论文标题

智能网格中基于规范的网络攻击检测

On Specification-based Cyber-Attack Detection in Smart Grids

论文作者

van der Velde, Ömer Sen Dennis, Lühman, Maik, Sprünken, Florian, Hacker, Immanuel, Ulbig, Andreas, Andres, Michael, Henze, Martin

论文摘要

将电网转换为智能网络物理系统带来了许多好处,但也显着增加了网络攻击的表面,要求适当的对策。但是,针对网络攻击的数据驱动的对策的开发,验证和测试,例如基于机器学习的检测方法,缺乏来自现实世界中网络事件的重要数据。与实际网络事件发生的攻击数据不同,基础架构知识和标准可以通过专家和领域知识访问。我们提出的方法使用域知识来定义在非攻击条件下智能电网的行为,并检测攻击模式和异常。使用基于图的规范形式主义,我们结合了跨域知识,该知识不仅可以针对静态定义的协议字段,而且还用于通信OWS和技术操作边界,从而可以生成白名单规则。最后,我们针对各种攻击场景评估了基于规范的入侵检测系统,并评估检测质量和性能。特别是,我们研究了基于IEC 60870的SCADA系统的未来以未来为导向的用例中的数据操纵攻击,该案例控制了分发网格中的分布式能源。我们的方法可以及时可靠地检测出严重的数据操纵攻击。

The transformation of power grids into intelligent cyber-physical systems brings numerous benefits, but also significantly increases the surface for cyber-attacks, demanding appropriate countermeasures. However, the development, validation, and testing of data-driven countermeasures against cyber-attacks, such as machine learning-based detection approaches, lack important data from real-world cyber incidents. Unlike attack data from real-world cyber incidents, infrastructure knowledge and standards are accessible through expert and domain knowledge. Our proposed approach uses domain knowledge to define the behavior of a smart grid under non-attack conditions and detect attack patterns and anomalies. Using a graph-based specification formalism, we combine cross-domain knowledge that enables the generation of whitelisting rules not only for statically defined protocol fields but also for communication ows and technical operation boundaries. Finally, we evaluate our specification-based intrusion detection system against various attack scenarios and assess detection quality and performance. In particular, we investigate a data manipulation attack in a future-orientated use case of an IEC 60870-based SCADA system that controls distributed energy resources in the distribution grid. Our approach can detect severe data manipulation attacks with high accuracy in a timely and reliable manner.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源