Deep Reinforcement Learning for Penetration Testing of Cyber-Physical Attacks in the Smart Grid

被引:0
作者
Li, Yuanliang [1 ,2 ]
Yan, Jun [1 ]
Naili, Mohamed [2 ]
机构
[1] Concordia Univ, Concordia Inst Informat Syst Engn CIISE, Montreal, PQ, Canada
[2] Ericsson, Global Artificial Intelligence Accelerator GAIA, Montreal, PQ, Canada
来源
2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN) | 2022年
基金
加拿大自然科学与工程研究理事会;
关键词
Cyber-physical security; penetration testing; smart grid; deep reinforcement learning;
D O I
10.1109/IJCNN55064.2022.9892584
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The fast expansion of interconnectivity in cyberphysical critical infrastructures like smart grids has given rise to concerning exposures and vulnerabilities. Although penetration testing (PT) has been an effective approach to searching for vulnerabilities in software, devices, and networks from the attacker's view, the strong cyber-physical coupling in these large-scale infrastructures has made it challenging to manually pinpoint critical vulnerabilities, particularly at system levels due to the complexity, dimensionality, and uncertainty therein. To better protect the security of cyber-physical systems, this paper proposes a deep reinforcement learning (DRL)-based PT framework to efficiently and adaptively identify critical vulnerabilities in smart grids. Using replay attacks as an example, the paper models the attack as a Markov Decision Process with three actions - stop, record, and replay - to learn the optimal timing and ordering of replays in different operating scenarios. A cyber-physical cosimulation platform with dedicated simulators for the physical part, cyber part, control part, and attacker part of a smart distribution grid was developed as a sandbox environment to train the DRL agent. Scenarios with different levels of difficulty are tested to validate the learning capability and performance in finding critical attack paths of the DRL-based PT. The simulation results show that DRL-based PT can learn to find the optimal attack path against system stability when the grid is under high load demand, solar power generation, and weather variation. These results are promising first steps toward a highly customizable framework to pen-test complex cyber-physical systems with automatic DRL agents and various attack schemes.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] Cyber-Physical Security Testbeds: Architecture, Application, and Evaluation for Smart Grid
    Hahn, Adam
    Ashok, Aditya
    Sridhar, Siddharth
    Govindarasu, Manimaran
    IEEE TRANSACTIONS ON SMART GRID, 2013, 4 (02) : 847 - 855
  • [42] Smart grid cyber-physical systems: communication technologies, standards and challenges
    Jha, A. V.
    Appasani, B.
    Ghazali, A. N.
    Pattanayak, P.
    Gurjar, D. S.
    Kabalci, E.
    Mohanta, D. K.
    WIRELESS NETWORKS, 2021, 27 (04) : 2595 - 2613
  • [43] Cyber-Physical Device Authentication for the Smart Grid Electric Vehicle Ecosystem
    Chan, Aldar C. -F.
    Zhou, Jianying
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2014, 32 (07) : 1509 - 1517
  • [44] Analysis of Cyber-Physical Security in Electric Smart Grid Survey and challenges
    Dcruz, Hans John
    Kaliaperumal, Baskaran
    2018 6TH INTERNATIONAL RENEWABLE AND SUSTAINABLE ENERGY CONFERENCE (IRSEC), 2018, : 1182 - 1187
  • [45] Integrated Cyber-Physical Fault Injection for Reliability Analysis of the Smart Grid
    Faza, Ayman
    Sedigh, Sahra
    McMillin, Bruce
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, 2010, 6351 : 277 - 290
  • [46] ScorePlus: An Integrated Scalable Cyber-Physical Experiment Environment for Smart Grid
    Tan, Song
    Song, Wen-Zhan
    Yothment, Steve
    Yang, Junjie
    Tong, Lang
    2015 12TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON SENSING, COMMUNICATION, AND NETWORKING (SECON), 2015, : 381 - 389
  • [47] Stability of a Cyber-Physical Smart Grid System using Cooperating Invariants
    Choudhari, Ashish
    Ramaprasad, Harini
    Paul, Tamal
    Kimball, Jonathan W.
    Zawodniok, Maciej
    McMillin, Bruce
    Chellappan, Sriram
    2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), 2013, : 760 - 769
  • [48] Aggregation and Charging Control of PHEVs in Smart Grid: A Cyber-Physical Perspective
    Liu, Mingxi
    Shi, Yang
    Gao, Huijun
    PROCEEDINGS OF THE IEEE, 2016, 104 (05) : 1071 - 1085
  • [49] Deep Reinforcement Learning for Intelligent Penetration Testing Path Design
    Yi, Junkai
    Liu, Xiaoyan
    APPLIED SCIENCES-BASEL, 2023, 13 (16):
  • [50] Reflective Attenuation of Cyber-Physical Attacks
    Segovia, Mariana
    Cavalli, Ana Rosa
    Cuppens, Nora
    Rubio-Hernan, Jose
    Garcia-Alfaro, Joaquin
    COMPUTER SECURITY, ESORICS 2019, 2020, 11980 : 19 - 34