Framework for the Development of Anomaly Detection and Classification Models for Cyber-Physical Systems
摘要
As the number of applications and hardware solutions for cyber-physical systems grows, the attack surface grows at the same time. The concept behind this paper is primarily that of the processes, the laws of parameter variation, the parameters themselves, the laws of control theory and, therefore, the sets of scenarios that a cyber-physical system implements. In the case of using machine learning methods, the task can be reduced to a clustering task, within which an intelligent algorithm is trained to divide the set of values of the analyzed parameters into areas of acceptable and unacceptable values. For this purpose, for example, a neural network model can be trained without an instructor based on data obtained in the normal mode of operation of the cyber-physical systems. This approach usually requires less effort due to the lack of the need to collect data containing anomalies and assumes that parameter values differ depending on the mode of operation (normal or unstable). The measure of discrepancy between the actual data and the data generated by the intelligent algorithm can be the RMS or absolute error, with the higher the error, the less similar the analyzed data are to those used for training. In other words, a change in the measure of divergence in a larger direction allows us to talk about the probable non-compliance of the behavior of the system parameters with physical laws. The paper discloses the proposed method and evaluates the method.