Visible to the public Semantic Security Analysis of SCADA Networks to Detect Malicious Control Commands in Power GridsConflict Detection Enabled

TitleSemantic Security Analysis of SCADA Networks to Detect Malicious Control Commands in Power Grids
Publication TypeConference Paper
Year of Publication2013
AuthorsHui Lin, University of Illinois at Urbana-Champaign, Adam Slagell, University of Illinois at Urbana-Champaign, Zbigniew Kalbarczyk, University of Illinois at Urbana-Champaign, Peter W. Sauer, University of Illinois at Urbana-Champaign, Ravishankar K. Iyer, University of Illinois at Urbana-Champaign
Conference NameFirst ACM Workshop on Smart Engergy Grid Security
Date Published11/2013
PublisherACM
Conference LocationBerlin, Germany
KeywordsFrom Measurements to Security Science: Data-Driven Approach, NSA SoS Lablets Materials, science of security, UIUC
Abstract

In the current generation of SCADA (Supervisory Control And Data Acquisition) systems used in power grids, a sophisticated attacker can exploit system vulnerabilities and use a legitimate maliciously crafted command to cause a wide range of system changes that traditional contingency analysis does not consider and remedial action schemes cannot handle. To detect such malicious commands, we propose a semantic analysis framework based on a distributed network of intrusion detection systems (IDSes). The framework combines system knowledge of both cyber and physical infrastructure in power grid to help IDS to estimate execution consequences of control commands, thus to reveal attacker's malicious intentions. We evaluated the approach on the IEEE 30-bus system. Our experiments demonstrate that: (i) by opening 3 transmission lines, an attacker can avoid detection by the traditional contingency analysis and instantly put the tested 30-bus system into an insecure state and (ii) the semantic analysis provides reliable detection of malicious commands with a small amount of analysis time.

Citation Keynode-31881

Other available formats:

Semantic Security Analysis of SCADA Networks to Detect Malicious Control Commands in Power Grids