2024 年 37 巻 4 号 p. 109-118
As the frequency and types of cyber-attacks on control systems are increasing, it is important to recover from cyber-attacks in addition to detecting and preventing cyber-attacks. The objective of this paper is to design the sequence of operations to return the control system to a normal state as recovery control in the event of cyber-attacks. Representing control system behaviors in terms of finite automata, this paper recasts the design of recovery operations as a path finding problem. In this case, it is important to avoid secondary damages due to the obtained recovery operation, such as collisions between field devices. Then, this paper also considers the safety of the recovery operation. The basic idea of the safety is the specification of the normal control in which the collisions are avoid. The proposed method evaluates whether the recovery operation satisfies the specification of the normal control.