An Approach of Replicating Multi-Staged Cyber-Attacks and Countermeasures in a Smart Grid Co-Simulation Environment

10/05/2021
by   Ömer Sen, et al.
0

While the digitization of power distribution grids brings many benefits, it also introduces new vulnerabilities for cyber-attacks. To maintain secure operations in the emerging threat landscape, detecting and implementing countermeasures against cyber-attacks are paramount. However, due to the lack of publicly available attack data against Smart Grids (SGs) for countermeasure development, simulation-based data generation approaches offer the potential to provide the needed data foundation. Therefore, our proposed approach provides flexible and scalable replication of multi-staged cyber-attacks in an SG Co-Simulation Environment (COSE). The COSE consists of an energy grid simulator, simulators for Operation Technology (OT) devices, and a network emulator for realistic IT process networks. Focusing on defensive and offensive use cases in COSE, our simulated attacker can perform network scans, find vulnerabilities, exploit them, gain administrative privileges, and execute malicious commands on OT devices. As an exemplary countermeasure, we present a built-in Intrusion Detection System (IDS) that analyzes generated network traffic using anomaly detection with Machine Learning (ML) approaches. In this work, we provide an overview of the SG COSE, present a multi-stage attack model with the potential to disrupt grid operations, and show exemplary performance evaluations of the IDS in specific scenarios.

READ FULL TEXT

page 1

page 2

page 3

page 4

page 5

research
10/18/2021

Investigating Man-in-the-Middle-based False Data Injection in a Smart Grid Laboratory Environment

With the increasing use of information and communication technology in e...
research
10/11/2022

Detecting Hidden Attackers in Photovoltaic Systems Using Machine Learning

In modern smart grids, the proliferation of communication-enabled distri...
research
11/20/2022

On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach

While digitization of distribution grids through information and communi...
research
06/11/2022

Web-Based Platform for Evaluation of Resilient and Transactive Smart-Grids

Today's smart-grids have seen a clear rise in new ways of energy generat...
research
01/31/2023

Machine Learning and Port Scans: A Systematic Review

Port scanning is the process of attempting to connect to various network...
research
08/15/2018

Anomaly Detection in Cyber Network Data Using a Cyber Language Approach

As the amount of cyber data continues to grow, cyber network defenders a...
research
06/28/2021

Towards anomaly detection in smart grids by combining Complex Events Processing and SNMP objects

This paper describes the architecture and the fundamental methodology of...

Please sign up or login with your details

Forgot password? Click here to reset