Application of Correlation Indices on Intrusion Detection Systems: Protecting the Power Grid Against Coordinated Attacks

06/09/2018
by   Christian Moya, et al.
0

The future power grid will be characterized by the pervasive use of heterogeneous and non-proprietary information and communication technology, which exposes the power grid to a broad scope of cyber-attacks. In particular, Monitoring-Control Attacks (MCA) --i.e., attacks in which adversaries manipulate control decisions by fabricating measurement signals in the feedback loop-- are highly threatening. This is because, MCAs are (i) more likely to happen with greater attack surface and lower cost, (ii) difficult to detect by hiding in measurement signals, and (iii) capable of inflicting severe consequences by coordinating attack resources. To defend against MCAs, we have developed a semantic analysis framework for Intrusion Detection Systems (IDS) in power grids. The framework consists of two parts running in parallel: a Correlation Index Generator (CIG), which indexes correlated MCAs, and a Correlation Knowledge-Base (CKB), which is updated aperiodically with attacks' Correlation Indices (CI). The framework has the advantage of detecting MCAs and estimating attack consequences with promising runtime and detection accuracy. To evaluate the performance of the framework, we computed its false alarm rates under different attack scenarios.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/18/2021

Investigating Man-in-the-Middle-based False Data Injection in a Smart Grid Laboratory Environment

With the increasing use of information and communication technology in e...
research
11/20/2022

On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach

While digitization of distribution grids through information and communi...
research
09/09/2022

On Specification-based Cyber-Attack Detection in Smart Grids

The transformation of power grids into intelligent cyber-physical system...
research
11/02/2018

Alert Correlation Algorithms: A Survey and Taxonomy

Alert correlation is a system which receives alerts from heterogeneous I...
research
02/13/2018

Probabilistic Warnings in National Security Crises: Pearl Harbor Revisited

Imagine a situation where a group of adversaries is preparing an attack ...
research
02/22/2021

An Online Approach to Cyberattack Detection and Localization in Smart Grid

Complex interconnections between information technology and digital cont...
research
10/16/2021

An Effective Attack Scenario Construction Model based on Attack Steps and Stages Identification

A Network Intrusion Detection System (NIDS) is a network security techno...

Please sign up or login with your details

Forgot password? Click here to reset