项目名称: 典型主动攻击下网络化控制系统的安全性研究
项目编号: No.61203230
项目类型: 青年科学基金项目
立项/批准年度: 2013
项目学科: 自动化学科
项目作者: 庞中华
作者单位: 北方工业大学
项目金额: 25万元
中文摘要: 网络化控制系统(NCS)现已逐渐成为工业自动化系统的发展趋势,以实现分布式测量与控制。然而,由于共享网络的开放性、交互性与分散性等特点,NCS面临着网络安全攻击的问题。本项目针对两类典型主动攻击:篡改欺骗攻击和UDP泛洪DoS攻击,从信息安全和控制理论角度出发,设计积极的攻击检测和控制策略:1)基于加密算法、异常数据检测方法、预测控制理论等,实现通道欺骗攻击的检测和补偿;2)针对特定NCS,构造合理的隐蔽欺骗攻击模型,进而设计攻击检测和控制策略;3)针对特定NCS,建立DoS攻击模型,定量分析网络安全性,进而设计攻击检测与定位方法和主动容侵容错控制策略;4)为实验验证本项目理论结果的有效性和促进NCS理论的工业应用,设计一套工业网络化实时控制平台。通过本项目的研究,可进一步丰富和完善NCS安全性理论与技术,并推动NCS理论的实际工程应用。
中文关键词: 网络化控制系统;输出跟踪控制;模型预测方法;欺骗攻击;容侵容错控制
英文摘要: Networked control systems (NCSs) have been a growing trend in industrial automation systems for the purposes of distributed measurement and control. However, due to the properties of a shared network, such as opening-up, interactivity, and decentralization, NCSs are confronted with such problems as network security attacks. Two kinds of typical active attacks, tampering deception attacks and UDP flooding DoS attacks, are considered in this project. To guarantee the desired control performance when suffering from these attacks, the active strategies of detection and control are proposed from the viewpoint of information security and control theories. 1) The encryption algorithms, anomaly data detection methods and predictive control theories are used to achieve the detection and control of the deception attacks over NCS channels. 2) A reasonable model is constructed for stealthy deception attacks over a specific NCS, and the corresponding methods of diction and control are designed. 3) For a specific NCS, a DoS attack model is built to quantitatively analyze the network security, and the corresponding strategies of attack detection and location are designed, as well as active intrusion and fault tolerant methods. 4) A real-time industrial networked control platform is designed to test the effectiveness of the re
英文关键词: Networked control systems;output tracking control;model-based prediction approach;deception attacks;intrusion and fault tolerant control