论文标题

多阶段移动目标防御:安全增强的D-FACT实施方法

Multi-stage Moving Target Defense: A Security-enhanced D-FACTS Implementation Approach

论文作者

Wang, Jiazhou, Tian, Jue, Liu, Yang, Guan, Xiaohong, Yang, Dong, Liu, Ting

论文摘要

在最近的研究中,采用移动目标防御(MTD)用于使用分布式柔性交流传输系统(D-FACTS)设备检测错误数据注入(FDI)攻击。但是,MTD的安全目标(即检测FDI攻击)与D-FACTS设备的经济目标(即减少功率损失)之间的固有冲突将阻碍MTD在实际系统中的应用。此外,现有MTD的检测功能通常不足。本文提出了一种多阶段的MTD(MMTD)方法来解决这两个问题,通过在D-Facts以经济为导向的方案之前添加一组设计的面向安全性方案来检测FDI攻击。我们将这些面向安全的方案保持在很短的时间间隔内,然后恢复到以经济为导向的计划,以确保经济要求。我们证明,与现有的一阶段MTD相比,设计的MMTD可以显着提高检测能力。我们发现MMTD检测能力的至高无上,并研究了其与系统拓扑和D-Facts部署的关系。同时,提出了一种贪婪的算法来搜索MMTD策略以达到这一至高无上。仿真结果表明,拟议的MMTD可以针对外国直接投资攻击实现最高攻击,同时在经济指标上表现优于当前的MTD策略。

In recent studies, moving target defense (MTD) has been applied to detect false data injection (FDI) attacks using distributed flexible AC transmission system (D-FACTS) devices. However, the inherent conflict between the security goals of MTD (i.e., detecting FDI attacks) and the economic goals of D-FACTS devices (i.e., reducing power losses) would impede the application of MTD in real systems. Moreover, the detection capabilities of existing MTDs are often insufficient. This paper proposes a multi-stage MTD (MMTD) approach to resolve these two issues by adding a group of designed security-oriented schemes before D-FACTS' economic-oriented scheme to detect FDI attacks. We keep these security-oriented schemes for a very short time interval and then revert to the economic-oriented scheme for the remaining time to ensure the economic requirements. We prove that a designed MMTD can significantly improve the detection capability compared to existing one-stage MTDs. We find the supremum of MMTD's detection capability and study its relationship with system topology and D-FACTS deployment. Meanwhile, a greedy algorithm is proposed to search the MMTD strategy to reach this supremum. Simulation results show that the proposed MMTD can achieve the supremum against FDI attacks while outperforming current MTD strategies on economic indicators.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源