Attack Rules: Automatically Generating New Cyberattacks for Industrial Control Systems

5 minute read

Published:

Evaluating the security of an Industrial Control System requires more than testing a small collection of previously observed cyberattacks.

Attackers may manipulate different combinations of sensors and actuators, change the timing or magnitude of those manipulations, and construct attack patterns that were not considered when the detection system was designed.

This blog post discusses our paper, Attack Rules: An Adversarial Approach to Generate Attacks for Industrial Control Systems Using Machine Learning https://doi.org/10.1145/3462633.3483976, presented at the 2021 Workshop on CPS and IoT Security and Privacy.

Why is attack generation necessary?

Machine-learning-based anomaly detection systems are frequently evaluated using historical datasets. These datasets contain examples of normal operation and a limited selection of attacks.

Strong performance on a fixed dataset does not necessarily demonstrate that the detector will recognise new attacks. It may simply have learned the patterns associated with the attacks already represented in its training data.

A comprehensive security assessment should determine how the detector behaves when confronted with plausible attack patterns it has not previously encountered.

Manually designing every possible attack is not practical. Industrial systems may contain large numbers of sensors, actuators, controllers, and operational constraints. The possible combinations of manipulated components can grow rapidly.

What did we propose?

We developed an attack-generation method based on association rule mining.

Association rule mining is commonly used to identify relationships of the form: when one set of conditions occurs, another condition frequently follows.

In an industrial control system, these rules can represent relationships between sensor readings, actuator states, and process conditions. For example, the state of a pump may be associated with changes in flow, pressure, or tank level.

Once these relationships are identified, selected rules can be modified or violated to produce potential cyber-physical attack patterns.

How does attack generation work?

The approach first learns associations from operational data collected from a Secure Water Treatment plant.

These associations represent expected relationships between process variables. Attack patterns can then be generated by identifying combinations of sensor and actuator changes that disrupt those relationships.

This enables the systematic creation of attacks that:

  • manipulate several process components;
  • violate established operational associations;
  • represent previously unseen combinations;
  • test the boundaries of anomaly detection models; and
  • expose assumptions embedded in existing security mechanisms.

The purpose is defensive. Automatically generated attacks can be used to stress-test anomaly detectors and improve understanding of how a system might be compromised.

What did we find?

The published study generated more than 110,000 attack patterns, with many representing attack vectors that had not previously been included in the evaluated data.

This scale would be extremely difficult to achieve through exclusively manual attack design.

The automatically generated attacks provide a broader basis for security evaluation. They can help researchers identify weaknesses in anomaly detection methods and select additional attack scenarios for detailed investigation.

Why is this useful?

Anomaly detection research can become overly dependent on the attacks already available in public datasets. This creates a risk that models are optimised for known benchmarks rather than the wider attack space.

Attack Rules provides a mechanism for expanding that space. It supports more demanding evaluation by exposing detectors to combinations they have not already learned.

The approach can also contribute to:

  • adversarial testing of machine learning models;
  • generation of additional security test cases;
  • assessment of attack coverage;
  • design of more robust anomaly detectors; and
  • identification of relationships between attacks and physical processes.

Perspective

The key contribution of this work is a shift from asking, “Can the detector identify these known attacks?” to asking, “What other attacks could plausibly be generated from the system’s operational relationships?”

Automatically generated attacks should not replace expert knowledge. Some generated combinations may be physically infeasible, operationally irrelevant, or require attacker capabilities that are not realistic.

The strongest approach combines automated generation with process knowledge, threat modelling, and expert validation. Automation expands the search space, while domain expertise determines which attacks deserve further analysis.

The paper was co-authored with Muhammad Azmi Umer, Muhammad Taha Jilani, and Aditya P. Mathur.

Research collaboration and consultancy

Our research investigates systematic methods for generating, modelling, and evaluating cyberattacks against industrial control systems and critical infrastructure.

We welcome enquiries relating to:

  • automated cyberattack generation;
  • adversarial testing of intrusion detection systems;
  • association rule mining for cybersecurity;
  • industrial anomaly detection;
  • red-team scenario generation;
  • security evaluation of AI-based detectors;
  • cyber-physical attack modelling;
  • attack coverage and dataset limitations;
  • water treatment and critical-infrastructure security;
  • design of realistic industrial cybersecurity testbeds; and
  • robust machine learning for industrial systems.

We can support critical-infrastructure organisations, industrial operators, cybersecurity vendors, engineering organisations, and research groups through consultancy, independent evaluation, collaborative research, threat modelling, specialist training, and knowledge exchange.

For consultancy, research collaboration, advisory activities, or invited talks, contact Dr Mujeeb Ahmed, Senior Lecturer in Computing at Newcastle University:

Email: mujeeb.ahmed@newcastle.ac.uk

huadhry Mujeeb Ahmed, Muhammad Taha Jilani, and Aditya P. Mathur. 2021. [Attack Rules: An Adversarial Approach to Generate Attacks for Industrial Control Systems Using Machine Learning](https://doi.org/10