Mufeng Wang

dblp:244/3389 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0001-5706-8960ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2025 Small-Signal-Stability-Guaranteed Moving Target Defense Against Load Redistribution Attack on IoT-Based Smart Grid
abstract
Moving target defense (MTD) is a promising approach to defend against load redistribution attacks on the Internet of Things (IoT)-based smart grid networks by probing the distorted state estimates with the distributed flexible AC transmission system. However, existing studies mainly focus on optimizing the performance of MTD and ignore the safety effect of it on the system’s operation. In this article, we fill this gap by deeply analyzing the effect of MTD on the small signal stability and aim to alleviate the negative impact and guarantee its defending performance simultaneously. First, the stability is formally described using the eigenvalue sensitivity. The relationship between the MTD-induced perturbation (MTDper) and the stability criteria is derived. Second, a new indicator is proposed to measure the effectiveness of MTDper. Third, a constrained optimization problem is formulated to compute the bound of MTDper for guaranteeing the small signal stability. In addition, a surprising finding is that the stability margin can be improved and enhanced by optimizing the value of MTDper without losing the MTD’s effectiveness. Finally, we evaluate the performance of MTDper and its impact on the small signal stability with extensive simulations on the IEEE 30-bus, 39-bus, and 68-bus test power systems.
Bingdong Wang, Zhenyong Zhang, Mufeng Wang, Mengxiang Liu, Ruilong Deng, Xin Zhang 0028
IEEE Internet Things J.3
2024 Control Logic Attack Detection and Forensics Through Reverse-Engineering and Verifying PLC Control Applications
abstract
Industrial control systems (ICSs) are prevalent in critical infrastructures, where programmable logic controllers (PLCs) and physical instruments are integrated. However, multiple successful attacks against PLC control logic programs have caused significant damage to ICSs, which has led to an urgent need for detection and forensics of such attacks. Although several off-the-shelf defending mechanisms have been presented in the past, few of them can detect and locate the control logic attacks at run time. In this article, we propose a practical and automatic control logic attack detection and forensics framework (CLADF) to conduct control logic attack detection and forensics in ICSs. Specifically, the core of CLADF includes: 1) a control application extraction module to extract PLC binary control applications by simulating PLC normal upload functionality; 2) a control application reverse engineering module to disassemble binary control applications; and 3) an attack detection and forensics module for verifying the integrity of PLC control applications, recovering the normal control application, and locating the modified control instructions. We extensively evaluated CLADF in five different application scenarios and two real-world Schneider PLCs. For each PLC, we generated three types of 150 mutated control logic attacks. The results demonstrate that CLADF can effectively extract the run-time binary control application in different application scenarios and disassemble these binary control applications into assembly instructions. Moreover, CLADF can accurately detect the attacks and locate the modified subroutines.
Yangyang Geng, Rongkuan Ma, Mufeng Wang, Yuqi Chen 0001
IEEE Internet Things J.5
2022 Toward a Trust Evaluation Framework Against Malicious Behaviors of Industrial IoT
abstract
With the development of the Industrial Internet of Things (IIoT) technology, edge computing is a promising area to release the sensing and computing burdens from the overloaded center. However, in edge network scenarios, we cannot trust every node’s output since some nodes can behave maliciously by making use of the properties, such as multiple identities, heterogeneous capabilities, and mobility. In that case, trust management is widely used to solve the problem of network trustworthiness. In this article, we propose a trust evaluation framework by comprehensively considering the nodes’ malicious behaviors and heterogeneous characteristics of edge networks. Under the Bayesian framework, we use the semi-ring theory to dynamically establish mobile-edge nodes’ trust models. First, we calculate the trust value for each node with a different identity (service provider or requester). Then, we propose a security-regarded task allocation mechanism to improve the reliability of selected trusted nodes according to the matched relationship between the service requesters’ expected capability and the providers’ actual capability. Further, we conduct extensive analysis and simulations to evaluate the proposed methods in typical IIoT scenarios. The results show that the proposed method has better immunity to abnormal behaviors, including the noncooperation, malicious feedback, on–off attacks, Sybil attacks, whitewashing attack, malicious access, etc., and has higher scheduling accuracy and controllable time complexity compared to existing methods.
