An IEC 61850 MMS Traffic Parser for Customizable and Efficient Intrusion Detection

Author(s):  
Heng Chuan Tan ◽  
Vyshnavi Mohanraj ◽  
Binbin Chen ◽  
Daisuke Mashima ◽  
Shing Kham Shing Nan ◽  
...  
Symmetry ◽  
2021 ◽  
Vol 13 (5) ◽  
pp. 826
Author(s):  
Taha Selim Ustun ◽  
S. M. Suhail Hussain ◽  
Ahsen Ulutas ◽  
Ahmet Onen ◽  
Muhammad M. Roomi ◽  
...  

Increased connectivity is required to implement novel coordination and control schemes. IEC 61850-based communication solutions have become popular due to many reasons—object-oriented modeling capability, interoperable connectivity and strong communication protocols, to name a few. However, communication infrastructure is not well-equipped with cybersecurity mechanisms for secure operation. Unlike online banking systems that have been running such security systems for decades, smart grid cybersecurity is an emerging field. To achieve security at all levels, operational technology-based security is also needed. To address this need, this paper develops an intrusion detection system for smart grids utilizing IEC 61850’s Generic Object-Oriented Substation Event (GOOSE) messages. The system is developed with machine learning and is able to monitor the communication traffic of a given power system and distinguish normal events from abnormal ones, i.e., attacks. The designed system is implemented and tested with a realistic IEC 61850 GOOSE message dataset under symmetric and asymmetric fault conditions in the power system. The results show that the proposed system can successfully distinguish normal power system events from cyberattacks with high accuracy. This ensures that smart grids have intrusion detection in addition to cybersecurity features attached to exchanged messages.


2017 ◽  
Vol 32 (2) ◽  
pp. 1068-1078 ◽  
Author(s):  
Yi Yang ◽  
Hai-Qing Xu ◽  
Lei Gao ◽  
Yu-Bo Yuan ◽  
Kieran McLaughlin ◽  
...  

2014 ◽  
Vol 8 (1) ◽  
pp. 536-543
Author(s):  
Zhao Ming ◽  
Sun Qiangqiang

The paper proposes the use of digital watermark based authentication for intrusion detection in IEC 61850- automated substations. The watermark can be embedded into the Least Significant Bits of the measurements without visible deterioration in precision. When Intelligent Electronics Devices gets measurements, the watermark in the measurement can be retrieved to determine whether it has been attacked and detect malicious intrusion. The proposed approach is appropriate for the time critical and resource constrained applications in substation automation system for its simplicity. Numerical simulation shows that the process latency and error incurred by watermarking is acceptable and will not impact performance of protective function in IEC 61850 automated substations.


Sign in / Sign up

Export Citation Format

Share Document