Department of Electronic Information and Electrical Engineering, Changsha University, Changsha 410022, China.
College of Computer, National University of Defense Technology, Changsha 410073, China.
Sensors (Basel). 2021 Feb 2;21(3):991. doi: 10.3390/s21030991.
A large-scale Cyber-Physical System (CPS) such as a smart grid usually provides service to a vast number of users as a public utility. Security is one of the most vital aspects in such critical infrastructures. The existing CPS security usually considers the attack from the information domain to the physical domain, such as injecting false data to damage sensing. Social Collective Attack on CPS (SCAC) is proposed as a new kind of attack that intrudes into the social domain and manipulates the collective behavior of social users to disrupt the physical subsystem. To provide a systematic description framework for such threats, we extend MITRE ATT&CK, the most used cyber adversary behavior modeling framework, to cover social, cyber, and physical domains. We discuss how the disinformation may be constructed and eventually leads to physical system malfunction through the social-cyber-physical interfaces, and we analyze how the adversaries launch disinformation attacks to better manipulate collective behavior. Finally, simulation analysis of SCAC in a smart grid is provided to demonstrate the possibility of such an attack.
大规模的信息物理系统(CPS),如智能电网,通常作为公共设施为大量用户提供服务。安全是这些关键基础设施中最重要的方面之一。现有的 CPS 安全通常考虑从信息域到物理域的攻击,例如注入虚假数据以破坏传感。社会集体攻击信息物理系统(SCAC)被提出作为一种新的攻击方式,它会侵入社会领域并操纵社会用户的集体行为来扰乱物理子系统。为了为这些威胁提供一个系统的描述框架,我们扩展了 MITRE ATT&CK,这是最常用的网络对手行为建模框架,以涵盖社会、网络和物理领域。我们讨论了虚假信息是如何构建的,并最终通过社会-网络-物理接口导致物理系统故障,我们还分析了对手如何发起虚假信息攻击以更好地操纵集体行为。最后,提供了智能电网中 SCAC 的仿真分析,以演示这种攻击的可能性。