LAPSE:2024.0653
Published Article

LAPSE:2024.0653
Security Assessment of Industrial Control System Applying Reinforcement Learning
June 6, 2024
Abstract
Industrial control systems are often used to assist and manage an industrial operation. These systems’ weaknesses in the various hierarchical structures of the system components and communication backbones make them vulnerable to cyberattacks that jeopardize their security. In this paper, the security of these systems is studied by employing a reinforcement learning extended attack graph to efficiently reveal the subsystems’ flaws. Specifically, an attack graph that mimics the environment is constructed for the system using the state−action−reward−state−action technique, in which the agent is regarded as the attacker. Attackers may cause the greatest amount of system damage with the fewest possible actions if they have the highest cumulative reward. The worst-case assault scheme with a total reward of 42.9 was successfully shown in the results, and the most badly affected subsystems were recognized.
Industrial control systems are often used to assist and manage an industrial operation. These systems’ weaknesses in the various hierarchical structures of the system components and communication backbones make them vulnerable to cyberattacks that jeopardize their security. In this paper, the security of these systems is studied by employing a reinforcement learning extended attack graph to efficiently reveal the subsystems’ flaws. Specifically, an attack graph that mimics the environment is constructed for the system using the state−action−reward−state−action technique, in which the agent is regarded as the attacker. Attackers may cause the greatest amount of system damage with the fewest possible actions if they have the highest cumulative reward. The worst-case assault scheme with a total reward of 42.9 was successfully shown in the results, and the most badly affected subsystems were recognized.
Record ID
Keywords
cyber–physical system security, industrial control system, industry, innovation, and infrastructure, reinforcement learning, SARSA
Subject
Suggested Citation
Ibrahim M, Elhafiz R. Security Assessment of Industrial Control System Applying Reinforcement Learning. (2024). LAPSE:2024.0653
Author Affiliations
Ibrahim M: Department of Mechatronics Engineering, German Jordanian University, Amman 11180, Jordan [ORCID]
Elhafiz R: Department of Mechatronics Engineering, German Jordanian University, Amman 11180, Jordan
Elhafiz R: Department of Mechatronics Engineering, German Jordanian University, Amman 11180, Jordan
Journal Name
Processes
Volume
12
Issue
4
First Page
801
Year
2024
Publication Date
2024-04-16
ISSN
2227-9717
Version Comments
Original Submission
Other Meta
PII: pr12040801, Publication Type: Journal Article
Record Map
Published Article

LAPSE:2024.0653
This Record
External Link

https://doi.org/10.3390/pr12040801
Publisher Version
Download
Meta
Record Statistics
Record Views
589
Version History
[v1] (Original Submission)
Jun 6, 2024
Verified by curator on
Jun 6, 2024
This Version Number
v1
Citations
Most Recent
This Version
URL Here
http://psecommunity.org/LAPSE:2024.0653
Record Owner
Auto Uploader for LAPSE
Links to Related Works
(0.09 seconds)
[0.09 s]
