{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T13:57:14Z","timestamp":1760709434777,"version":"build-2065373602"},"reference-count":36,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2017,10,21]],"date-time":"2017-10-21T00:00:00Z","timestamp":1508544000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Natural Science Foundation of  China","award":["61572514"],"award-info":[{"award-number":["61572514"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61402527"],"award-info":[{"award-number":["61402527"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>A cyber-physical attack in the industrial Internet of Things can cause severe damage to physical system. In this paper, we focus on the command disaggregation attack, wherein attackers modify disaggregated commands by intruding command aggregators like programmable logic controllers, and then maliciously manipulate the physical process. It is necessary to investigate these attacks, analyze their impact on the physical process, and seek effective detection mechanisms. We depict two different types of command disaggregation attack modes: (1) the command sequence is disordered and (2) disaggregated sub-commands are allocated to wrong actuators. We describe three attack models to implement these modes with going undetected by existing detection methods. A novel and effective framework is provided to detect command disaggregation attacks. The framework utilizes the correlations among two-tier command sequences, including commands from the output of central controller and sub-commands from the input of actuators, to detect attacks before disruptions occur. We have designed components of the framework and explain how to mine and use these correlations to detect attacks. We present two case studies to validate different levels of impact from various attack models and the effectiveness of the detection framework. Finally, we discuss how to enhance the detection framework.<\/jats:p>","DOI":"10.3390\/s17102408","type":"journal-article","created":{"date-parts":[[2017,10,23]],"date-time":"2017-10-23T04:32:19Z","timestamp":1508733139000},"page":"2408","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Command Disaggregation Attack and Mitigation in Industrial Internet of Things"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5225-6118","authenticated-orcid":false,"given":"Peng","family":"Xun","sequence":"first","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pei-Dong","family":"Zhu","sequence":"additional","affiliation":[{"name":"Department of Electronic Information and Electrical Engineering, Changsha University, Changsha 410022, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi-Fan","family":"Hu","sequence":"additional","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng-Shuai","family":"Cui","sequence":"additional","affiliation":[{"name":"College of Computer, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Informatics, University of Oslo, Oslo 0316, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,10,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Fraga-Lamas, P., Fern\u00e1ndez-Caram\u00e9s, T.M., and Castedo, L. (2017). Towards the Internet of Smart Trains: A Review on Industrial IoT-Connected Railways. Sensors, 17.","DOI":"10.3390\/s17061457"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Min, B., and Varadharajan, V. (2016, January 4\u20138). Cascading Attacks Against Smart Grid Using Control Command Disaggregation and Services. Proceedings of the 31st Annual ACM Symposium on Applied Computing, Pisa, Italy.","DOI":"10.1145\/2851613.2853128"},{"key":"ref_3","unstructured":"Taft, J.D. (2012). Control Command Disaggregation and Distribution within A Utility Grid. (20120310435), U.S. Patent."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Remmersmann, T., Schade, U., and Schlick, C. (2012, January 14\u201317). Supervisory control of multi-robot systems by disaggregation and scheduling of quasi-natural language commands. Proceedings of the 2012 IEEE International Conference on Systems, Man, and Cybernetics (SMC), Seoul, Korea.","DOI":"10.1109\/ICSMC.2012.6377720"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"3576","DOI":"10.1109\/TPWRS.2013.2261096","article-title":"Optimal Load Control via Frequency Measurement and Neighborhood Area Communication","volume":"28","author":"Zhao","year":"2013","journal-title":"IEEE Trans. Power Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1553","DOI":"10.1109\/TSG.2015.2491340","article-title":"Improving Frequency Stability Based on Distributed Control of Multiple Load Aggregators","volume":"8","author":"Hu","year":"2017","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Sargolzaei, A., Yen, K., and Abdelghani, M. (2014, January 19\u201322). Delayed inputs attack on load frequency control in smart grid. Proceedings of the Innovative Smart Grid Technologies Conference (ISGT), Washington, DC, USA.","DOI":"10.1109\/ISGT.2014.6816508"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"350","DOI":"10.1109\/TR.2015.2406860","article-title":"Modeling and Analysis of Attacks and Counter Defense Mechanisms for Cyber Physical Systems","volume":"65","author":"Mitchell","year":"2016","journal-title":"IEEE Trans. Reliab."