IM-DISCO: Invariant Mining for Detecting IntrusionS in Critical Operations
摘要
In today’s interconnected world, robust cybersecurity measures are crucial, especially for Cyber-Physical Systems. While anomaly-based Intrusion Detection Systems can identify abnormal behaviors, interpreting the resulting alarms is challenging. An alternative approach utilizes invariant rules to describe system operations, providing clearer explanations for abnormal behaviors. In this context, invariant rules are conditions that must hold true for a system’s different operational modes. However, defining these rules is time-consuming and costly. This paper presents IM-DISCO, a tool that analyzes operational data to propose inference rules characterizing different modes of system operation. Deviations from these rules indicate anomalies, enabling continuous monitoring with incident detection and response. In our evaluation, focusing on rail transportation, we achieved 99.29% accuracy in detecting and characterizing operational modes using real-world train data. Additionally, we achieved 99.86% accuracy in identifying anomalies during simulated attacks. Notably, our results demonstrate an average detection time of 0.026 ms, enabling swift incident response to prevent catastrophic events.