<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    jis
   </journal-id>
   <journal-title-group>
    <journal-title>
     Journal of Information Security
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    2153-1234
   </issn>
   <issn publication-format="print">
    2153-1242
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/jis.2025.161008
   </article-id>
   <article-id pub-id-type="publisher-id">
    jis-138710
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Computer Science 
     </subject>
     <subject>
       Communications
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    Architecture to Secure Electrical Control System in Cyber-Physical System
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Depeng
      </surname>
      <given-names>
       Li
      </given-names>
     </name>
    </contrib>
   </contrib-group> 
   <aff id="affnull">
    <addr-line>
     aDepartment of Information and Computer Sciences, University of Hawaii at Manoa, Honolulu, HI, USA
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     19
    </day> 
    <month>
     11
    </month>
    <year>
     2024
    </year>
   </pub-date> 
   <volume>
    16
   </volume> 
   <issue>
    01
   </issue>
   <fpage>
    149
   </fpage>
   <lpage>
    157
   </lpage>
   <history>
    <date date-type="received">
     <day>
      29,
     </day>
     <month>
      October
     </month>
     <year>
      2024
     </year>
    </date>
    <date date-type="published">
     <day>
      31,
     </day>
     <month>
      October
     </month>
     <year>
      2024
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      31,
     </day>
     <month>
      December
     </month>
     <year>
      2024
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    It’s possible for malicious operators to seize hold of electrical control systems, for instance, the engine control unit of driverless vehicles, from various vectors, e.g. autonomic control system, remote vehicle access, or human drivers. To mitigate potential risks, this paper provides the inauguration study by proposing a theoretical framework in the physical, human and cyber triad. Its goal is to, at each time point, detect adversary control behaviors and protect control systems against malicious operations via integrating a variety of methods. This paper only proposes a theoretical framework which tries to indicate possible threats. With the support of the framework, the security system can lightly reduce the risk. The development and implementation of the system are out of scope.
   </abstract>
   <kwd-group> 
    <kwd>
     Architecture
    </kwd> 
    <kwd>
      Control System
    </kwd> 
    <kwd>
      Framework
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>1. Introduction</title>
   <p>In the past, cyber-attacks have not been introduced to our world. The malfunction of the control system has only been treated as a mechanical device failure. Customers’ safety is rarely threatened by hackers via remote access cyber channels. Nowadays, electronic control systems are vulnerable to different kinds of attacks. Automobiles, for instance, can be manipulated by hackers through a variety of attack vectors <xref ref-type="bibr" rid="scirp.138710-1">
     [1]
    </xref>-<xref ref-type="bibr" rid="scirp.138710-4">
     [4]
    </xref>. In this paper, we would like to find the right operator when malicious ones are trying to take it over.</p>
   <p>Previously, control systems such as automobiles, robots, and so on were handled only by onsite human operators. Gradually, control privileges have been granted to industrial autonomic control systems and, then, be granted to remote access cyber systems through network communication channels. This paradigm shift offers incredible productivity and much more convenience. But a security concern has also been introduced: it is possible that autonomic control systems have been taken over by the wrong hand: the human operator can act maliciously, the autonomic control system can be infected, and the remote access cyber system can be compromised by hackers. The recent growth of misbehavior activities covers all possible aspects of Cyber Physical Systems (CPS) <xref ref-type="bibr" rid="scirp.138710-1">
     [1]
    </xref>-<xref ref-type="bibr" rid="scirp.138710-4">
     [4]
    </xref>. This paper’s major motivation is that since adversaries could potentially launch attacks from every channel, we should mitigate the risks by identifying the malicious controllers and then preventing their attacks.</p>
   <p>This paper intends to propose a theoretical framework that protects control systems against malicious operations launched by attackers, ranging from human operators to automation control systems to remote access cyber control systems. This paper, specifically, focuses on a system with more than one controller. Each of them can independently operate the control system. The main questions we want to address are 1) how to detect the malicious CPS controllers; 2) how to protect the control system after the malicious CPS controller is identified.</p>
   <p>This paper cannot totally solve the problems above. But, to partially answer these questions, the new ideas are to 1) Propose the Physical, Human and Cyber Triad; and 2) Establish a quantitative framework that aims to develop a set of metrics which are used to assess and analyze the security condition of each controller instance. The driverless vehicle is used as a case study to verify this idea.</p>
   <p>This paper can neither eliminate any attacks nor develop any real-time systems. Its goal is to lightly mitigate risks resulting from the aforementioned misbehaviors by proposing a framework.</p>
  </sec><sec id="s2">
   <title>2. Related Works</title>
   <p>From the perspective of human operators, various guides, manuals or frameworks are published to regulate operations impacting safety, reliability and security <xref ref-type="bibr" rid="scirp.138710-1">
     [1]
    </xref> <xref ref-type="bibr" rid="scirp.138710-5">
     [5]
    </xref> <xref ref-type="bibr" rid="scirp.138710-6">
     [6]
    </xref>. As an example of an automation control system, the Supervisor Control and Data Acquisition (SCADA) control system was analyzed in areas of malware that could compromise critical infrastructure systems <xref ref-type="bibr" rid="scirp.138710-7">
     [7]
    </xref>.</p>
   <p>To study the problem of human-in-the-loop feedback control systems, modeling human behavior and incorporating the model into the formal feedback control system are briefly addressed <xref ref-type="bibr" rid="scirp.138710-8">
     [8]
    </xref>. A cyber-physical-social based security architecture (namely, IPM) studied three critical security perspectives: information, physical, and management <xref ref-type="bibr" rid="scirp.138710-9">