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Amini, S., Mohsenian-Rad, H., and Pasqualetti, F. (2015, January 18\u201320). Dynamic load altering attacks in smart grid. Proceedings of the 2015 IEEE Power Energy Society Innovative Smart Grid Technologies Conference (ISGT), Washington, DC, USA.","DOI":"10.1109\/ISGT.2015.7131791"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ning, P., and Reiter, M.K. (2009, January 9\u201313). False Data Injection Attacks Against State Estimation in Electric Power Grids. In Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago, IL, USA.","DOI":"10.1145\/1653662.1653666"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Yi, P., Zhu, T., Zhang, Q., Wu, Y., and Li, J. (2014, January 10\u201314). A denial of service attack in advanced metering infrastructure network. Proceedings of the 2014 IEEE International Conference on Communications (ICC), Sydney, Australia.","DOI":"10.1109\/ICC.2014.6883456"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2211","DOI":"10.1007\/s11277-015-2510-3","article-title":"Impact of Distributed Denial-of-Service Attack on Advanced Metering Infrastructure","volume":"83","author":"Asri","year":"2015","journal-title":"Wirel. Pers. Commun."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Gacia, L.A., Brasser, F., Cintuglu, M.H., and Sadeghi, A.R. (2017, January 26\u201328). Hey, My Malware Knows Physics Attacking PLCs with Physical Model Aware Rootkit. Proceedings of the Network & Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2017.23313"},{"key":"ref_14","unstructured":"Vu, Q.D., Tan, R., and Yau, D.K.Y. (2016, January 10\u201314). On applying fault detectors against false data injection attacks in cyber-physical control systems. Proceedings of the IEEE INFOCOM 2016\u2014The 35th Annual IEEE International Conference on Computer Communications, San Francisco, CA, USA."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Vuong, T.P., Loukas, G., Gan, D., and Bezemskij, A. (2015, January 16\u201319). Decision tree-based detection of denial of service and command injection attacks on robotic vehicles. Proceedings of the 2015 IEEE International Workshop on Information Forensics and Security (WIFS), Rome, Italy.","DOI":"10.1109\/WIFS.2015.7368559"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1016\/j.cose.2016.01.001","article-title":"False sequential logic attack on SCADA system and its physical impact analysis","volume":"58","author":"Li","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Quarta, D., Pogliani, M., Polino, M., and Maggi, F. (2017, January 22\u201326). An Experimental Security Analysis of an Industrial Robot Controller. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.20"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Tan, R., Nguyen, H.H., Foo, E.Y.S., and Dong, X. (2016, January 11\u201314). Optimal False Data Injection Attack against Automatic Generation Control in Power Grids. Proceedings of the 2016 ACM\/IEEE 7th International Conference on Cyber-Physical Systems (ICCPS), Vienna, Austria.","DOI":"10.1109\/ICCPS.2016.7479109"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1016\/j.jpdc.2016.12.012","article-title":"Distributed host-based collaborative detection for false data injection attacks in smart grid cyber-physical system","volume":"103","author":"Li","year":"2017","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Wang, J.K., and Peng, C. (2017, January 18\u201321). Analysis of Time Delay Attacks Against Power Grid Stability. Proceedings of the 2nd Workshop on Cyber-Physical Security and Resilience in Smart Grids, Pittsburgh, PA, USA.","DOI":"10.1145\/3055386.3055392"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Guo, Y., Ten, C.W., Hu, S., and Weaver, W.W. (2015, January 18\u201320). Modeling distributed denial of service attack in advanced metering infrastructure. Proceedings of the 2015 IEEE Power Energy Society Innovative Smart Grid Technologies Conference (ISGT), Washington, DC, USA.","DOI":"10.1109\/ISGT.2015.7131828"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"449","DOI":"10.1016\/j.future.2015.06.006","article-title":"Robust cyber physical systems: Concept, models, and implementation","volume":"56","author":"Hu","year":"2016","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Cheng, W., Zhang, K., Chen, H., and Jiang, G. (2016, January 13\u201317). Ranking Causal Anomalies via Temporal and Dynamical Analysis on Vanishing Correlations. