Anomaly detection in substation networks

被引:19
作者
Kreimel, Philipp [1 ]
Eigner, Oliver [2 ]
Mercaldo, Francesco [3 ,4 ]
Santone, Antonella [4 ]
Tavolato, Paul [2 ]
机构
[1] Limes Secur, Hagenberg, Austria
[2] St Polten Univ Appl Sci, Dept Comp Sci & Secur, St Polten, Austria
[3] Natl Res Council Italy CNR, Inst Informat & Telemat, Pisa, Italy
[4] Univ Molise, Dept Biosci & Terr, Pesche, IS, Italy
关键词
Anomaly detection; Neural networks; Formal methods; Model checking; SCADA; Substation; SECURITY; SAFETY;
D O I
10.1016/j.jisa.2020.102527
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fundamental components of the distribution systems of electric energy are primary and secondary substation networks. Considering the incorporation of legacy communication infrastructure in these systems, they often have inherent cybersecurity vulnerabilities. Moreover, traditional intrusion defence strategies for IT systems are often not applicable. With the aim to improve cybersecurity in substation networks, in this paper we present two methods for monitoring SCADA system: the first one exploiting neural networks, while the second one is based on formal methods. To evaluate the effectiveness of the proposed methods, we conducted experiments on a real test bed representing the substation domain as close to real-world as possible. From this test bed we collect data during normal operation and during situations where the system is under attack. To this end several different types of attack are conducted. The data collected is used to test two versions of the monitoring system: one based on machine learning with a neural network and one using a model-checking approach. Moreover, the two proposed models are tested with new data to evaluate their performance. The experiments demonstrate that both methods obtain an accuracy greater than 90%. In particular, the methodology based on formal methods achieves better performance if compared to the one based on neural networks. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 53 条
[51]  
Yang Y., 2013, Rule-based intrusion detection system for SCADA networks
[52]   Novel Approach for Detecting Network Anomalies for Substation Automation based on IEC 61850 [J].
Yoo, Hyunguk ;
Shon, Taeshik .
MULTIMEDIA TOOLS AND APPLICATIONS, 2015, 74 (01) :303-318
[53]   A security scheme for intelligent substation communications considering real-time performance [J].
Zhang, Jie ;
Li, Jun'e ;
Chen, Xiong ;
Ni, Ming ;
Wang, Ting ;
Luo, Jianbo .
JOURNAL OF MODERN POWER SYSTEMS AND CLEAN ENERGY, 2019, 7 (04) :948-961