open access publication

Article, 2023

CyPhERS: A cyber-physical event reasoning system providing real-time situational awareness for attack and fault response

Computers in Industry, ISSN 0166-3615, 1872-6194, Volume 151, Page 103982, 10.1016/j.compind.2023.103982

Contributors

Müller, Nils 0000-0002-3749-5073 (Corresponding author) [1] Bao, Kaibin 0000-0002-8231-4331 [2] Matthes, Jörg 0000-0002-0963-6000 [2] Heussen, Kai 0000-0003-3623-1372 [1]

Affiliations

  1. [1] Technical University of Denmark
  2. [NORA names: DTU Technical University of Denmark; University; Denmark; Europe, EU; Nordic; OECD];
  3. [2] Karlsruhe Institute of Technology
  4. [NORA names: Germany; Europe, EU; OECD]

Abstract

Cyber–physical systems (CPSs) constitute the backbone of critical infrastructures such as power grids or water distribution networks. Operating failures in these systems can cause serious risks for society. To avoid or minimize downtime, operators require real-time awareness about critical incidents. However, online event identification in CPSs is challenged by the complex interdependency of numerous physical and digital components, requiring to take cyber attacks and physical failures equally into account. The online event identification problem is further complicated through the lack of historical observations of critical but rare events, and the continuous evolution of cyber attack strategies. This work introduces and demonstrates CyPhERS, a Cyber-Physical Event Reasoning System. CyPhERS provides real-time information pertaining the occurrence, location, physical impact, and root cause of potentially critical events in CPSs, without the need for historical event observations. Key novelty of CyPhERS is the capability to generate informative and interpretable event signatures of known and unknown types of both cyber attacks and physical failures. The concept is evaluated and benchmarked on a demonstration case that comprises a multitude of attack and fault events targeting various components of a CPS. The results demonstrate that the event signatures provide relevant and inferable information on both known and unknown event types.

Keywords

Cyber-Physical, Cypher, attack strategy, attacks, awareness, backbone, capability, cases, cause, complex interdependencies, components, concept, continuous evolution, critical infrastructures, cyber, cyber-attack strategies, cyber-attacks, cyber-physical systems, digital components, distribution network, downtime, event identification, event observations, event signatures, event types, events, failure, fault, fault response, grid, historical observations, identification, identification problem, impact, incidence, inferring information, information, infrastructure, interdependence, lack, location, minimal downtime, network, novelty, observations, occurrence, operation, operational failures, physical failures, physical impact, power, power grid, problem, rare event, real-time awareness, real-time information, real-time situational awareness, reasoning system, response, results, risk, root, root cause, signature, situational awareness, society, strategies, system, target various components, type, water, water distribution networks

Funders

  • Helmholtz Association of German Research Centres
  • Innovation Fund Denmark

Data Provider: Digital Science