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939765"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Momtazpour, M., Zhang, J., Rahman, S., Sharma, R., and Ramakrishnan, N. (2015, January 10\u201313). Analyzing Invariants in Cyber-Physical Systems Using Latent Factor Regression. Proceedings of the 21th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Sydney, Australia.","DOI":"10.1145\/2783258.2788605"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Luo, C., Lou, J.G., Lin, Q., Fu, Q., and Ding, R. (2014, January 24\u201327). Correlating Events with Time Series for Incident Diagnosis. Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, New York, NY, USA.","DOI":"10.1145\/2623330.2623374"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Melnyk, I., Banerjee, A., Matthews, B., and Oza, N. (2016, January 13\u201317). Semi-Markov Switching Vector Autoregressive Model-Based Anomaly Detection in Aviation Systems. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939789"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Wang, J., Tu, W., Hui, L.C.K., Yiu, S.M., and Wang, E.K. (2017, January 5\u20138). Detecting Time Synchronization Attacks in Cyber-Physical Systems with Machine Learning Techniques. Proceedings of the 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), Atlanta, GA, USA.","DOI":"10.1109\/ICDCS.2017.25"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1109\/TSMCC.2008.2007248","article-title":"Anomaly Detection and Diagnosis Algorithms for Discrete Symbol Sequences with Applications to Airline Safety","volume":"39","author":"Budalakoti","year":"2009","journal-title":"IEEE Trans. Syst. Man Cybern. Part C (Appl. Rev.)"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1109\/TSM.2017.2721820","article-title":"Failure Prediction Using Sequential Pattern Mining in the Wire Bonding Process","volume":"30","author":"Lim","year":"2017","journal-title":"IEEE Trans. Semicond. Manuf."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"5943","DOI":"10.1002\/sec.1748","article-title":"FairAccess: A new Blockchain-based access control framework for the Internet of Things","volume":"9","author":"Ouaddah","year":"2017","journal-title":"Secur. Commun. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Liu, B., Yu, X.L., Chen, S., Xu, X., and Zhu, L. (2017, January 25\u201330). Blockchain Based Data Integrity Service Framework for IoT Data. Proceedings of the 2017 IEEE International Conference on Web Services (ICWS), Honolulu, HI, USA.","DOI":"10.1109\/ICWS.2017.54"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"587","DOI":"10.1016\/j.isatra.2010.04.003","article-title":"Observer based on-line fault diagnosis of continuous systems modeled as Petri nets","volume":"49","author":"Renganathan","year":"2010","journal-title":"ISA Trans."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Rahmani-andebili, M., and Shen, H. (2017, January 21\u201325). Cooperative distributed energy scheduling for smart homes applying stochastic model predictive controla. Proceedings of the 2017 IEEE International Conference on Communications (ICC), Paris, France.","DOI":"10.1109\/ICC.2017.7996420"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Ci, S., Li, H., and Yang, Y. (2017, January 21\u201325). A new framework for peer-to-peer energy sharing and coordination in the energy internet. Proceedings of the 2017 IEEE International Conference on Communications (ICC), Paris, France.","DOI":"10.1109\/ICC.2017.7996424"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"510","DOI":"10.1109\/TDSC.2011.16","article-title":"Efficient Fault Detection and Diagnosis in Complex Software Systems with Information-Theoretic Monitoring","volume":"8","author":"Jiang","year":"2011","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Sharma, A.B., Chen, H., Ding, M., Yoshihira, K., and Jiang, G. (2013, January 24\u201327). Fault detection and localization in distributed systems using invariant relationships. Proceedings of the 2013 43rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), Budapest, Hungary.","DOI":"10.1109\/DSN.2013.6575304"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/10\/2408\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:48:04Z","timestamp":1760208484000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/10\/2408"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,10,21]]},"references-count":36,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2017,10]]}},"alternative-id":["s17102408"],"URL":"https:\/\/doi.org\/10.3390\/s17102408","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2017,10,21]]}}}