Mazen Azzam

dblp:294/5167 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
2since 2021 · last 2023
0000-0003-0384-5861ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2023 Forensic readiness of industrial control systems under stealthy attacks
abstract
Cyberattacks against Industrial Control Systems (ICS) can have harmful physical impacts. Investigating such attacks can be difficult, as evidence could be lost to physical damage. This is especially true with stealthy attacks ; i.e., attacks that can evade detection. In this paper, we aim to engineer Forensic Readiness (FR) in safety-critical, geographically distributed ICS, by proactively collecting potential evidence of stealthy attacks. The collection of all data generated by an ICS at all times is infeasible due to the large volume of such data. Hence, our approach only triggers data collection when there is the possibility for a potential stealthy attack to cause damage. We determine the conditions for such an event by performing predictive, model-based, safety checks. Furthermore, we use the geographical layout of the ICS and the safety predictions to identify data that is at risk of being lost due to damage, i.e., relevant data. Finally, to reduce the control performance overhead resulting from real-time data collection, we select a subset of relevant data to collect by performing a trade-off between expected impact of the attack and the estimated cost of collection. We demonstrate these ideas using simulations of the widely-used Tennessee–Eastman Process (TEP) benchmark. We show that the proposed approach does not miss relevant data and results in a reduced control performance overhead compared to the case when all data generated by the ICS is collected. We also showcase the applicability of our approach in improving the efficiency of existing ICS forensic log analysis tools.
Mazen Azzam, Liliana Pasquale, Gregory M. Provan, Bashar Nuseibeh
Comput. Secur.1
2022 Grounds for Suspicion: Physics-Based Early Warnings for Stealthy Attacks on Industrial Control Systems
abstract
Stealthy attackson Industrial Control Systems can cause significant damage while evading detection. In this article, instead of focusing on the detection of stealthy attacks, we aim to provide early warnings to operators, in order to avoid physical damage and preserve in advance data that may serve as an evidence during an investigation. We propose a framework to providegrounds for suspicion, i.e., preliminary indicators reflecting the likelihood of success of a stealthy attack. We propose two grounds for suspicion based on the behaviour of the physical process: (i)feasibilityof a stealthy attack, and (ii)proximityto unsafe operating regions. We propose a metric to measure grounds for suspicion in real-time and provide soundness principles to ensure that such a metric is consistent with the grounds for suspicion. We apply our framework to Linear Time-Invariant (LTI) systems and formulate the suspicion metric computation as a real-time reachability problem. We validate our framework on a case study involving the benchmark Tennessee-Eastman process. We show through numerical simulation that we can provide early warnings well before a potential stealthy attack can cause damage, while incurring minimal load on the network. Finally, we apply our framework on a use case to illustrate its usefulness in supporting early evidence collection.
Mazen Azzam, Liliana Pasquale, Gregory M. Provan, Bashar Nuseibeh
IEEE Trans. Dependable Secur. Comput.1
2020 Towards a Quantum based GA Search for an Optimal Artificial Neural Networks Architecture and Feature Selection to Model NOx Emissions: A Case Study
abstract
This paper describes the methodology used to design a NOxpredictive emissions monitoring system (PEMS) based on an artificial neural network (ANN). To find the optimal ANN architecture, a QGA-based search was performed over the set of possible model architectures, the activation function in each layer and the learning rate were architecture parameters taken into consideration. In addition, the QGA performed feature selection to remove non-significant input parameters that did not contribute significantly to the output. The objective function included penalties for network complexity and generalization error, among which a newly introduced penalty that makes use of the effective number of parameters provided by Bayesian Regularization. The developed framework was tested on data collected from a power plant consisting of twelve diesel engine-powered generators. It was found that the newly introduced penalty was enough to yield well-performing ANN's who demonstrated superior performance when compared to some traditional ML models, with up to a 75% reduction in the mean relative error when compared with a normal radial-basis network. In addition, the QGA was better at avoiding local optima, and on average converged in half the time required for the classical GA to converge.
Mazen Azzam, Joseph Zeaiter, Mariette Awad
CEC1