     [9]
    </xref>. Physical security is addressed by artificial immunity, and management security is achieved through social strategies. But, to the best of my knowledge, less attention is paid to studying critical topics: 1) effectively preventing malicious activities in CPS over the control system and 2) withdrawing the access right from misbehavior controllers have not been carefully studied.</p>
   <p>To evaluate malicious activities and to prevent cyber-attacks, the reputation of hosts has been widely studied, which can detect, filter and block the misbehavior activities such as spam, unauthorized access control, etc. <xref ref-type="bibr" rid="scirp.138710-10">
     [10]
    </xref>.</p>
  </sec><sec id="s3">
   <title>3. Theoretical Background</title>
   <sec id="s3_1">
    <title>3.1. Group Key Scheme</title>
    <p>In order to grant/withdraw the access right over the control system, we will leverage the Group Key Scheme <xref ref-type="bibr" rid="scirp.138710-11">
      [11]
     </xref>, based on which the new CPS controller can join and the malicious CPS controller can be forced to leave. In this paper, each controller’s activities will be viewed/audited by other peer controllers in real time.</p>
    <p>The group key scheme we utilized includes two components: 1) efficient and reliable group key agreement; 2) virtual synchrony view. The former ensures that only the present group members contain the current group key. Malicious controllers will be expelled based on their misbehavior. The group key is a symmetric key shared among all current group members in such a way that the control commands or measured statuses will be encrypted by the group key during their transmission over control systems. A group key scheme should satisfy two privacies: 1) Forward secrecy: previous group members who know contiguous subsets of old group keys must not be able to discover subsequent group keys after they leave the group. 2) Backward secrecy: current group members who know a contiguous subset of current group keys must not be able to discover preceding group keys. The virtual synchrony view means that, if processes 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        p 
      </mi> 
     </math> and 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        q 
      </mi> 
     </math> install the same new view 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        V 
      </mi> 
     </math> in the same previous view 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <msup> 
       <mi>
         V 
       </mi> 
       <mo>
         ′ 
       </mo> 
      </msup> 
     </math>, then any message received by 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        p 
      </mi> 
     </math> in 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <msup> 
       <mi>
         V 
       </mi> 
       <mo>
         ′ 
       </mo> 
      </msup> 
     </math> is also received by 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        q 
      </mi> 
     </math> in 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <msup> 
       <mi>
         V 
       </mi> 
       <mo>
         ′ 
       </mo> 
      </msup> 
     </math>. So,</p>
    <p>
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         i 
       </mi> 
       <mi>
         n 
       </mi> 
       <mi>
         s 
       </mi> 
       <mi>
         t 
       </mi> 
       <mi>
         a 
       </mi> 
       <mi>
         l 
       </mi> 
       <mi>
         l 
       </mi> 
       <msub> 
        <mi>
          s 
        </mi> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mi>
           n 
         </mi> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <mi>
             p 
           </mi> 
           <mo>
             , 
           </mo> 
           <mi>
             V 
           </mi> 
           <mo>
             , 
           </mo> 
           <msup> 
            <mi>
              V 
            </mi> 
            <mo>
              ′ 
            </mo> 
           </msup> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
        </mrow> 
       </msub> 
       <mo>
         ∧ 
       </mo> 
       <mi>
         i 
       </mi> 
       <mi>
         n 
       </mi> 
       <mi>
         s 
       </mi> 
       <mi>
         t 
       </mi> 
       <mi>
         a 
       </mi> 
       <mi>
         l 
       </mi> 
       <msub> 
        <mi>
          l 
        </mi> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mi>
           n 
         </mi> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <mi>
             q 
           </mi> 
           <mo>
             , 
           </mo> 
           <mi>
             V 
           </mi> 
           <mo>
             , 
           </mo> 
           <msup> 
            <mi>
              V 
            </mi> 
            <mo>
              ′ 
            </mo> 
           </msup> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
        </mrow> 
       </msub> 
       <mo>
         ∧ 
       </mo> 
       <mi>
         r 
       </mi> 
       <mi>
         e 
       </mi> 
       <mi>
         c 
       </mi> 
       <mi>
         e 
       </mi> 
       <mi>
         i 
       </mi> 
       <mi>
         v 
       </mi> 
       <msub> 
        <mi>
          e 
        </mi> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mi>
           n 
         </mi> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <mi>
             p 
           </mi> 
           <mo>
             , 
           </mo> 
           <mi>
             m 
           </mi> 
           <mo>
             , 
           </mo> 
           <msup> 
            <mi>
              V 
            </mi> 
            <mo>
              ′ 
            </mo> 
           </msup> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
        </mrow> 
       </msub> 
       <mo>
         → 
       </mo> 
       <mi>
         r 
       </mi> 
       <mi>
         e 
       </mi> 
       <mi>
         c 
       </mi> 
       <mi>
         e 
       </mi> 
       <mi>
         i 
       </mi> 
       <mi>
         v 
       </mi> 
       <mi>
         e 
       </mi> 
       <msub> 
        <mi>
          s 
        </mi> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mi>
           n 
         </mi> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <mi>
             q 
           </mi> 
           <mo>
             , 
           </mo> 
           <mi>
             m 
           </mi> 
           <mo>
             , 
           </mo> 
           <msup> 
            <mi>
              V 
            </mi> 
            <mo>
              ′ 
            </mo> 
           </msup> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
        </mrow> 
       </msub> 
       <mo>
         . 
