Industrial control systems that manage the UK’s power grids, water supplies, and transport networks will continuously shift their own operational parameters to throw off stealthy cyberattacks. The problem is that conventional security measures are static—once an attacker learns the system’s fixed behaviour, they can manipulate controls without triggering alarms, even if they are insiders with legitimate access. This project builds a defence that constantly varies key settings, guided by physics-based models that ensure changes stay within safe operational limits. If an unexpected fluctuation violates physical laws, the system flags it as suspicious, even if it falls within normal thresholds. The impact is a proactive, rather than reactive, security layer for critical infrastructure. By eliminating the need for external hardware and adapting to both large plants and small facilities, the platform could reduce implementation costs while revealing sophisticated attacks that current tools miss. Success would mean fewer false alarms for operators, faster response to genuine threats, and a more resilient digital backbone for the UK’s essential services.
View original technical description
Industrial Control Systems (ICS) are the backbone of critical infrastructure, managing essential services such as energy, water, transportation, and manufacturing. However, they are increasingly vulnerable to sophisticated cyberattacks. One of the key challenges in ICS security is the potential for attackers to manipulate system controls while avoiding detection. Such threats can come from both external actors and insiders---individuals with legitimate access to system operations. Although our project is not specifically designed to target insider threats, it enhances overall resilience against such risks by dynamically adjusting key operational parameters in a controlled and safe manner. These parameters are carefully selected to maintain operational stability while introducing variability that disrupts potential attack strategies. Unlike conventional defences, which are static and reactive, our solution continuously changes the system's vulnerable points and key parameters that attackers rely on to design stealthy attacks, using dynamic, multi-parameter perturbation. Instead of relying on a fixed security model, our system intelligently varies operational conditions in a way that remains fully functional but unpredictable to attackers. The key innovation here is that these adjustments are guided by physics-informed decision-making, ensuring that any changes align with the real-world constraints of industrial operations and Operational Technology (OT). This means security measures can be enforced without disrupting normal activities, maintaining both safety and efficiency. By synthesising IT, OT, and CVE data with MITRE techniques and integrating real-time data with predictive, physics-based models, our platform provides operators with enhanced situational awareness. This allows them to distinguish between normal operational fluctuations and potential cyber intrusions, significantly reducing false positives, revealing stealthy sophisticated attacks, and enabling rapid response to threats. For example, if an unexpected fluctuation occurs that does not align with physical laws, the system flags it as suspicious, even if it falls within normal operational thresholds. Our approach leverages selective, built-in system parameters through our multi-parameter perturbation technique, therefore, eliminating the need for external hardware, reducing implementation expenses while maintaining robust security. Designed as a modular and scalable platform, our solution adapts to various ICS architectures, making it accessible to both large-scale industrial operators and smaller facilities. With the increasing frequency and sophistication of cyberattacks on critical infrastructure, there is a pressing need for proactive and intelligent defence strategies. Our project not only addresses this need but also aligns with the objectives of the National Cyber Strategy, contributing to a more secure and resilient digital infrastructure in the UK.
Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.
Is something wrong? Let us know