Abstract
Industrial Control Systems (ICS) form the core of smart critical infrastructure (CI) that includes systems such as the power grid and water treatment plants, and are known to be susceptible to cyber attacks. The impact of such attacks is often visible as an anomaly in the underlying process. If not detected early enough, and suitable mitigating actions enforced, an anomaly may lead to undesirable consequences such as component damage and service disruption. Several types of anomaly detectors have been proposed to detect anomalies and raise alerts for plant operators when detected. Prior to its implementation in an operational plant, any such detector needs to be tested thoroughly and its effectiveness demonstrated, against a variety of cyber attacks. This work is focused on a methodology of using digital twinning for testing anomaly detectors. In this methodology, a digital copy of the plant and anomaly detector is built as a network of timed automata models to test the anomaly detector prior to their installation in an operational plant. Attack models are important in effectively creating test suits for testing anomaly detectors. In this work we propose a method, namely SCM, to create attack models using a novel variant of program mutation. Creation of an attack model begins with a set of reference attacks created as timed automata models. These reference attacks are mutated using a set of well defined mutation operators. When applied, such mutations create a set of attacks termed attacklets. The attacklets are launched in the integrated model of the plant, that includes the detector, to study the detector’s effectiveness against the reference attacks and the attacklets. In a case study, the entire methodology was implemented in a water treatment plant. Results indicate the utility of the methodology in assessing the effectiveness of an anomaly detector and enhancing it to improve its effectiveness.