       </mo> 
      </mrow> 
     </math> (1)</p>
    <p>Authentication and integrity will be provided for group keys to prevent attacks, e.g., Man-In-The-Middle attacks, etc. But we will not explain the details here.</p>
   </sec>
   <sec id="s3_2">
    <title>3.2. Supervisory Control Theory</title>
    <p>Our research tries to isolate the malicious CPS controllers from the control system by employing the supervisory control theory in which discrete state spaces and event-driven dynamics are widely used. From the viewpoint of discrete event systems, the control system under protection can be modelled as a plant to which the supervisory controllers send control actions. The control system is treated as the feedback control of dynamic systems, the specification of which is represented as finite-state automata over the set of discrete events. Any actions from the controllers will force the control system to make discrete changes and, consequently, generate a sequence of discrete events that can formulate transition-based, event-driven models. Research focusing on the models can analyze the security, safety, reliability, etc. <xref ref-type="bibr" rid="scirp.138710-12">
      [12]
     </xref>. Due to its capability to quickly detect and isolate malfunctions, the fault detection and diagnosis methodology synthesizing to discrete state event-driven dynamics is further studied to model the control system’s activities and to further deduce controllers’ misbehavior <xref ref-type="bibr" rid="scirp.138710-13">
      [13]
     </xref>. However, it is still a concern that they are sensitive to noises, which may easily lead to false alarms during normal operations.</p>
   </sec>
   <sec id="s3_3">
    <title>3.3. Rejection for Cyber Misbehaviors</title>
    <p>The reputation of a host <xref ref-type="bibr" rid="scirp.138710-10">
      [10]
     </xref> has been treated as a vital metric which measures the security condition of a host. Based on the reputation value, some systems construct a list of rejections. The purpose is to block/filter the inbound or outbound traffic sent from/forwarded to hosts in the list.</p>
   </sec>
  </sec><sec id="s4">
   <title>4. Overview of the Proposed System</title>
   <sec id="s4_1">
    <title>4.1. Problem Descriptions</title>
    <p>A control system, for example, a driverless vehicle, could be driven by a few controllers. At each time point 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          t 
        </mi> 
        <mi>
          i 
        </mi> 
       </msub> 
      </mrow> 
     </math>, the vehicle received a few control commands, one of which was issued by the controller in charge. Our decision is based on the current status of the vehicle (e.g. speed, engine brake, gas, light, etc.), context around the vehicle (e.g. other vehicles at the same lane or different lanes, road condition, etc.), and the mission of this trip. Then, we need to figure out how to evaluate which control command is safe. If the control command in charge is malicious, how can we find the right from others? To be more generic, let us assume the controller may be physical, cyber or human operators, namely, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         O 
       </mi> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            O 
          </mi> 
          <mi>
            x 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math>, where 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         x 
       </mi> 
       <mo>
         = 
       </mo> 
       <mn>
         1 
       </mn> 
       <mo>
         , 
       </mo> 
       <mo>
         ⋯ 
       </mo> 
       <mi>
         n 
       </mi> 
      </mrow> 
     </math>. Let 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        P 
      </mi> 
     </math> denote the control system, say, driverless vehicle which is fed with a number of control commands from different controllers at every time point. Therefore, at a sequence of time points, 
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mn>
            1 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mn>
            2 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <mo>
           ⋯ 
         </mo> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            m 
          </mi> 
         </msub> 
         <mo>
           , 
         </mo> 
         <mo>
           ⋯ 
         </mo> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math>, there are a series of control commands 
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mrow> 
           <mrow> 
            <mo>
              { 
            </mo> 
            <mrow> 
             <msub> 
              <mi>
                c 
              </mi> 
              <mrow> 
               <msub> 
                <mi>
                  O 
                </mi> 
                <mn>
                  1 
                </mn> 
               </msub> 
              </mrow> 
             </msub> 
             <mo>
               , 
             </mo> 
             <msub> 
              <mi>
                c 
              </mi> 
              <mrow> 
               <msub> 
                <mi>
                  O 
                </mi> 
                <mn>
                  2 
                </mn> 
               </msub> 
              </mrow> 
             </msub> 
             <mo>
               , 
             </mo> 
             <mo>
               ⋯ 
             </mo> 
            </mrow> 
            <mo>
              } 
            </mo> 
           </mrow> 
          </mrow> 
          <mrow> 
           <msub> 
            <mi>
              t 
            </mi> 
            <mn>
              1 
            </mn> 
           </msub> 
          </mrow> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mrow> 
           <mrow> 
            <mo>
              { 
            </mo> 
            <mrow> 
             <msub> 
              <mi>
                c 
