Multi-Source Data Fusion for Cyberattack Detection in Power Systems

01/18/2021
by   Abhijeet Sahu, et al.
6

Cyberattacks can cause a severe impact on power systems unless detected early. However, accurate and timely detection in critical infrastructure systems presents challenges, e.g., due to zero-day vulnerability exploitations and the cyber-physical nature of the system coupled with the need for high reliability and resilience of the physical system. Conventional rule-based and anomaly-based intrusion detection system (IDS) tools are insufficient for detecting zero-day cyber intrusions in the industrial control system (ICS) networks. Hence, in this work, we show that fusing information from multiple data sources can help identify cyber-induced incidents and reduce false positives. Specifically, we present how to recognize and address the barriers that can prevent the accurate use of multiple data sources for fusion-based detection. We perform multi-source data fusion for training IDS in a cyber-physical power system testbed where we collect cyber and physical side data from multiple sensors emulating real-world data sources that would be found in a utility and synthesizes these into features for algorithms to detect intrusions. Results are presented using the proposed data fusion application to infer False Data and Command injection-based Man-in- The-Middle (MiTM) attacks. Post collection, the data fusion application uses time-synchronized merge and extracts features followed by pre-processing such as imputation and encoding before training supervised, semi-supervised, and unsupervised learning models to evaluate the performance of the IDS. A major finding is the improvement of detection accuracy by fusion of features from cyber, security, and physical domains. Additionally, we observed the co-training technique performs at par with supervised learning methods when fed with our features.

READ FULL TEXT

page 1

page 10

page 13

research
02/18/2022

Assessment of Cyber-Physical Intrusion Detection and Classification for Industrial Control Systems

The increasing interaction of industrial control systems (ICSs) with pub...
research
11/20/2021

Inter-Domain Fusion for Enhanced Intrusion Detection in Power Systems: An Evidence Theoretic and Meta-Heuristic Approach

False alerts due to misconfigured/ compromised IDS in ICS networks can l...
research
09/07/2020

Unsupervised Learning Based Robust Multivariate Intrusion Detection System for Cyber-Physical Systems using Low Rank Matrix

Regular and uninterrupted operation of critical infrastructures such as ...
research
01/22/2023

Condition monitoring and anomaly detection in cyber-physical systems

The modern industrial environment is equipping myriads of smart manufact...
research
02/13/2020

Compensation of Linear Attacks to Cyber Physical Systems through ARX System Identification

Cyber-Physical Systems (CPSs) are vastly used in today's cities critical...
research
02/20/2022

Behind Closed Doors: Process-Level Rootkit Attacks in Cyber-Physical Microgrid Systems

Embedded controllers, sensors, actuators, advanced metering infrastructu...
research
07/02/2019

Efficient Cyber Attacks Detection in Industrial Control Systems Using Lightweight Neural Networks

Industrial control systems (ICSs) are widely used and vital to industry ...

Please sign up or login with your details

Forgot password? Click here to reset