Mufeng Wang, Zhenyong Zhang, Hengye Zhu
IEEE Internet Things J.2
2022 Detection and localization of cyber attacks on water treatment systems: an entropy-based approach
abstract
With the advent of Industry 4.0, water treatment systems (WTSs) are recognized as typical industrial cyber-physical systems (iCPSs) that are connected to the open Internet. Advanced information technology (IT) benefits the WTS in the aspects of reliability, efficiency, and economy. However, the vulnerabilities exposed in the communication and control infrastructure on the cyber side make WTSs prone to cyber attacks. The traditional IT system oriented defense mechanisms cannot be directly applied in safety-critical WTSs because the availability and real-time requirements are of great importance. In this paper, we propose an entropy-based intrusion detection (EBID) method to thwart cyber attacks against widely used controllers (e.g., programmable logic controllers) in WTSs to address this issue. Because of the varied WTS operating conditions, there is a high false-positive rate with a static threshold for detection. Therefore, we propose a dynamic threshold adjustment mechanism to improve the performance of EBID. To validate the performance of the proposed approaches, we built a high-fidelity WTS testbed with more than 50 measurement points. We conducted experiments under two attack scenarios with a total of 36 attacks, showing that the proposed methods achieved a detection rate of 97.22% and a false alarm rate of 1.67%.
Mufeng Wang, Rongkuan Ma, Zhenyong Zhang
Frontiers Inf. Technol. Electron. Eng.2
2022 Automatic protocol reverse engineering for industrial control systems with dynamic taint analysis
abstract
Proprietary (or semi-proprietary) protocols are widely adopted in industrial control systems (ICSs). Inferring protocol format by reverse engineering is important for many network security applications, e.g., program tests and intrusion detection. Conventional protocol reverse engineering methods have been proposed which are considered time-consuming, tedious, and error-prone. Recently, automatical protocol reverse engineering methods have been proposed which are, however, neither effective in handling binary-based ICS protocols based on network traffic analysis nor accurate in extracting protocol fields from protocol implementations. In this paper, we present a framework called the industrial control system protocol reverse engineering framework (ICSPRF) that aims to extract ICS protocol fields with high accuracy. ICSPRF is based on the key insight that an individual field in a message is typically handled in the same execution context, e.g., basic block (BBL) group. As a result, by monitoring program execution, we can collect the tainted data information processed in every BBL group in the execution trace and cluster it to derive the protocol format. We evaluate our approach with six open-source ICS protocol implementations. The results show that ICSPRF can identify individual protocol fields with high accuracy (on average a 94.3% match ratio). ICSPRF also has a low coarse-grained and overly fine-grained match ratio. For the same metric, ICSPRF is more accurate than AutoFormat (88.5% for all evaluated protocols and 80.0% for binary-based protocols).
Rongkuan Ma, Mufeng Wang
Frontiers Inf. Technol. Electron. Eng.4
2022 A Trust Management Method Against Abnormal Behavior of Industrial Control Networks Under Active Defense Architecture
abstract
Trusted computing is a typical active defense technology. Trust management is a core support technology of trusted computing. However, when trust management is applied in the industrial control systems, how to identify malicious behavior effectively, model trust relationships, and make a decision based on behavior trustworthiness, meanwhile how to ensure deployed trust mechanism does not affect the control network’s availability, is a significant issue that has not been solved in the previous literature. This paper proposes a trust management method against abnormal behavior of industrial control networks under active defense architecture. Firstly, we review the difficulties of trust management when applied to industrial control networks and analyze abnormal behaviors of the control operations under unknown threats. Then we extract trust information, model the trust relationship of abnormal behaviors, and establish a trust update and decision-making mechanism under the availability constraints of industrial control networks. Furthermore, we provide a deployment method of the proposed trust management in a distributed control network. Finally, we take five typical abnormal operations on control instruction in an industrial control network as an example and perform a detailed analysis and experimental verification of the proposed method. The results prove that the proposed trust management method has good immunity to abnormal behaviors of the control flow and can be deployed in an industrial control system with availability constraints.
Zhenyong Zhang, Mufeng Wang
IEEE Trans. Netw. Serv. Manag.3