              </mi> 
              <mrow> 
               <msub> 
                <mi>
                  O 
                </mi> 
                <mn>
                  1 
                </mn> 
               </msub> 
              </mrow> 
             </msub> 
             <mo>
               , 
             </mo> 
             <msub> 
              <mi>
                c 
              </mi> 
              <mrow> 
               <msub> 
                <mi>
                  O 
                </mi> 
                <mn>
                  2 
                </mn> 
               </msub> 
              </mrow> 
             </msub> 
             <mo>
               , 
             </mo> 
             <mo>
               ⋯ 
             </mo> 
            </mrow> 
            <mo>
              } 
            </mo> 
           </mrow> 
          </mrow> 
          <mrow> 
           <msub> 
            <mi>
              t 
            </mi> 
            <mn>
              2 
            </mn> 
           </msub> 
          </mrow> 
         </msub> 
         <mo>
           , 
         </mo> 
         <mo>
           ⋯ 
         </mo> 
         <mrow> 
          <mo>
            { 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mn>
                1 
              </mn> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mn>
                2 
              </mn> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <mo>
             ⋯ 
           </mo> 
          </mrow> 
          <mo>
            } 
          </mo> 
         </mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            m 
          </mi> 
         </msub> 
         <mo>
           ⋯ 
         </mo> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math>. At each time point, the mobile control system could be at a status, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mi>
          k 
        </mi> 
       </msub> 
      </mrow> 
     </math> where 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mi>
          k 
        </mi> 
       </msub> 
       <mo>
         ∈ 
       </mo> 
       <mi>
         S 
       </mi> 
      </mrow> 
     </math> and 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mi>
          k 
        </mi> 
       </msub> 
       <mo>
         = 
       </mo> 
       <msub> 
        <mrow> 
         <mrow> 
          <mo>
            [ 
          </mo> 
          <mi>
            M 
          </mi> 
          <mo>
            ] 
          </mo> 
         </mrow> 
        </mrow> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mo>
           × 
         </mo> 
         <mi>
           j 
         </mi> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> and 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         i 
       </mi> 
       <mo>
         , 
       </mo> 
       <mi>
         j 
       </mi> 
       <mo>
         , 
       </mo> 
       <mi>
         m 
       </mi> 
      </mrow> 
     </math> are integers. Note that 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mrow> 
         <mrow> 
          <mo>
            [ 
          </mo> 
          <mi>
            M 
          </mi> 
          <mo>
            ] 
          </mo> 
         </mrow> 
        </mrow> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mo>
           × 
         </mo> 
         <mi>
           j 
         </mi> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> represents a block of key parameters which are measured from object, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        P 
      </mi> 
     </math>. The problem we would like to address is that, at time point 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          t 
        </mi> 
        <mi>
          i 
        </mi> 
       </msub> 
      </mrow> 
     </math>, we need to select a control command 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          c 
        </mi> 
        <mi>
          x 
        </mi> 
       </msub> 
       <mo>
         ∈ 
       </mo> 
       <msub> 
        <mrow> 
         <mrow> 
          <mo>
            { 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mn>
                1 
              </mn> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mn>
                2 
              </mn> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <mo>
             ⋯ 
           </mo> 
          </mrow> 
          <mo>
            } 
          </mo> 
         </mrow> 
        </mrow> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> in a sense that 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          c 
        </mi> 
        <mi>
          x 
        </mi> 
       </msub> 
      </mrow> 
     </math> will lead driverless vehicle from status 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> to 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mrow> 
           <mi>
             i 
           </mi> 
           <mo>
             + 
           </mo> 
           <mn>
             1 
           </mn> 
          </mrow> 
         </msub> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> in which the condition 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mrow> 
           <mi>
             i 
           </mi> 
           <mo>
             + 
           </mo> 
           <mn>
             1 
           </mn> 
          </mrow> 
         </msub> 
        </mrow> 
       </msub> 
      </mrow> 
     </math> is safe. The challenge is (1) how to validate 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          c 
        </mi> 
        <mi>
          x 
        </mi> 
       </msub> 
      </mrow> 
     </math> in case of the context set 
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            φ 
          </mi> 
          <mn>
            1 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            φ 
          </mi> 
          <mn>
            2 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <mo>
           ⋯ 
