On Specification-based Cyber-Attack Detection in Smart Grids

The transformation of power grids into intelligent cyber-physical systems brings numerous benefits, but also significantly increases the surface for cyber-attacks, demanding appropriate countermeasures. However, the development, validation, and testing of data-driven countermeasures against cyber-attacks, such as machine learning-based detection approaches, lack important data from real-world cyber incidents. Unlike attack data from real-world cyber incidents, infrastructure knowledge and standards are accessible through expert and domain knowledge. Our proposed approach uses domain knowledge to define the behavior of a smart grid under non-attack conditions and detect attack patterns and anomalies. Using a graph-based specification formalism, we combine cross-domain knowledge that enables the generation of whitelisting rules not only for statically defined protocol fields but also for communication ows and technical operation boundaries. Finally, we evaluate our specification-based intrusion detection system against various attack scenarios and assess detection quality and performance. In particular, we investigate a data manipulation attack in a future-orientated use case of an IEC 60870-based SCADA system that controls distributed energy resources in the distribution grid. Our approach can detect severe data manipulation attacks with high accuracy in a timely and reliable manner.

READ FULL TEXT

page 1

page 7

page 11

research
11/20/2022

On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach

While digitization of distribution grids through information and communi...
research
12/16/2021

A Heterogeneous Graph Learning Model for Cyber-Attack Detection

A cyber-attack is a malicious attempt by experienced hackers to breach t...
research
09/06/2021

Towards an Approach to Contextual Detection of Multi-Stage Cyber Attacks in Smart Grids

Electric power grids are at risk of being compromised by high-impact cyb...
research
06/09/2018

Application of Correlation Indices on Intrusion Detection Systems: Protecting the Power Grid Against Coordinated Attacks

The future power grid will be characterized by the pervasive use of hete...
research
10/21/2021

Attack Detection and Localization in Smart Grid with Image-based Deep Learning

Smart grid's objective is to enable electricity and information to flow ...
research
07/06/2021

SAGE: Intrusion Alert-driven Attack Graph Extractor

Attack graphs (AG) are used to assess pathways availed by cyber adversar...
research
06/28/2021

Towards anomaly detection in smart grids by combining Complex Events Processing and SNMP objects

This paper describes the architecture and the fundamental methodology of...

Please sign up or login with your details

Forgot password? Click here to reset