on a control system used for regulation of temperature within a building.

Ort, förlag, år, upplaga, sidor
Wiley, 2020
Nyckelord
Control Engineering, Reglerteknik
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-268917 (URN)10.1002/rnc.4375 (DOI)000541068900008 ()2-s2.0-85055057291 (Scopus ID)
Anmärkning

QC 20200225

Tillgänglig från: 2020-02-25 Skapad: 2020-02-25 Senast uppdaterad: 2024-03-18Bibliografiskt granskad
Milosevic, J., Dahan, M., Amin, S. & Sandberg, H. (2019). A Network Monitoring Game with Heterogeneous Component Criticality Levels. In: Proceedings of the IEEE Conference on Decision and Control: . Paper presented at 58th IEEE Conference on Decision and Control, CDC 2019, 11 December 2019 through 13 December 2019 (pp. 4379-4384). Institute of Electrical and Electronics Engineers Inc.
Öppna denna publikation i ny flik eller fönster >>A Network Monitoring Game with Heterogeneous Component Criticality Levels
2019 (Engelska)Ingår i: Proceedings of the IEEE Conference on Decision and Control, Institute of Electrical and Electronics Engineers Inc. , 2019, s. 4379-4384Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

We consider an attacker-operator game for monitoring a large-scale network that is comprised of components that differ in their criticality levels. In this zero-sum game, the operator seeks to position a limited number of sensors to monitor the network against the attacker who strategically targets a network component. The operator (resp. attacker) seeks to minimize (resp. maximize) the network loss. To study the properties of mixed-strategy Nash Equilibria of this game, we first study two simple instances: When component sets monitored from individual sensor locations are mutually disjoint; When only a single sensor is positioned, but with possibly overlapping monitoring component sets. Our analysis reveals new insights on how criticality levels impact the players equilibrium strategies. Next, we extend a previously developed approach to obtain an approximate Nash equilibrium in the general case. This approach uses solutions to minimum set cover and maximum set packing problems to construct an approximate Nash equilibrium. Finally, we implement a column generation procedure to improve this solution and numerically evaluate the performance of our approach. 

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers Inc., 2019
Nyckelord
Computation theory, Game theory, Linear programming, Column generation, Equilibrium strategy, Heterogeneous component, Large-scale network, Minimum set cover, Network Monitoring, Sensor location, Set packing problem, Criticality (nuclear fission)
Nationell ämneskategori
Datorsystem
Identifikatorer
urn:nbn:se:kth:diva-274080 (URN)10.1109/CDC40024.2019.9029427 (DOI)000560779004006 ()2-s2.0-85082501356 (Scopus ID)
Konferens
58th IEEE Conference on Decision and Control, CDC 2019, 11 December 2019 through 13 December 2019
Anmärkning

QC 20200702

Part of ISBN 9781728113982

Tillgänglig från: 2020-07-02 Skapad: 2020-07-02 Senast uppdaterad: 2024-10-15Bibliografiskt granskad
Milosevic, J., Sandberg, H. & Johansson, K. H. (2019). A Security Index for Actuators Based on Perfect Undetectability: Properties and Approximation. In: 2018 56th Annual Allerton Conference on Communication, Control, and Computing, Allerton 2018: . Paper presented at 56th Annual Allerton Conference on Communication, Control, and Computing, Allerton 2018, 2 October 2018 through 5 October 2018 (pp. 235-241). Institute of Electrical and Electronics Engineers (IEEE)
Öppna denna publikation i ny flik eller fönster >>A Security Index for Actuators Based on Perfect Undetectability: Properties and Approximation
2019 (Engelska)Ingår i: 2018 56th Annual Allerton Conference on Communication, Control, and Computing, Allerton 2018, Institute of Electrical and Electronics Engineers (IEEE), 2019, s. 235-241Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

A novel security index based on the definition of perfect undetectability is proposed. The index is a tool that can help a control system operator to localize the most vulnerable actuators in the network. In particular, the security index of actuator i represents the minimal number of sensors and actuators that needs to be compromised in addition to i, such that a perfectly undetectable attack is possible. A method for computing this index for small scale systems is derived, and difficulties with the index once the system is of large scale are outlined. An upper bound for the index that overcomes these difficulties is then proposed. The theoretical developments are illustrated on a numerical example. 

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2019
Serie
Annual Allerton Conference on Communication Control and Computing, ISSN 2474-0195
Nyckelord
Computer programming, Computer science, Control engineering, Security indices, Sensors and actuators, Small-scale systems, System operator, Theoretical development, Upper Bound, Actuators
Nationell ämneskategori
Reglerteknik
Identifikatorer
urn:nbn:se:kth:diva-252077 (URN)10.1109/ALLERTON.2018.8635906 (DOI)000461021200034 ()2-s2.0-85062843906 (Scopus ID)
Konferens
56th Annual Allerton Conference on Communication, Control, and Computing, Allerton 2018, 2 October 2018 through 5 October 2018
Projekt
CERCES
Anmärkning

QC 20190801

Part of ISBN 978-1-5386-6596-1

Tillgänglig från: 2019-08-01 Skapad: 2019-08-01 Senast uppdaterad: 2024-10-15Bibliografiskt granskad
Organisationer
Identifikatorer
ORCID-id: ORCID iD iconorcid.org/0000-0002-2045-5665

Sök vidare i DiVA

Visa alla publikationer