         </mo> 
         <msub> 
          <mi>
            φ 
          </mi> 
          <mi>
            n 
          </mi> 
         </msub> 
         <mo>
           ⋯ 
         </mo> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math> and the mission 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        M 
      </mi> 
     </math> where 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          φ 
        </mi> 
        <mi>
          i 
        </mi> 
       </msub> 
      </mrow> 
     </math> is one element of context, (2) how to drop the malicious commands and (3) how to punish the corresponding unsafe controller.</p>
   </sec>
   <sec id="s4_2">
    <title>4.2. Physical-Human-Cyber Triad</title>
    <p>As depicted in <xref ref-type="fig" rid="fig1">
      Figure 1
     </xref>, our paper proposes a new physical, human and cyber triad system, which is comprised of three components (sketched as circles), each denoting one type of controller.</p>
    <p>The system under protection is represented by the “control system” blocks (sketched as rectangles), which abstract a general model with such instances as modern vehicles, unmanned robots, etc. The solid, directional links connecting controller elements and the control system blocks denote the capability of the control privilege, and the dashed links represent functions of collecting statuses from control systems.</p>
    <p>A controller operates control systems through three channels: the human operators drive the handle, e.g., function lever, the automation control systems execute embedded operational instructions in firmware, and the remote access cyber systems forward control commands that are encapsulated in packets through cyber communication channels.</p>
    <fig id="fig1" position="float">
     <label>Figure 1</label>
     <caption>
      <title>Figure 1. Physical, Human and Cyber (PHC) Triad.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/7801059-rId76.jpeg?20250103114018" />
    </fig>
    <p>This paper assumes that any controller in a physical, human and cyber triad could act maliciously since, even if not hostile at the beginning, it may potentially be compromised by attackers in future. The paper will use this conceptual architecture to offer a quantitative, abstract model to assess the compromised controller based on their misbehavior activities and to further provide a mechanism which can withdraw the control privileges after the detection of corresponding attacks.</p>
   </sec>
   <sec id="s4_3">
    <title>4.3. Architecture</title>
    <p>This paper seeks to mitigate the threat introduced by the following problems for each physical, human and cyber controller: 1) Define a variety of metrics to model the misbehaviors over the control systems; 2) Construct the quantitative framework to evaluate the security conditions of the control system based on the captured operational commands and the corresponding results; and 3) Define reputation index thresholds in the quantitative framework and withdraw adversary controller’s control privilege when its reputation index is beyond the threshold.</p>
    <p>Note that this paper only proposes the framework rather than studying the details due to the limited space.</p>
    <p>So, the following work will not be considered in this paper. But they can be accomplished in our future work:</p>
    <p>1) Fulfill numerous data collection, data separation, and data analyses over not only control commands instructed by all physical, human and cyber controllers but also the status result data measured over the control system for both before and after the control commands are executed;</p>
    <p>2) Construct a generic model to measure a set of essential metrics which can not only evaluate the security condition of control systems but also assess other critical parameters such as reliability, safety and so on;</p>
    <p>3) Design the quantitative framework indicating the security level for each controller, namely, the autonomic controller, human operators, and remote access cyber controllers. Security conditions will be assessed by discrete-state event-driven fault-diagnosis theories <xref ref-type="bibr" rid="scirp.138710-14">
      [14]
     </xref> <xref ref-type="bibr" rid="scirp.138710-15">
      [15]
     </xref>, by human operation manuals <xref ref-type="bibr" rid="scirp.138710-1">
      [1]
     </xref> <xref ref-type="bibr" rid="scirp.138710-5">
      [5]
     </xref> <xref ref-type="bibr" rid="scirp.138710-6">
      [6]
     </xref>, by finite-state machines, and by reputation systems <xref ref-type="bibr" rid="scirp.138710-10">
      [10]
     </xref>, and;</p>
    <p>4) Withdraw the malicious controllers’ control privileges via group key schemes <xref ref-type="bibr" rid="scirp.138710-11">
      [11]
     </xref> after attacks are detected.</p>
   </sec>
  </sec><sec id="s5">
   <title>5. Our System</title>
   <p>We outline our system here, but the detailed implementation will be our future task. As depicted in <xref ref-type="fig" rid="fig2">
     Figure 2
    </xref>, our architecture includes four layers.</p>
   <fig id="fig2" position="float">
    <label>Figure 2</label>
    <caption>
     <title>Figure 2. Architecture of our system.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/7801059-rId77.jpeg?20250103114019" />
   </fig>
   <p>In the control layer, control commands are issued by physical (autonomic control system), remote access cyber, and human operators.</p>
   <p>In the quantitative layer, a set of metrics is established for each controller in the physical, human and cyber triad. Each controller’s metric indicator decides whether this controller instance is malicious or not. In the access control layer, the detected malicious controller instance will be expelled from the group key agreement in such a way that a new group key is generated, and the expelled group member cannot access the new group key. So, there is no chance for it to send its control commands to the control system.</p>
