Detection of Cyber-attacks with Zone Dividing and PCA

Abstract Recently cyber-attacks become serious threats even for control systems. For process control, not only security but also safety must be assured. For safety assurance, the effects of cyber-attacks such as concealed remote operation and maneuvering must be evaluated. We proposed a securing method to divide field networks into plural zones. Even when a zone is intruded and attacks are concealed, the effects appear in other zones. In this paper, an automatic cyber-attacks detection system using PCA (Principal Component Analysis) is proposed. There are many kinds of relationships among variables included plural zones. Cyber-attacks change some of them. PCA is effective to detect the changes.