返回
Cyber-attack TTP analysis for EPES systems
DOI:10.1080/15567249.2025.2516445.png)
摘要
En 中文
The electrical grid consists of legacy systems that were built with no security in mind. As we move toward the Industry 4.0 area though, a high degree of automation and connectivity provides: 1) fast and flexible configuration and updates as well as 2) easier maintenance and handling of mis-configurations and operational errors. Even though considerations are present about the security implications of the Industry 4.0 era in the electrical grid, electricity stakeholders deem their infrastructures as secure since they are isolated and allow no external connections. However, external connections are not the only security risk for electrical utilities. The Tactics, Techniques and Procedures (TTPs) that are employed by adversaries to perform cyber-attack toward the critical Electrical Power and Energy System (EPES) infrastructures are gradually becoming highly advanced and sophisticated. In this article, we elaborate on these techniques and demonstrate them in a power plant of a major utility company within the Greek area. The demonstrated TTPs allow exploiting and executing remote commands in smart meters as well as Programmable Logic Controllers (PLCs) that are responsible for the power generator operation.
Keyword:
Cyber-attack TTPs
Electrical power and energy systems
programmable logic controllers
smart meters
期刊
IF:
2.2
论文数:
1.1K
被引数:
1.5K
机构
引用论文
Assessing the Effectiveness of Attack Detection at a Hackfest on Industrial Control Systems在工业控制系统的Hackfest上评估攻击检测的有效性

