Abstract
This dissertation focuses on the development of a high fidelity anomaly detection mechanism for use in large-scale operational plants found in Critical Infrastructure. Such plants include those for water treatment, water distribution, electric power grid, and oil refinery. A physics-based anomaly detection system has been developed, implemented, and tested extensively in an operational water treatment plant. The detector is created using a design-centric approach that uses plant design and physics to create a set of invariants that are checked during plant operation for the existence of any anomaly. The approach is usable in both new and legacy plants unlike those designed using data-centric approaches that require the availability of state data from an operational plant. The detector is able to detect anomalies resulting from cyber-attacks and component failures with an exceptionally high accuracy and low rate of false positives. Testing the detector required creation of a new attack model. This model is constructive in contrast to the descriptive models available in the literature. The attack model was used to design a variety of simple and complex cyber-attacks that were launched on an operational plant to test the effectiveness of the detector. A method, named Distributed Attack Detection (DAD), is proposed, implemented and tested that deploys the detector in a plant at various levels of communication resulting in high rate of anomaly detection. Information generated by the detector is used in DAD to protect the plant against component damage using a command validation mechanism. The algorithm underlying DAD is shown to be non-polynomial. However, several carefully designed heuristics enable a drastic reduction in the complexity in support of the argument that the method is scalable to plants much larger than those on which the algorithm has been tested. Contributions presented in this dissertation are novel and complementary to a multitude of existing mechanisms for securing critical infrastructure.