Applying Hoeffding Adaptive Trees for Real-Time Cyber-Power Event and Intrusion Classification

被引:48
作者
Adhikari, Ullain [1 ]
Morris, Thomas H. [2 ]
Pan, Shengyi [3 ]
机构
[1] Peak Reliabil, Loveland, CO 80538 USA
[2] Univ Alabama, Dept Elect & Comp Engn, Huntsville, AL 35899 USA
[3] MaxPoint Interact, Data Engn Team, Morrisville, NC 27560 USA
关键词
Hoeffding adaptive trees; cyber security; intrusion detection system; electric transmission system; DATA STREAMS; SYSTEM; PROTECTION;
D O I
10.1109/TSG.2017.2647778
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Electricity transmission systems are networked cyber physical systems that are subject to many well-known control, weather, and equipment failure related contingencies which can disrupt power delivery. Cyber-attacks against electric transmission systems are another class of contingency which can disrupt power delivery. Wide area monitoring systems (WAMSs) enhanced with phasor measurement units provide high volume and high velocity power system sensor data which can be combined with traditional power system data sources and cyber data sources to enable real time detection of both types of contingencies. This paper describes research toward a cyber-power event and intrusion detection system (EIDS) which can be used for multiclass or binary-class classification of traditional power system contingencies and cyber-attacks. The continuous streams of high speed data from WAMS pose significant challenges in data storage, management, and handling. Data stream mining addresses the continuous data problem and can deal with very large data sizes. Hoeffding adaptive trees (HAT) augmented with the drift detection method (DDM) and adaptive windowing (AMIN) can effectively be used to classify traditional and cyber contingencies in real time. Experiments performed for this paper demonstrate HAT + DDM + ADWIN provides classification accuracy of greater than 94% for multiclass and greater than 98% for binary class classification for a dataset with artifacts from 45 classes of cyber-power contingencies. Results also show that HAT + DDM + ADWIN has a small memory foot print and a fast evaluation time which enables real time EIDS.
引用
收藏
页码:4049 / 4060
页数:12
相关论文
共 46 条
[1]   WAMS Cyber-Physical Test Bed for Power System, Cybersecurity Study, and Data Mining [J].
Adhikari, Uttam ;
Morris, Thomas ;
Pan, Shengyi .
IEEE TRANSACTIONS ON SMART GRID, 2017, 8 (06) :2744-2753
[2]  
Al Karim M., 2012, 2012 3rd IEEE PES Innovative Smart Grid Technologies Europe (ISGT Europe), P1
[3]  
[Anonymous], 2010, POWER SYSTEM ANAL
[4]  
[Anonymous], Proceedings of the 9th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2003
[5]  
[Anonymous], 2015, Reinforcement Learning: An Introduction
[6]  
[Anonymous], EVENT INTRUSION DETE
[7]  
[Anonymous], FREQ RESP STAND WHIT
[8]  
[Anonymous], 2010, Real-time application of synchrophasors for improving reliability
[9]  
[Anonymous], P 7 INT S RES CONTR
[10]  
Babcock B., 2002, PODS, P1, DOI [DOI 10.1145/543613.543615, 10.1145/543613.543615]