Dealing with Advanced Persistent Threats in Smart Grid ICT Networks

被引:0
|
作者
Skopik, Florian [1 ]
Friedberg, Ivo [1 ]
Fiedler, Roman [1 ]
机构
[1] AIT Austrian Inst Technol, Safety & Secur Dept, Vienna, Austria
关键词
anomaly detection; event correlation; ict security; SECURITY;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the increasing use of novel smart grid technologies, a comprehensive ICT network will be established in parallel to the electricity grid, which due to its large size, number of participants and access points will be exposed to similar threats as those seen on the current Internet. However, modern security systems that are applied in today's highly dynamic ICT networks, including malware scanners and intrusion detection systems, apply a kind of black-list approach, where they consider only actions and behavior that match to well-known attack patterns and signatures of malware traces. We argue that for the smart grid a more restrictive approach, that cannot be circumvented by customized malware, will increase the security level tremendously. Therefore, in this paper we present a smart white-list approach. Our anomaly detection technique keeps track of system events, their dependencies and occurrences, and thus learns the normal system behavior over time and reports all actions that differ from the created system model. The application of such a system is promising in a smart grid environment which mostly implements well-specified processes, resulting in rather predictable and static behavior. We demonstrate the application of the system in a small-scale pilot case of a real utility provider.
引用
收藏
页数:5
相关论文
共 50 条
  • [31] Surviving Advanced Persistent Threats - a Framework and Analysis
    Mehresh, Ruchika
    Upadhyaya, Shambhu
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015), 2015, : 445 - 454
  • [32] Dimensions of 'Socio' Vulnerabilities of Advanced Persistent Threats
    Nicho, Mathew
    McDermott, Christopher D.
    [J]. 2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 521 - 525
  • [33] Mitigating Exploits, Rootkits and Advanced Persistent Threats
    Durham, David
    [J]. 2014 IEEE HOT CHIPS 26 SYMPOSIUM (HCS), 2014,
  • [34] Hidden Markov models for advanced persistent threats
    Brogi, Guillaume
    Di Bernardino, Elena
    [J]. International Journal of Security and Networks, 2019, 14 (04) : 181 - 190
  • [35] A novel approach for detecting advanced persistent threats
    Al-Saraireh, Jaafer
    Masarweh, Ala'
    [J]. EGYPTIAN INFORMATICS JOURNAL, 2022, 23 (04) : 45 - 55
  • [36] Targeted Cyberattacks: A Superset of Advanced Persistent Threats
    Sood, Aditya K.
    Enbody, Richard J.
    [J]. IEEE SECURITY & PRIVACY, 2013, 11 (01) : 54 - 61
  • [37] Tree Balancing in Smart Grid Advanced Metering Infrastructure Mesh Networks
    Kulkarni, Parag
    Gormus, Sedat
    Fan, Zhong
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND COMMUNICATIONS, CONFERENCE ON INTERNET OF THINGS, AND CONFERENCE ON CYBER, PHYSICAL AND SOCIAL COMPUTING (GREENCOM 2012), 2012, : 109 - 115
  • [38] Wireless Sensor Networks and Advanced Metering Infrastructure Deployment in Smart Grid
    Longe, Omowunmi M.
    Ouahada, Khmaies
    Ferreira, Hendrick C.
    Rimer, Suvendi
    [J]. E-INFRASTRUCTURE AND E-SERVICES FOR DEVELOPING COUNTRIES, AFRICOMM 2013, 2014, 135 : 167 - 171
  • [39] Optimal Deployment of Cellular Networks for Advanced Measurement Infrastructure in Smart Grid
    Inga, Esteban
    Arevalo, German
    Hincapie, Roberto
    [J]. 2014 IEEE COLOMBIAN CONFERENCE ON COMMUNICATIONS AND COMPUTING (COLCOM), 2014,
  • [40] Current and Future Threats Framework in Smart Grid Domain
    Procopiou, A.
    Komninos, N.
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON CYBER TECHNOLOGY IN AUTOMATION, CONTROL, AND INTELLIGENT SYSTEMS (CYBER), 2015, : 1852 - 1857