Toward the Integration of Cyber and Physical Security Monitoring Systems for Critical Infrastructures

Sensors (Basel). 2021 Oct 20;21(21):6970. doi: 10.3390/s21216970.

Abstract

Critical Infrastructures (CIs) are sensible targets. They could be physically damaged by natural or human actions, causing service disruptions, economic losses, and, in some extreme cases, harm to people. They, therefore, need a high level of protection against possible unintentional and intentional events. In this paper, we show a logical architecture that exploits information from both physical and cybersecurity systems to improve the overall security in a power plant scenario. We propose a Machine Learning (ML)-based anomaly detection approach to detect possible anomaly events by jointly correlating data related to both the physical and cyber domains. The performance evaluation showed encouraging results-obtained by different ML algorithms-which highlights how our proposed approach is able to detect possible abnormal situations that could not have been detected by using only information from either the physical or cyber domain.

Keywords: anomaly detection; critical infrastructure; cybersecurity; machine learning; physical security.

MeSH terms

  • Algorithms
  • Computer Security*
  • Computers
  • Humans
  • Information Systems*