Abstract
Several attack detectors have been deployed to deal with the explosion of attacks to mission-critical networks. However, existing detectors do not address motivated and knowledgeable attackers who craft attacks using knowledge of the system including its methods of detecting attacks. In this thesis, we propose different techniques to improve the resilience of two existing attack detectors: (i) cyber-physical control systems (CPCS) attack detector and (ii) machine learning-based malicious traffic detector. To improve CPCS attack detection, we analyze the conditions for an attacker to by-pass a dissipativity-theoretic fault detector adopted in prior work to detect attacks in CPCS. We show that the attacker can use a quadratic programming solver to efficiently compute false data injection attacks to bypass the detector. We show further that, by applying an OR gate to fuse binary detection results from a number of the detectors, with carefully chosen parameters, we can achieve an integrated detector bank that can-not be bypassed by an attacker, if the attacker can tamper with either the sensor or control data of the system. To enhance machine learning-based malicious traffic detection, we first study the possibility for an attacker to bypass the autoencoder-based malicious traffic detector. We then formulate the condition for the attacker to bypass the detector as a constrained optimization problem and propose an efficient method to solve this problem. Evalu-ation results show that the attacker can successfully modify the network behavior to create adversarial examples for the existing malicious traffic detector. We then propose a new attack detection mechanism to enhance the robustness of existing malicious flow traffic detector, making the process of crafting adversarial examples more difficult.