   <p>In the system layer, the control system decrypts the ciphertext command by using the new group key and then executes the command. Malicious/illegal controller instances’ ciphertext cannot be correctly decrypted since they cannot hold the current group key. Just notice that the controller instance can access the control systems by utilizing wearable devices such as a master card/token.</p>
   <p>Note that after executions, the monitored statuses of the control system will be used to analyze the behavior of each control command. If the result is unsafe/negative or even an alarm is triggered, the negative value will be reflected in the metric indicators of corresponding controllers. The loopback of the control system is critical for this paper as it demonstrates each controller’s behavior, which impacts its reputation index.</p>
   <sec id="s5_1">
    <title>5.1. Subsystem</title>
    <p>Capture Control Commands and Statuses:</p>
    <p>We collect the control commands that are issued by physical, human, and cyber controllers, as well as a finite sequence of statuses of control systems. Those raw data will be de-noised, stored, classified, filtered and evaluated through a set of pre-processing operations or algorithms.</p>
    <p>Autonomic control system (P): we first map a sequence of observable events 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         E 
       </mi> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            e 
          </mi> 
          <mn>
            1 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            e 
          </mi> 
          <mn>
            2 
          </mn> 
         </msub> 
         <mo>
           ⋯ 
         </mo> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            e 
          </mi> 
          <mi>
            n 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math> to a set of control actions 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         C 
       </mi> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            c 
          </mi> 
          <mn>
            1 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            c 
          </mi> 
          <mn>
            2 
          </mn> 
         </msub> 
         <mo>
           ⋯ 
         </mo> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            c 
          </mi> 
          <mi>
            n 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math>. Function 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         F 
       </mi> 
       <mo>
         : 
       </mo> 
       <mi>
         E 
       </mi> 
       <mo>
         × 
       </mo> 
       <mi>
         C 
       </mi> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            e 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
       <mo>
         × 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            c 
          </mi> 
          <mi>
            j 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math>. Our intrusion detection system is defined as 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        I 
      </mi> 
     </math> (a fault-diagnosis function). The control loop 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         A 
       </mi> 
       <mo>
         → 
       </mo> 
       <mi>
         F 
       </mi> 
      </mrow> 
     </math> (where A: finite-state automation) is named as a potential attack if the action 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          c 
        </mi> 
        <mi>
          j 
        </mi> 
       </msub> 
      </mrow> 
     </math> is misbehavior and if the 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          e 
        </mi> 
        <mi>
          i 
        </mi> 
       </msub> 
      </mrow> 
     </math> is one of the fault states of the control system. Combining the active fault-diagnosis theory and the finite-state automation method, the intrusion detection 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        I 
      </mi> 
     </math> could abstract the control system as discrete-state event-driven dynamic and identify the misbehavior or attacks as an active fault event. If a fault even occurs, the corresponding action 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          c 
        </mi> 
        <mi>
          j 
        </mi> 
       </msub> 
      </mrow> 
     </math> will be traced back to its controller, whose reputation index, in turn, will be impacted.</p>
    <p>Human Operator (H): wrong human operations can negatively impact the control systems, which are shown as different kinds of symptoms. We can collect a number of symptoms led by the misbehavior which will be treated as complementary to some well-known guides or user manuals <xref ref-type="bibr" rid="scirp.138710-1">
      [1]
     </xref> <xref ref-type="bibr" rid="scirp.138710-5">
      [5]
     </xref> <xref ref-type="bibr" rid="scirp.138710-6">
      [6]
     </xref>. They altogether can correct the mis-operation and stop adversaries.</p>
    <p>Cyber remote control (C): we will analyze the malicious activities launched from remote access cyber controller through the method for data collection and measurement. Its result reflects the reputation index of each specific remote host, based on which the list of rejection can be constructed.</p>
    <p>Misbehavior Abstraction, Profiling and Modeling:</p>
    <p>While analyzing control commands, we aim to identify, profile, model and filter attacks based on a formal method via utilizing finite-state machine, namely 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        Φ 
      </mi> 
     </math>, which is listed below:</p>
    <p>
     <xref ref-type="bibr" rid="scirp.138710-"></xref> 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         S 
       </mi> 
       <mo>
         × 
       </mo> 
       <mi>
         C 
       </mi> 
       <mover> 
        <mo>
