Anomaly detection in substation networks

被引:19
作者
Kreimel, Philipp [1 ]
Eigner, Oliver [2 ]
Mercaldo, Francesco [3 ,4 ]
Santone, Antonella [4 ]
Tavolato, Paul [2 ]
机构
[1] Limes Secur, Hagenberg, Austria
[2] St Polten Univ Appl Sci, Dept Comp Sci & Secur, St Polten, Austria
[3] Natl Res Council Italy CNR, Inst Informat & Telemat, Pisa, Italy
[4] Univ Molise, Dept Biosci & Terr, Pesche, IS, Italy
关键词
Anomaly detection; Neural networks; Formal methods; Model checking; SCADA; Substation; SECURITY; SAFETY;
D O I
10.1016/j.jisa.2020.102527
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fundamental components of the distribution systems of electric energy are primary and secondary substation networks. Considering the incorporation of legacy communication infrastructure in these systems, they often have inherent cybersecurity vulnerabilities. Moreover, traditional intrusion defence strategies for IT systems are often not applicable. With the aim to improve cybersecurity in substation networks, in this paper we present two methods for monitoring SCADA system: the first one exploiting neural networks, while the second one is based on formal methods. To evaluate the effectiveness of the proposed methods, we conducted experiments on a real test bed representing the substation domain as close to real-world as possible. From this test bed we collect data during normal operation and during situations where the system is under attack. To this end several different types of attack are conducted. The data collected is used to test two versions of the monitoring system: one based on machine learning with a neural network and one using a model-checking approach. Moreover, the two proposed models are tested with new data to evaluate their performance. The experiments demonstrate that both methods obtain an accuracy greater than 90%. In particular, the methodology based on formal methods achieves better performance if compared to the one based on neural networks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 53 条
[1]   The Cohomology of Non-Locality and Contextuality [J].
Abramsky, Samson ;
Mansfield, Shane ;
Barbosa, Rui Soares .
ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2012, (95) :1-14
[2]   A THEORY OF TIMED AUTOMATA [J].
ALUR, R ;
DILL, DL .
THEORETICAL COMPUTER SCIENCE, 1994, 126 (02) :183-235
[3]  
[Anonymous], 2011, 2011 16 INT C INT SY
[4]  
[Anonymous], 2009, P 1 WORKSH FUT DIR C
[5]  
[Anonymous], 2000, P 27 ANN W PROT REL
[6]  
Apvrille L., 2014, ARXIV14041985
[7]  
Barbosa RRR, 2010, LECT NOTES COMPUT SC, V6155, P163, DOI 10.1007/978-3-642-13986-4_23
[8]   Reduced models for efficient CCS verification [J].
Barbuti, R ;
Francesco, N ;
Santone, A ;
Vaglini, G .
FORMAL METHODS IN SYSTEM DESIGN, 2005, 26 (03) :319-350
[9]  
Bernardo M, 2004, FORMAL METHODS DESIG, P3185
[10]   Model-checking Timed Temporal Logics [J].
Bouyer, Patricia .
ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2009, 231 :323-341