Threat analysis and adversarial model for Smart Grids

被引:0
作者
Sande-Rios, Javier [1 ]
Canal-Sanchez, Jesus [1 ]
Manzano-Hernandez, Carmen [1 ]
Pastrana, Sergio [1 ]
机构
[1] Univ Carlos III Madrid, Madrid, Spain
来源
9TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW 2024 | 2024年
关键词
Smart Grid; Cybersecurity; Adversarial Model; Power Grid; Critical Infrastructures; ATTACKS;
D O I
10.1109/EuroSPW61312.2024.00020
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The power grid is a critical infrastructure that allows for the efficient and robust generation, transmission, delivery and consumption of electricity. In the recent years, the physical components have been equipped with computing and network devices, which optimizes the operation and maintenance of the grid. The cyber domain of this smart power grid opens a new plethora of threats, which adds to classical threats on the physical domain. Accordingly, different stakeholders including regulation bodies, industry and academy, are making increasing efforts to provide security mechanisms to mitigate and reduce cyber-risks. Despite these efforts, there have been various cyberattacks that have affected the smart grid, leading in some cases to catastrophic consequences, showcasing that the industry might not be prepared for attacks from high profile adversaries. At the same time, recent work shows a lack of agreement among grid practitioners and academic experts on the feasibility and consequences of academic-proposed threats. This is in part due to inadequate simulation models which do not evaluate threats based on attackers full capabilities and goals. To address this gap, in this work we first analyze the main attack surfaces of the smart grid, and then conduct a threat analysis from the adversarial model perspective, including different levels of knowledge, goals, motivations and capabilities. To validate the model, we provide real-world examples of the potential capabilities by studying known vulnerabilities in critical components, and then analyzing existing cyber-attacks that have affected the smart grid, either directly or indirectly.
引用
收藏
页码:130 / 145
页数:16
相关论文
共 74 条
  • [1] Attacks on smart grid: power supply interruption and malicious power generation
    Adepu, Sridhar
    Kandasamy, Nandha Kumar
    Zhou, Jianying
    Mathur, Aditya
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (02) : 189 - 211
  • [2] A review on renewable energy and electricity requirement forecasting models for smart grid and buildings
    Ahmad, Tanveer
    Zhang, Hongcai
    Yan, Biao
    [J]. SUSTAINABLE CITIES AND SOCIETY, 2020, 55
  • [3] [Anonymous], Official Common Platform Enumeration (CPE) Dictionary
  • [4] [Anonymous], 2019, BBC NEWS
  • [5] Review of the Data-Driven Methods for Electricity Fraud Detection in Smart Metering Systems
    Badr, Mahmoud M.
    Ibrahem, Mohamed I.
    Kholidy, Hisham A.
    Fouda, Mostafa M.
    Ismail, Muhammad
    [J]. ENERGIES, 2023, 16 (06)
  • [6] Brook Chris, 2016, Blackenergy apt group spreading malware via tainted word docs
  • [7] Assessing a Potential Cyberattack on the Italian Electric System
    Bruno, Clementina
    Guidi, Luca
    Lorite-Espejo, Azahara
    Pestonesi, Daniela
    [J]. IEEE SECURITY & PRIVACY, 2015, 13 (05) : 42 - 51
  • [8] CERT-UA, 2022, Cyberattack of the sandworm group (uac-0082) on energy facilities of ukraine using industroyer2 and caddywiper malware (cert-ua-4435)
  • [9] Cherepanov Anton, 2022, Industroyer 2-sandworm's cyberwarfare targets ukraine's power grid again
  • [10] Clueley Graham, 2017, Attack on ireland's state-owned power provider blamed on state-sponsored hackers