On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach

11/20/2022
by   Ömer Sen, et al.
0

While digitization of distribution grids through information and communications technology brings numerous benefits, it also increases the grid's vulnerability to serious cyber attacks. Unlike conventional systems, attacks on many industrial control systems such as power grids often occur in multiple stages, with the attacker taking several steps at once to achieve its goal. Detection mechanisms with situational awareness are needed to detect orchestrated attack steps as part of a coherent attack campaign. To provide a foundation for detection and prevention of such attacks, this paper addresses the detection of multi-stage cyber attacks with the aid of a graph-based cyber intelligence database and alert correlation approach. Specifically, we propose an approach to detect multi-stage attacks by leveraging heterogeneous data to form a knowledge base and employ a model-based correlation approach on the generated alerts to identify multi-stage cyber attack sequences taking place in the network. We investigate the detection quality of the proposed approach by using a case study of a multi-stage cyber attack campaign in a future-orientated power grid pilot.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/06/2021

Towards an Approach to Contextual Detection of Multi-Stage Cyber Attacks in Smart Grids

Electric power grids are at risk of being compromised by high-impact cyb...
research
09/09/2022

On Specification-based Cyber-Attack Detection in Smart Grids

The transformation of power grids into intelligent cyber-physical system...
research
06/09/2018

Application of Correlation Indices on Intrusion Detection Systems: Protecting the Power Grid Against Coordinated Attacks

The future power grid will be characterized by the pervasive use of hete...
research
10/05/2021

An Approach of Replicating Multi-Staged Cyber-Attacks and Countermeasures in a Smart Grid Co-Simulation Environment

While the digitization of power distribution grids brings many benefits,...
research
08/04/2019

Boundary Defense against Cyber Threat for Power System Operation

The operation of power grids is becoming increasingly data-centric. Whil...
research
09/25/2020

Towards Reconstructing Multi-Step Cyber Attacks in Modern Cloud Environments with Tripwires

Rapidly-changing cloud environments that consist of heavily interconnect...
research
07/18/2019

An AI-based, Multi-stage detection system of banking botnets

Banking Trojans, botnets are primary drivers of financially-motivated cy...

Please sign up or login with your details

Forgot password? Click here to reset