Man-in-the-middle attacks and defence in a power system cyber-physical testbed

被引:39
|
作者
Wlazlo, Patrick [1 ]
Sahu, Abhijeet [2 ]
Mao, Zeyu [2 ]
Huang, Hao [2 ]
Goulart, Ana [1 ,2 ]
Davis, Katherine [2 ]
Zonouz, Saman [3 ]
机构
[1] Texas A&M Univ, Elect Syst Engn Technol, College Stn, TX 77843 USA
[2] Texas A&M Univ, Elect & Comp Engn, College Stn, TX USA
[3] Rutgers State Univ, Elect & Comp Engn, New Brunswick, NJ USA
关键词
33;
D O I
10.1049/cps2.12014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Man-in-The-Middle (MiTM) attacks present numerous threats to a smart grid. In a MiTM attack, an intruder embeds itself within a conversation between two devices to either eavesdrop or impersonate one of the devices, making it appear to be a normal exchange of information. Thus, the intruder can perform false data injection (FDI) and false command injection (FCI) attacks that can compromise power system operations, such as state estimation, economic dispatch, and automatic generation control (AGC). Very few researchers have focused on MiTM methods that are difficult to detect within a smart grid. To address this, we are designing and implementing multi-stage MiTM intrusions in an emulation-based cyber-physical power system testbed against a large-scale synthetic grid model to demonstrate how such attacks can cause physical contingencies such as misguided operation and false measurements. MiTM intrusions create FCI, FDI, and replay attacks in this synthetic power grid. This work enables stakeholders to defend against these stealthy attacks, and we present detection mechanisms that are developed using multiple alerts from intrusion detection systems and network monitoring tools. Our contribution will enable other smart grid security researchers and industry to develop further detection mechanisms for inconspicuous MiTM attacks.
引用
收藏
页码:164 / 177
页数:14
相关论文
共 50 条
  • [11] Framework of a benchmark testbed for power system cyber-physical reliability studies
    Lei, Hangtian
    Chakhchoukh, Yacine
    Singh, Chanan
    INTERNATIONAL TRANSACTIONS ON ELECTRICAL ENERGY SYSTEMS, 2019, 29 (01)
  • [12] Testbed for LoRaWAN Security: Design and Validation through Man-in-the-Middle Attacks Study
    Pospisil, Ondrej
    Fujdiak, Radek
    Mikhaylov, Konstantin
    Ruotsalainen, Henri
    Misurec, Jiri
    APPLIED SCIENCES-BASEL, 2021, 11 (16):
  • [13] A Cyber-Physical Testbed Design for the Electric Power Grid
    O'Toole, Zachary
    Moya, Christian
    Rubin, Connor
    Schnabel, Alec
    Wang, Jiankang
    2019 51ST NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2019,
  • [14] Software Defined Cyber-Physical Testbed for Analysis of Automated Cyber Responses for Power System Security
    Ulrich, Jacob J.
    Vaagensmith, Bjorn C.
    Rieger, Craig G.
    Welch, Justin J.
    2019 RESILIENCE WEEK (RWS), 2019, : 47 - 54
  • [15] Cyber-physical attacks on power distribution systems
    Ayad, Abdelrahman
    Farag, Hany
    Youssef, Amr
    El-Saadany, Ehab
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2020, 5 (02) : 218 - 225
  • [16] Advancing Future Space Habitation: A Cyber-Physical Testbed for Space Power System
    Nisar, Hasnain
    Chebbo, Leila
    Bazzi, Ali M.
    Zhang, Yang
    Xue, Chuanyu
    Tang, Jiong
    Han, Song
    IEEE Power Electronics Magazine, 2024, 11 (03): : 26 - 36
  • [17] A Networked Cyber-Physical System Testbed for Undergraduate Education
    Rodriguez-Seda, Erick J.
    Frontera, Paul J.
    Bradshaw, Joseph
    IECON 2018 - 44TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2018, : 3007 - 3012
  • [18] MPC for the Cyber-Physical System with Deception Attacks
    Liu, Yuezhi
    Chen, Yong
    Li, Meng
    Wan, Zhi
    PROCEEDINGS OF THE 32ND 2020 CHINESE CONTROL AND DECISION CONFERENCE (CCDC 2020), 2020, : 3847 - 3852
  • [19] Impact of Man-In-The-Middle Attacks on Ethereum
    Ekparinya, Parinya
    Gramoli, Vincent
    Jourjon, Guillaume
    2018 IEEE 37TH INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2018, : 11 - 20
  • [20] Taxonomy of Man-in-the-Middle Attacks on HTTPS
    Stricot-Tarboton, Shaun
    Chaisiri, Sivadon
    Ko, Ryan K. L.
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 527 - 534