Dealing with Advanced Persistent Threats in Smart Grid ICT Networks

被引:0
|
作者
Skopik, Florian [1 ]
Friedberg, Ivo [1 ]
Fiedler, Roman [1 ]
机构
[1] AIT Austrian Inst Technol, Safety & Secur Dept, Vienna, Austria
关键词
anomaly detection; event correlation; ict security; SECURITY;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the increasing use of novel smart grid technologies, a comprehensive ICT network will be established in parallel to the electricity grid, which due to its large size, number of participants and access points will be exposed to similar threats as those seen on the current Internet. However, modern security systems that are applied in today's highly dynamic ICT networks, including malware scanners and intrusion detection systems, apply a kind of black-list approach, where they consider only actions and behavior that match to well-known attack patterns and signatures of malware traces. We argue that for the smart grid a more restrictive approach, that cannot be circumvented by customized malware, will increase the security level tremendously. Therefore, in this paper we present a smart white-list approach. Our anomaly detection technique keeps track of system events, their dependencies and occurrences, and thus learns the normal system behavior over time and reports all actions that differ from the created system model. The application of such a system is promising in a smart grid environment which mostly implements well-specified processes, resulting in rather predictable and static behavior. We demonstrate the application of the system in a small-scale pilot case of a real utility provider.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] Preventing Advanced Persistent Threats in Complex Control Networks
    Rubio, Juan E.
    Alcaraz, Cristina
    Lopez, Javier
    [J]. COMPUTER SECURITY - ESORICS 2017, PT II, 2017, 10493 : 402 - 418
  • [2] Review and Evaluation of Security Threats on the Communication Networks in the Smart Grid
    Lu, Zhuo
    Lu, Xiang
    Wang, Wenye
    Wang, Cliff
    [J]. MILITARY COMMUNICATIONS CONFERENCE, 2010 (MILCOM 2010), 2010, : 1830 - 1835
  • [3] Advanced Persistent Threats
    Ozzengin, Yavuz Selim
    Sakiz, Fatih
    Benzer, Recep
    [J]. 2016 24TH SIGNAL PROCESSING AND COMMUNICATION APPLICATION CONFERENCE (SIU), 2016, : 1845 - 1848
  • [4] Security Evaluation of the Cyber Networks Under Advanced Persistent Threats
    Yang, Lu-Xing
    Li, Pengdeng
    Yang, Xiaofan
    Tang, Yuan Yan
    [J]. IEEE ACCESS, 2017, 5 : 20111 - 20123
  • [5] Handling of advanced persistent threats and complex incidents in healthcare, transportation and energy ICT infrastructures
    Papastergiou, Spyridon
    Mouratidis, Haralambos
    Kalogeraki, Eleni-Maria
    [J]. EVOLVING SYSTEMS, 2021, 12 (01) : 91 - 108
  • [6] Handling of advanced persistent threats and complex incidents in healthcare, transportation and energy ICT infrastructures
    Spyridon Papastergiou
    Haralambos Mouratidis
    Eleni-Maria Kalogeraki
    [J]. Evolving Systems, 2021, 12 : 91 - 108
  • [7] Defense Against Advanced Persistent Threats in Smart Grids: A Reinforcement Learning Approach
    Ning, Baifeng
    Xiao, Liang
    [J]. 2021 PROCEEDINGS OF THE 40TH CHINESE CONTROL CONFERENCE (CCC), 2021, : 8598 - 8603
  • [8] A Study on Advanced Persistent Threats
    Chen, Ping
    Desmet, Lieven
    Huygens, Christophe
    [J]. COMMUNICATIONS AND MULTIMEDIA SECURITY, CMS 2014, 2014, 8735 : 63 - 72
  • [9] Security Threats and Dealing with Social Networks
    Barati R.
    [J]. SN Computer Science, 4 (1)
  • [10] Analysis of the Cybersecurity Threats in Smart Grid
    Stoyanov, I. S.
    Iliev, T. B.
    Mihaylov, G. Y.
    Evstatiev, B. I.
    Sokolov, S. A.
    [J]. 2018 IEEE 24TH INTERNATIONAL SYMPOSIUM FOR DESIGN AND TECHNOLOGY IN ELECTRONIC PACKAGING (SIITME), 2018, : 90 - 93