Vulnerability Assessment of Cybersecurity for SCADA Systems

被引:360
作者
Ten, Chee-Wooi [1 ]
Liu, Chen-Ching [1 ]
Manimaran, Govindarasu [1 ]
机构
[1] Iowa State Univ Sci & Technol, Dept Elect & Comp Engn, Ames, IA 50010 USA
关键词
Cyber-physical system; dependability measures; passwords; Petri nets; power systems; vulnerability indices;
D O I
10.1109/TPWRS.2008.2002298
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Vulnerability assessment is a requirement of NERC's cybersecurity standards for electric power systems. The purpose is to study the impact of a cyber attack on supervisory control and data acquisition (SCADA) systems. Compliance of the requirement to meet the standard has become increasingly challenging as the system becomes more dispersed in wide areas. Interdependencies between computer communication system and the physical infrastructure also become more complex as information technologies are further integrated into devices and networks. This paper proposes a vulnerability assessment framework to systematically evaluate the vulnerabilities of SCADA systems at three levels: system, scenarios, and access points. The proposed method is based on cyber systems embedded with the firewall and password models, the primary mode of protection in the power industry today. The impact of a potential electronic intrusion is evaluated by its potential loss of load in the power system. This capability is enabled by integration of a logic-based simulation method and a modul e for the power flow computation. The IEEE 30-bus system is used to evaluate the impact of attacks launched from outside or from within the substation networks. Countermeasures are identified for improvement of the cybersecurity.
引用
收藏
页码:1836 / 1846
页数:11
相关论文
共 23 条
[1]  
AMIN M, 2002, IEEE COMPUT, V35, P8
[2]  
[Anonymous], SOURC STAG CYB ATT R
[3]  
[Anonymous], 21 STEPS IMPROVE CYB
[4]  
[Anonymous], 2007, VULNERABILITY ASSESS
[5]  
Bause F., 2002, Stochastic Petri Nets, VVolume 1
[6]  
CARLSON RE, 2005, NATION TEST BED SUMM
[7]  
CARLSON RE, 2005, DOE OFFICE ELECT DEL
[8]  
CIARDO G, USER MANUAL SPNP STO
[9]  
CLEVELAND F, 2007, P IEEE POW ENG SOC G
[10]   SCADA cyber security testbed development [J].
Davis, C. M. ;
Tate, J. E. ;
Okhravi, H. ;
Grier, C. ;
Overbye, T. J. ;
Nicol, D. .
2006 38TH ANNUAL NORTH AMERICAN POWER SYMPOSIUM, NAPS-2006 PROCEEDINGS, 2006, :483-+