DDoS Cyber-Incident Detection in Smart Grids

被引:5
|
作者
Merlino, Jorge C. [1 ]
Asiri, Mohammed [1 ]
Saxena, Neetesh [1 ]
机构
[1] Cardiff Univ, Sch Comp Sci & Informat, Cardiff CF10 3AT, Wales
关键词
IOC; industrial control systems; DDoS; situational awareness; smart grid;
D O I
10.3390/su14052730
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
The smart grid (SG) offers potential benefits for utilities, electric generators, and customers alike. However, the prevalence of cyber-attacks targeting the SG emphasizes its dark side. In particular, distributed denial-of-service (DDoS) attacks can affect the communication of different devices, interrupting the SG's operation. This could have profound implications for the power system, including area blackouts. The problem is that few operational technology tools provide reflective DDoS protection. Furthermore, such tools often fail to classify the types of attacks that have occurred. Defensive capabilities are necessary to identify the footprints of attacks in a timely manner, as they occur, and to make these systems sustainable for delivery of the services as expected. To meet this need for defensive capabilities, we developed a situational awareness tool to detect system compromise by monitoring the indicators of compromise (IOCs) of amplification DDoS attacks. We achieved this aim by finding IOCs and exploring attack footprints to understand the nature of such attacks and their cyber behavior. Finally, an evaluation of our approach against a real dataset of DDoS attack instances indicated that our tool can distinguish and detect different types of amplification DDoS attacks.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] A Review of Possibilities and Solutions of Cyber Attacks in Smart Grids
    Yadav, Suman Avdhesh
    Kumar, Shipra Ravi
    Sharma, Smita
    Singh, Akanksha
    2016 1ST INTERNATIONAL CONFERENCE ON INNOVATION AND CHALLENGES IN CYBER SECURITY (ICICCS 2016), 2016, : 60 - 63
  • [32] Ensemble Regression Model-Based Anomaly Detection for Cyber-Physical Intrusion Detection in Smart Grids
    Kosek, Anna Magdalena
    Gehrke, Oliver
    2016 IEEE ELECTRICAL POWER AND ENERGY CONFERENCE (EPEC), 2016,
  • [33] Detection of cyber attacks in smart grids using SVM-boosted machine learning models
    Hathal Salamah Alwageed
    Service Oriented Computing and Applications, 2022, 16 : 313 - 326
  • [34] Detection of cyber attacks in smart grids using SVM-boosted machine learning models
    Alwageed, Hathal Salamah
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2022, 16 (04) : 313 - 326
  • [35] Specialized CSIRT for Incident Response Management in Smart Grids
    Martins, Rafael de Jesus
    Dias Knob, Luis Augusto
    da Silva, Eduardo Germano
    Wickboldt, Juliano Araujo
    Schaeffer-Filho, Alberto
    Granville, Lisandro Zambenedetti
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2019, 27 (01) : 269 - 285
  • [36] Specialized CSIRT for Incident Response Management in Smart Grids
    Rafael de Jesus Martins
    Luis Augusto Dias Knob
    Eduardo Germano da Silva
    Juliano Araujo Wickboldt
    Alberto Schaeffer-Filho
    Lisandro Zambenedetti Granville
    Journal of Network and Systems Management, 2019, 27 : 269 - 285
  • [37] Islanding detection in smart grids
    Timbus, Adrian
    Oudalov, Alexandre
    Ho, Carl N. M.
    2010 IEEE ENERGY CONVERSION CONGRESS AND EXPOSITION, 2010, : 3631 - 3637
  • [38] Cyber-physical security for Low-Voltage Smart Grids HAN Security within Smart Grids
    Czechowski, Robert
    PROCEEDINGS OF THE 2015 16TH INTERNATIONAL SCIENTIFIC CONFERENCE ON ELECTRIC POWER ENGINEERING (EPE), 2015, : 77 - 82
  • [39] DDoS attack detection in smart home applications
    Chandak, Ashish Virendra
    Ray, Niranjan Kumar
    SOFTWARE-PRACTICE & EXPERIENCE, 2024, 54 (10): : 2086 - 2101
  • [40] Preliminary Studies of the Security of the Cyber-Physical Smart Grids
    Rabelo, Luis
    Ballestas, Andres
    Ibrahim, Bibi
    Valdez, Javier
    APPLIED INFORMATICS (ICAI 2021), 2021, 1455 : 449 - 461