          → 
        </mo> 
        <mi>
          Φ 
        </mi> 
       </mover> 
       <mi>
         S 
       </mi> 
       <mo>
         × 
       </mo> 
       <mi>
         O 
       </mi> 
      </mrow> 
     </math> (2)</p>
    <p>
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         Φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <mi>
           S 
         </mi> 
         <mo>
           , 
         </mo> 
         <mi>
           C 
         </mi> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
       <mo>
         = 
       </mo> 
       <mi>
         Φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <mi>
           S 
         </mi> 
         <mo>
           , 
         </mo> 
         <mrow> 
          <mo>
            { 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mn>
              1 
            </mn> 
           </msub> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mn>
              2 
            </mn> 
           </msub> 
           <mo>
             , 
           </mo> 
           <mo>
             ⋯ 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mi>
              n 
            </mi> 
           </msub> 
          </mrow> 
          <mo>
            } 
          </mo> 
         </mrow> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math> (3)</p>
    <p>
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mo>
         = 
       </mo> 
       <mi>
         Φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <mi>
           Φ 
         </mi> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <mi>
             S 
           </mi> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mn>
              1 
            </mn> 
           </msub> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
         <mo>
           , 
         </mo> 
         <mrow> 
          <mo>
            { 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mn>
              2 
            </mn> 
           </msub> 
           <mo>
             , 
           </mo> 
           <mo>
             ⋯ 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mi>
              n 
            </mi> 
           </msub> 
          </mrow> 
          <mo>
            } 
          </mo> 
         </mrow> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math> (4)</p>
    <p>where</p>
    <p>S is the state,</p>
    <p>C is the control command sequence,</p>
    <p>O is the output,</p>
    <p>c<sub>n</sub> is each control command.</p>
    <p>Record Misbehavior:</p>
    <p>Regarding each control command c<sub>i</sub> on the list of rejection, the controller which sends out c<sub>i</sub>, will be impacted for its reputation index.</p>
    <p>Access Control (group key scheme):</p>
    <p>The group key will be rekeyed, which can guarantee both forward privacy and backward privacy. Thus, the expelled controller cannot get the subsequent group keys. The control system is assumed to always hold the current group key and therefore can decrypt the ciphertext. The other advantage is that peer and legal controllers can audit others’ activities in order to prevent the misbehavior via group key.</p>
   </sec>
   <sec id="s5_2">
    <title>5.2. Case Study</title>
    <p>Let us take a driverless car as an example: at a time point 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          t 
        </mi> 
        <mi>
          i 
        </mi> 
       </msub> 
      </mrow> 
     </math>, a few controllers, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          h 
        </mi> 
       </msub> 
      </mrow> 
     </math>, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          p 
        </mi> 
       </msub> 
       <mo>
         , 
       </mo> 
      </mrow> 
     </math> and 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          c 
        </mi> 
       </msub> 
      </mrow> 
     </math> represent the human driver, the physical automation control device in the vehicle and the remote access cyber control program, respectively. They issue control command 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mrow> 
         <mrow> 
          <mo>
            { 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mi>
                h 
              </mi> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mi>
                p 
              </mi> 
             </msub> 
            </mrow> 
           </msub> 
           <mo>
             , 
           </mo> 
           <msub> 
            <mi>
              c 
            </mi> 
            <mrow> 
             <msub> 
              <mi>
                O 
              </mi> 
              <mi>
                c 
              </mi> 
             </msub> 
            </mrow> 
           </msub> 
          </mrow> 
          <mo>
            } 
          </mo> 
         </mrow> 
        </mrow> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
       </msub> 
      </mrow> 
     </math>. In our paper, since each of 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          h 
        </mi> 
       </msub> 
      </mrow> 
     </math>, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          p 
        </mi> 
       </msub> 
       <mo>
         , 
       </mo> 
      </mrow> 
     </math> and 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          c 
        </mi> 
       </msub> 
      </mrow> 
     </math> could be malicious, we will choose the right control command 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          O 
        </mi> 
        <mi>
          r 
        </mi> 
       </msub> 
      </mrow> 
     </math> for driverless vehicle 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mi>
        P 
      </mi> 
     </math> based on the current context set 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math> and the vehicle statuses, 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          S 
        </mi> 
        <mi>
          k 
        </mi> 
