论文标题
一个分布式层次结构框架,用于增强控制中心应用程序的网络安全性
A Distributed Hierarchy Framework for Enhancing Cyber Security of Control Center Applications
论文作者
论文摘要
最近在电网上进行的网络攻击突出了保护控制中心的关键功能的必要性,这对于网格的安全操作至关重要。即使在分布式框架中,一个中央控制中心也是大多数控制中心体系结构的协调员。这样的控制中心可以成为网络和物理攻击的主要目标,因此,单点故障可能会导致电网的可见性完全丧失。如果可以在安全框架中随机选择在分布式计算环境中运行关键功能的控制中心,则可以在很大程度上降低攻击者导致单点故障的能力。为此,本文提出了一个新型的基于分布式层次结构以确保关键功能的框架。所提出的框架确保数据聚合和关键功能是在随机位置执行的,并结合了诸如证明和信任管理等安全功能以检测受损的代理。在拟议的信任管理协议中,信托价值的演变和融合证明了理论上的结果。还表明,只要折衷的节点的数量严格小于节点减去1的一半,该系统在名义上是可靠的。为了演示,使用相位测量的基于Kalman滤波器的状态估计用作要确定的关键函数。所提出的框架的实现可行性已在Alalella板的物理硬件集群上进行了测试。还使用IEEE 118总线系统上的模拟对该框架进行了验证。
Recent cyber-attacks on power grids highlight the necessity to protect the critical functionalities of a control center vital for the safe operation of a grid. Even in a distributed framework one central control center acts as a coordinator in majority of the control center architectures. Such a control center can become a prime target for cyber as well as physical attacks, and, hence, a single point failure can lead to complete loss of visibility of the power grid. If the control center which runs the critical functions in a distributed computing environment can be randomly chosen between the available control centers in a secure framework, the ability of the attacker in causing a single point failure can be reduced to a great extent. To achieve this, a novel distributed hierarchy based framework to secure critical functions is proposed in this paper. The proposed framework ensures that the data aggregation and the critical functions are carried out at a random location, and incorporates security features such as attestation and trust management to detect compromised agents. A theoretical result is proved on the evolution and convergence of the trust values in the proposed trust management protocol. It is also shown that the system is nominally robust so long as the number of compromised nodes is strictly less than one-half of the nodes minus 1. For demonstration, a Kalman filter-based state estimation using phasor measurements is used as the critical function to be secured. The proposed framework's implementation feasibility is tested on a physical hardware cluster of Parallella boards. The framework is also validated using simulations on the IEEE 118 bus system.