A hybrid cyber-physical risk identification method for grid-connected photovoltaic systems

被引:1
作者
Santos, Maria Fernanda Oliveira [1 ]
Melo Jr, Wilson de Souza [1 ]
de Sa, Alan Oliveira [2 ]
Pasetti, Marco [3 ]
Ferrari, Paolo [3 ]
机构
[1] Natl Inst Metrol Qual & Technol, Duque De Caxias, RJ, Brazil
[2] Univ Lisbon, Fac Ciencias, LASIGE, P-1749016 Lisbon, Portugal
[3] Univ Studi Brescia, Dept Informat Engn, Brescia, Italy
关键词
Distributed Energy Resources; Photovoltaic system; Cyber-physical systems; Risk identification; NIST Cybersecurity Framework; HAZOP; STEALTH ATTACK; MODEL;
D O I
10.1016/j.segan.2024.101490
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
Identifying risks in modern electric power systems is essential, and one of the main difficulties concerns covering the wide range of technologies that permeate its cyber and physical domains. Different risk identification methods have been proposed, but applying them individually does not guarantee coverage of both domains. On the other hand, the simple non-articulated application of a set of existing risk identification methods can lead to an exhaustive and inefficient process. This paper proposes a new Cyber-Physical Risks Identification Method (CPRIM) to comprehensively and efficiently identify risks in electrical power systems. To systematically cover risks ranging from the cyber domain to the physical domain, CPRIM combines in a complimentary and articulated way the National Institute of Standards and Technology (NIST) Cybersecurity Framework, a Risk Factor model, and the HAZOP, establishing a novel hybrid risk identification approach. This work also proposes a method based on Jaccard and overlap indexes to quantitatively assess the complementarity and superposition that may exist when applying different risk identification methods to electrical power systems. The results obtained in a real computer-managed photovoltaic plant indicate that CPRIM can efficiently identify cyber-physical risks, showing a reasonable trade-off between system coverage and redundancy in identified risks.
引用
收藏
页数:16
相关论文
共 58 条
  • [1] Cyber-physical systems and their security issues
    Alguliyev, Rasim
    Imamverdiyev, Yadigar
    Sukhostat, Lyudmila
    [J]. COMPUTERS IN INDUSTRY, 2018, 100 : 212 - 223
  • [2] [Anonymous], 2007, COBIT 41 FRAMEWORK C
  • [3] An analysis of process fault diagnosis methods from safety perspectives
    Arunthavanathan, Rajeevan
    Khan, Faisal
    Ahmed, Salim
    Imtiaz, Syed
    [J]. COMPUTERS & CHEMICAL ENGINEERING, 2021, 145
  • [4] Emerging Risk Management in Industry 4.0: An Approach to Improve Organizational and Human Performance in the Complex Systems
    Brocal, F.
    Gonzalez, C.
    Komljenovic, D.
    Katina, P. F.
    Sebastian, Miguel A.
    [J]. COMPLEXITY, 2019, 2019
  • [5] Center for Internet Security, 2021, CIS Controls(E)
  • [6] Fallback Control for Isochronous Energy Storage Systems in Autonomous Microgrids Under Denial-of-Service Cyber-Attacks
    Chlela, Marline
    Mascarella, Diego
    Joos, Geza
    Kassouf, Marthe
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2018, 9 (05) : 4702 - 4711
  • [7] Energy storage for large scale/utility renewable energy system-An enhanced safety model and risk assessment
    Choo, Boon Leong
    Go, Yun Ii
    [J]. RENEWABLE ENERGY FOCUS, 2022, 42 : 79 - 96
  • [8] Cybersecurity in the context of industry 4.0: A structured classification of critical assets and business impacts
    Corallo, Angelo
    Lazoi, Mariangela
    Lezzi, Marianna
    [J]. COMPUTERS IN INDUSTRY, 2020, 114
  • [9] Crawley F, 2015, HAZOP: GUIDE TO BEST PRACTICE: GUIDELINES TO BEST PRACTICE FOR THE PROCESS AND CHEMICAL INDUSTRIES, 3RD EDITION, P1
  • [10] Covert Attacks in Cyber-Physical Control Systems
    de Sa, Alan Oliveira
    Rust da Costa Carmo, Luiz F.
    Machado, Raphael C. S.
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2017, 13 (04) : 1641 - 1651