       </msub> 
       <mo>
         = 
       </mo> 
       <msub> 
        <mrow> 
         <mrow> 
          <mo>
            [ 
          </mo> 
          <mi>
            M 
          </mi> 
          <mo>
            ] 
          </mo> 
         </mrow> 
        </mrow> 
        <mrow> 
         <mi>
           i 
         </mi> 
         <mo>
           × 
         </mo> 
         <mi>
           j 
         </mi> 
        </mrow> 
       </msub> 
      </mrow> 
     </math>. The context set 
     <math xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         φ 
       </mi> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            t 
          </mi> 
          <mi>
            i 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math> could include the road traffic, the speed of other vehicles in front/behind the vehicle or at neighbor lanes, the pedestrian on the road, the condition of the road, parking space, gas level, map service, and so on. In a word, the context, together with the current status of the vehicle as well as the mission of the trip, can decide whether the vehicle is safe or not. Our future work includes both simulation and real-world experiments.</p>
   </sec>
  </sec><sec id="s6">
   <title>6. Conclusion</title>
   <p>In this paper, the proposed solution can decide which control command is malicious and how to select the right one from the others. We also record the malicious commands/misbehavior, which will impact the controller’s reputation index. The scheme could lightly mitigate the attacks from a variety of control vectors for CPS. Furthermore, this paper not only provides a framework to identify the misbehavior of the adversary controllers in the Physical, Human and Cyber triad, but also briefly explains how to construct a dataset. The dataset contains the misbehavior based on the specific status of the driverless vehicle and the corresponding context set. The goal of this paper is the development of a framework for protecting control systems against malicious operations. We cannot completely eliminate the attack but rather mitigate the risk resulting from misbehaviors.</p>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.138710-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     How to Prevent a Robot Rebellion. &gt;http://www.createthefuturecontest.com/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     India Blackouts (2012) Report on Grid Disturbance on 30th&amp;31st July 2012. &gt;http://www.cercind.gov.in/2012 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     (2014) US Military Begins Research into Moral, Ethical Robots, to Stave off Skynet-Like Apocalypse. &gt;http://www.extremetech.com/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Checkoway, S., et al. (2011) Comprehensive Experimental Analyses of Automotive Attack Surfaces. USENIX Security Symposium 2011, San Francisco, 8-12 August 2011, 1-16.
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Hawaii Driver’s Manual. &gt;https://m.driving-tests.org/hawaii/hi-dmv-drivers-handbook-manual/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Substation Operation and Maintenance. &gt;https://www.energy-consult.net/en/services/operation-maintenance-of-substations/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Cardenas, A.A., Amin, S. and Sastry, S. (2008) Secure Control: Towards Survivable Cyber-Physical Systems. 2008 The 28th International Conference on Distributed Computing Systems Workshops, Beijing, 17-20 June 2008, 495-500. &gt;https://doi.org/10.1109/icdcs.workshops.2008.40 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Munir, S., Stankovic, J.A., Mike Liang, C.-J. and Lin, S. (2014) Cyber Physical System Challenges for Human-in-the-Loop Control. The 8th Workshop on Feedback Computing, USENIX Security 2014, San Diego, 20-22 August 2014, 1-4.
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ning, H. and Liu, H. (2012) Cyber-Physical-Social Based Security Architecture for Future Internet of Things. Advances in Internet of Things, 2, 1-7. &gt;https://doi.org/10.4236/ait.2012.21001 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Pathak, A., Qian, F., Hu, Y.C., Mao, Z.M. and Ranjan, S. (2009) Botnet Spam Campaigns Can Be Long Lasting. ACM Sigmetrics Performance Evaluation Review, 37, 13-24. &gt;https://doi.org/10.1145/2492101.1555352 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Li, D. and Sampalli, S. (2008) A Hybrid Group Key Management Protocol for Reliable and Authenticated Rekeying. International Journal of Network Security, 6, 228-270.
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Girard, A. and Pappas, G.J. (2007) Approximation Metrics for Discrete and Continuous Systems. IEEE Transactions on Automatic Control, 52, 782-798. &gt;https://doi.org/10.1109/tac.2007.895849 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Luzar, M., Czajkowski, A., Witczak, M. and Korbicz, J. (2012) Actuators and Sensors Fault Diagnosis with Dynamic, State-Space Neural Networks. 2012 17th International Conference on Methods&amp;Models in Automation&amp;Robotics (MMAR), Miedzyzdroje, 27-30 August 2012, 196-201. &gt;https://doi.org/10.1109/mmar.2012.6347889 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref14">
    <label>14</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Banerjee, A., Venkatasubramanian, K.K., Mukherjee, T. and Gupta, S.K.S. (2012) Ensuring Safety, Security, and Sustainability of Mission-Critical Cyber–Physical Systems. Proceedings of the IEEE, 100, 283-299. &gt;https://doi.org/10.1109/jproc.2011.2165689 
    </mixed-citation>
   </ref>
   <ref id="scirp.138710-ref15">
    <label>15</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Li, D., Aung, Z., Williams, J.R. and Sanchez, A. (2014) Efficient and Fault-Diagnosable Authentication Architecture for AMI in Smart Grid. Security and Communication Networks, 8, 598-616. &gt;https://doi.org/10.1002/sec.1006
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>