Cheah Huei Yoong

dblp:267/2693 · also Andrew Cheah Huei Yoong · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
2since 2021 · last 2023
0000-0003-3222-3754ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2023 Mitigating Adversarial Attacks on Data-Driven Invariant Checkers for Cyber-Physical Systems
abstract
The use ofinvariantsin developing security mechanisms has become an attractive research area because of their potential to both prevent attacks and detect attacks in Cyber-Physical Systems (CPS). In general, an invariant is a property that is expressed using design parameters along with Boolean operators and which always holds in normal operation of a system, in particular, a CPS. Invariants can be derived by analysing operational data of various design parameters in a running CPS, or by analysing the system's requirements/design documents, with both of the approaches demonstrating significant potential to detect and prevent cyber-attacks on a CPS. While data-driven invariant generation can be fully automated, design-driven invariant generation has a substantial manual intervention. In this paper, we aim to highlight the shortcomings in data-driven invariants by demonstrating a set of adversarial attacks on such invariants. We propose a solution strategy to detect such attacks by complementing them with design-driven invariants. We perform all our experiments on a real water treatment testbed. We shall demonstrate that our approach can significantly reduce false positives and achieve high accuracy in attack detection on CPSs.
Rajib Ranjan Maiti, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
IEEE Trans. Dependable Secur. Comput.2
2021 Deriving invariant checkers for critical infrastructure using axiomatic design principles
abstract
Abstract Cyber-physical systems (CPSs) in critical infrastructure face serious threats of attack, motivating research into a wide variety of defence mechanisms such as those that monitor for violations ofinvariants, i.e. logical properties over sensor and actuator states that should always be true. Many approaches for identifying invariants attempt to do so automatically, typically using data logs, but these can miss valid system properties if relevant behaviours are not well-represented in the data. Furthermore, as the CPS is already built, resolving any design flaws or weak points identified through this process is costly. In this paper, we propose a systematic method for deriving invariants from an analysis of a CPSdesign, based on principles of the axiomatic design methodology from design science. Our method iteratively decomposes a high-level CPS design to identify sets of dependentdesign parameters(i.e. sensors and actuators), allowing for invariants and invariant checkers to be derived in parallel to the implementation of the system. We apply our method to the designs of two CPS testbeds, SWaT and WADI, deriving a suite of invariant checkers that are able to detect a variety of single- and multi-stage attacks without any false positives. Finally, we reflect on the strengths and weaknesses of our approach, how it can be complemented by other defence mechanisms, and how it could help engineers to identify and resolve weak points in a design before the controllers of a CPS are implemented.
Cheah Huei Yoong, Venkata Reddy Palleti, Rajib Ranjan Maiti, Arlindo Silva, Christopher M. Poskitt
Cybersecur.1
2015 Open Designettes, Flowcharts, and Pseudocodes in Python Programming with the Aid of Finch
Cheah Huei Yoong, Hyowon Lee 0001, Ngai-Man Cheung
ICCE1
2007 Average Network Blocking Probabilities for TDM WDM Optical Networks with OTSIs and without WC
abstract
Previous works have considered analytical models of TDM wavelength networks to evaluate the blocking performance, but they differ in their underlying assumptions and have varying computation complexities. In this paper, we present an analytical model of TDM WDM optical networks with optical time-slot interchangers and without wavelength converter for minimum fixed hop routing. In order to make the analysis tractable, we proposed an algorithm that works for any number of partition patterns regardless of numbers of links, wavelengths in each link, and time-slots in each wavelength. Our analytical model provides good accuracies in average network blocking probabilities when compared with the simulation results.
Cheah Huei Yoong, Pung Hung Keng, Nikolai K. Krivulin
MASCOTS1
2006 A Mini-Slot Router Architecture for TDM Optical WDM Networks
abstract
Many routing and wavelength assignment algorithms have been proposed for optical networks, but they lack the refinement of being able to further share the gigabit bandwidth in each wavelength. Obviously, TDM wavelength routing networks can offer better network throughput than traditional wavelength routed networks. However, with the advancement of optical technology, it is possible to divide a wavelength in a fiber into timeslots, and further divide a time-slot into mini-slots so that the fiber bandwidth can be more efficiently utilized. This paper proposes a router architecture with an electronic system controller to support optical data transfer at the mini-slots of a time-slot in a wavelength for each hop of a route. No wavelength converter is employed in the proposed router architecture. The effectiveness of this network in blocking probability and throughput is demonstrated by simulation.
Cheah Huei Yoong, Pung Hung Keng
AINA (1)1