Cyber-attack TTP analysis for EPES systems

02/17/2023
by   Alexios Lekidis, et al.
0

The electrical grid constitutes of legacy systems that were built with no security in mind. As we move towards the Industry 4.0 area though a high-degree of automation and connectivity provides: 1) fast and flexible configuration and updates as well as 2) easier maintenance and handling of misconfigurations and operational errors. Even though considerations are present about the security implications of the Industry 4.0 area in the electrical grid, electricity stakeholders deem their infrastructures as secure since they are isolated and allow no external connections. However, external connections are not the only security risk for electrical utilities. The Tactics, Techniques and Procedures (TTPs) that are employed by adversaries to perform cyber-attack towards the critical Electrical Power and Energy System (EPES) infrastructures are gradually becoming highly advanced and sophisticated. In this article we elaborate on these techniques and demonstrate them in a Power Plant of the Public Power Corporation (PPC). The demonstrated TTPs allow to exploit and execute remote commands in smart meters as well as Programmable Logic Controllers (PLCs) that are responsible for the power generator operation.

READ FULL TEXT

page 21

page 23

research
10/25/2021

Blockchain application in simulated environment for Cyber-Physical Systems Security

Critical Infrastructures (CIs) such as power grid, water and gas distrib...
research
05/10/2021

EPICTWIN: An Electric Power Digital Twin for Cyber Security Testing, Research and Education

Cyber-Physical Systems (CPS) rely on advanced communication and control ...
research
05/24/2022

Smart Grid: Cyber Attacks, Critical Defense Approaches, and Digital Twin

As a national critical infrastructure, the smart grid has attracted wide...
research
11/28/2019

Modelling Load-Changing Attacks in Cyber-Physical Systems

Cyber-Physical Systems (CPS) are present in many settings addressing a m...
research
05/15/2020

Cyberattack on the Microgrids Through Price Modification

Recent massive failures in the power grid acted as a wake up call for al...
research
07/18/2023

Dead Man's PLC: Towards Viable Cyber Extortion for Operational Technology

For decades, operational technology (OT) has enjoyed the luxury of being...
research
12/18/2020

Effectiveness of SCADA System Security Used Within Critical Infrastructure

Since the 1960s Supervisory Control and Data Acquisition (SCADA) systems...

Please sign up or login with your details

Forgot password? Click here to reset