On specification-based cyber-attack detection in smart grids

被引:1
|
作者
Sen Ö. [1 ,2 ]
van der Velde D. [1 ,2 ]
Lühman M. [1 ]
Sprünken F. [1 ]
Hacker I. [1 ,2 ]
Ulbig A. [1 ,2 ]
Andres M. [1 ,2 ]
Henze M. [3 ,4 ]
机构
[1] High Voltage Equipment and Grids, Digitalization and Energy Economics, RWTH Aachen University, Schinkelstraße 6, Aachen
[2] Fraunhofer Institute for Applied Information Technology FIT, Schloss Birlinghoven, Konrad-Adenauer-Straße, Sankt Augustin
[3] Security and Privacy in Industrial Cooperation, RWTH Aachen University, Ahornstraße 55, Aachen
[4] Fraunhofer Institute for Communication, Information Processing and Ergonomics FKIE, Fraunhoferstraße 20, Wachtberg
关键词
Cyber physical systems; Cyber security; Intrusion detection systems;
D O I
10.1186/s42162-022-00206-7
中图分类号
学科分类号
摘要
The transformation of power grids into intelligent cyber-physical systems brings numerous benefits, but also significantly increases the surface for cyber-attacks, demanding appropriate countermeasures. However, the development, validation, and testing of data-driven countermeasures against cyber-attacks, such as machine learning-based detection approaches, lack important data from real-world cyber incidents. Unlike attack data from real-world cyber incidents, infrastructure knowledge and standards are accessible through expert and domain knowledge. Our proposed approach uses domain knowledge to define the behavior of a smart grid under non-attack conditions and detect attack patterns and anomalies. Using a graph-based specification formalism, we combine cross-domain knowledge that enables the generation of whitelisting rules not only for statically defined protocol fields but also for communication flows and technical operation boundaries. Finally, we evaluate our specification-based intrusion detection system against various attack scenarios and assess detection quality and performance. In particular, we investigate a data manipulation attack in a future-orientated use case of an IEC 60870-based SCADA system that controls distributed energy resources in the distribution grid. Our approach can detect severe data manipulation attacks with high accuracy in a timely and reliable manner. © 2022, The Author(s).
引用
收藏
相关论文
共 50 条
  • [1] Specification-based Intrusion Detection for Home Area Networks in Smart Grids
    Jokar, Paria
    Nicanfar, Hasen
    Leung, Victor C. M.
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2011,
  • [2] Smart Grids Cyber-Attack Defense: A Solution Based on an Incremental Learning Support Vector Machine
    Alves, Helton do Nascimento
    Bretas, Arturo S.
    Bretas, Newton G.
    [J]. 2019 51ST NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2019,
  • [3] Simulation and Analysis of Cyber-Attack on Modbus Protocol for Smart Grids in Virtual Environment
    Banik, Shampa
    Manicavasagam, Rajesh
    Banik, Trapa
    Banik, Shudipta
    [J]. INTELLIGENT COMPUTING, VOL 2, 2024, 2024, 1017 : 384 - 401
  • [4] Data Mining Based Cyber-Attack Detection
    TIANFIELD Huaglory
    [J]. 系统仿真技术, 2017, 13 (02) : 90 - 104
  • [5] Observer-based cyber attack detection and isolation in smart grids
    Luo, Xiaoyuan
    Yao, Qian
    Wang, Xinyu
    Guan, Xinping
    [J]. INTERNATIONAL JOURNAL OF ELECTRICAL POWER & ENERGY SYSTEMS, 2018, 101 : 127 - 138
  • [6] A Deep and Scalable Unsupervised Machine Learning System for Cyber-Attack Detection in Large-Scale Smart Grids
    Karimipour, Hadis
    Dehghantanha, Ali
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    Leung, Henry
    [J]. IEEE ACCESS, 2019, 7 : 80778 - 80788
  • [7] Enhanced Anomaly Detection for Cyber-Attack Detection in Smart Water Distribution Systems
    Stojanovic, Branka
    Neuschmied, Helmut
    Winter, Martin
    Kleb, Ulrike
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [8] Online Cyber-Attack Detection in Smart Grid: A Reinforcement Learning Approach
    Kurt, Mehmet Necip
    Ogundijo, Oyetunji
    Li, Chong
    Wang, Xiaodong
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2019, 10 (05) : 5174 - 5185
  • [9] Cyber-attack group analysis method based on association of cyber-attack information
    Son, Kyung-ho
    Kim, Byung-ik
    Lee, Tae-jin
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2020, 14 (01): : 260 - 280
  • [10] Cognitive Dynamic System for Control and Cyber-Attack Detection in Smart Grid
    Oozeer, Mohammad Irshaad
    Haykin, Simon
    [J]. IEEE ACCESS, 2019, 7 : 78320 - 78335