On specification-based cyber-attack detection in smart grids

dc.bibliographicCitation.firstPage23eng
dc.bibliographicCitation.issueS1eng
dc.bibliographicCitation.journalTitleEnergy Informaticseng
dc.bibliographicCitation.volume5eng
dc.contributor.authorSen, Ömer
dc.contributor.authorvan der Velde, Dennis
dc.contributor.authorLühman, Maik
dc.contributor.authorSprünken, Florian
dc.contributor.authorHacker, Immanuel
dc.contributor.authorUlbig, Andreas
dc.contributor.authorAndres, Michael
dc.contributor.authorHenze, Martin
dc.date.accessioned2022-10-05T06:44:25Z
dc.date.available2022-10-05T06:44:25Z
dc.date.issued2022
dc.description.abstractThe transformation of power grids into intelligent cyber-physical systems brings numerous benefits, but also significantly increases the surface for cyber-attacks, demanding appropriate countermeasures. However, the development, validation, and testing of data-driven countermeasures against cyber-attacks, such as machine learning-based detection approaches, lack important data from real-world cyber incidents. Unlike attack data from real-world cyber incidents, infrastructure knowledge and standards are accessible through expert and domain knowledge. Our proposed approach uses domain knowledge to define the behavior of a smart grid under non-attack conditions and detect attack patterns and anomalies. Using a graph-based specification formalism, we combine cross-domain knowledge that enables the generation of whitelisting rules not only for statically defined protocol fields but also for communication flows and technical operation boundaries. Finally, we evaluate our specification-based intrusion detection system against various attack scenarios and assess detection quality and performance. In particular, we investigate a data manipulation attack in a future-orientated use case of an IEC 60870-based SCADA system that controls distributed energy resources in the distribution grid. Our approach can detect severe data manipulation attacks with high accuracy in a timely and reliable manner.eng
dc.description.versionpublishedVersioneng
dc.identifier.urihttps://oa.tib.eu/renate/handle/123456789/10215
dc.identifier.urihttp://dx.doi.org/10.34657/9262
dc.language.isoengeng
dc.relation.doihttps://doi.org/10.1186/s42162-022-00206-7
dc.relation.essn2520-8942
dc.rights.licenseCC BY 4.0 Unportedeng
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/eng
dc.subject.ddc004eng
dc.subject.ddc333.7eng
dc.subject.otherCyber securityeng
dc.subject.otherCyber physical systemseng
dc.subject.otherIntrusion detection systemseng
dc.titleOn specification-based cyber-attack detection in smart gridseng
dc.typeArticleeng
dc.typeTexteng
tib.accessRightsopenAccesseng
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
s42162-022-00206-7.pdf
Size:
1.82 MB
Format:
Adobe Portable Document Format
Description:
Collections