A System-level Behavioral Detection Framework for Compromised CPS Devices: Smart-Grid Case

12/02/2019
by   Leonardo Babun, et al.
0

Cyber-Physical Systems (CPS) play a significant role in our critical infrastructure networks from power-distribution to utility networks. The emerging smart-grid concept is a compelling critical CPS infrastructure that relies on two-way communications between smart devices to increase efficiency, enhance reliability, and reduce costs. However, compromised devices in the smart grid poses several security challenges. Consequences of propagating fake data or stealing sensitive smart grid information via compromised devices are costly. Hence, early behavioral detection of compromised devices is critical for protecting the smart grid's components and data. To address these concerns, in this paper, we introduce a novel and configurable system-level framework to identify compromised smart grid devices. The framework combines system and function call tracing techniques with signal processing and statistical analysis to detect compromised devices based on their behavioral characteristics. We measure the efficacy of our framework with a realistic smart grid substation testbed that includes both resource-limited and resource-rich devices. In total, using our framework, we analyze six different types of compromised device scenarios with different resources and attack payloads. To the best of our knowledge, the proposed framework is the first in detecting compromised CPS smart grid devices with system and function-level call tracing techniques. The experimental results reveal an excellent rate for the detection of compromised devices. Specifically, performance metrics include accuracy values between 95 Finally, the performance analysis demonstrates that the use of the proposed framework has minimal overhead on the smart grid devices' computing resources.

READ FULL TEXT
research
04/13/2018

Detection of Compromised Smart Grid Devices with Machine Learning and Convolution Techniques

The smart grid concept has transformed the traditional power grid into a...
research
02/19/2018

Cost-efficient QoS-Aware Data Acquisition Point Placement for Advanced Metering Infrastructure

In an advanced metering infrastructure (AMI), data acquisition points (D...
research
07/13/2021

Toward Safe Integration of Legacy SCADA Systems in the Smart Grid

A SCADA system is a distributed network of cyber-physical devices used f...
research
05/24/2022

Smart Grid: Cyber Attacks, Critical Defense Approaches, and Digital Twin

As a national critical infrastructure, the smart grid has attracted wide...
research
09/03/2018

IoTDots: A Digital Forensics Framework for Smart Environments

IoT devices and sensors have been utilized in a cooperative manner to en...
research
04/16/2022

A Hierarchical Terminal Recognition Approach based on Network Traffic Analysis

Recognizing the type of connected devices to a network helps to perform ...
research
07/11/2022

Experimental End-To-End Delay Analysis of LTE cat-M With High-Rate Synchrophasor Communications

Micro-Phasor Measurement Units (u-PMUs) are devices that permit monitori...

Please sign up or login with your details

Forgot password? Click here to reset