arrow
返回

Early Attack Detection for Securing GOOSE Network Traffic

delete2024-01-01
delete4
delete
OA
AI
G
Ghada Elbez *
K
Klara Nahrstedt
V
Veit Hagenmeyer
DOI:10.1109/TSG.2023.3272749delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The requirements for the security of the network communication in critical infrastructures have been more focused on the availability of the data rather than the integrity and the confidentiality. The availability of communication in IEC 61850 substations can be hindered by Generic Object Oriented Substation Event (GOOSE) poisoning attacks that might result in threats such as Denial of Service (DoS) or flooding attacks. In order to accurately detect similar attacks, a novel method for the Early Detection of Attacks for GOOSE Network Traffic (EDA4GNeT) is developed in the present work. The EDA4GNeT method considers the dynamic behavior of network traffic in electrical substations. A mathematical modeling of GOOSE network traffic is adopted for the anomaly detection based on statistical hypothesis testing. The developed mathematical model of the communication traffic can also support the management of the network architecture in IEC 61850 substations based on appropriate performance studies. To test the novel anomaly detection method and compare the obtained results with related works found in the literature, a simulation of a DoS attack against a ${66/11}{\mathrm{ kV}}$ substation with several experiments is used as a case study.
Keyword:
Substations
IEC Standards
Anomaly detection
Security
Telecommunication traffic
Mathematical models
Smart grids
communication network
cyber-security
electrical substations
GOOSE
IDS
IEC 61850
IEC 62351

期刊

IEEE Transactions on Smart Grid 封面图
IEEE Transactions on Smart Grid
IF:
9.8
论文数:
5.7K
被引数:
4.3W

机构

K
karlsruhe institute of technology
学者数:
2.0W
论文数: 1.4W
被引数: 23
H
Helmholtz Association
学者数:
13.2W
论文数: 10.7W
被引数: 145