错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SecMonS: A Security Monitoring Framework for IEC 61850 Substations Based on Configuration Files and Logs

  • Onur Duman,
  • Mengyuan Zhang,
  • Lingyu Wang,
  • Mourad Debbabi

摘要

Substations are critical components of the smart grid since compromising them can lead to significant consequences, such as blackouts. Threat modeling aims to model different ways critical networks, such as substations, can be attacked. Attack graphs are commonly used for modeling threats and there is a huge literature on attack graphs. However, attack graph generation is still an open problem, and attack graphs are usually generated based on static configurations. To overcome those challenges, this paper provides an attack graph-based threat modeling and Markov Decision Process (MDP)-based monitoring framework for substations, named SecMonS. Specifically, we first generate static attack graphs based on substation configuration language (SCL) descriptions of intelligent electronic devices (IED). Second, we generate automaton models for modeling the behaviors of IEDs directly from log files that contain Generic Object Oriented Substation Event (GOOSE) protocol parameter values. Third, we enhance static attack graphs with automaton models to ensure that those threat models contain updated information based on real-world attacks. Fourth, we tackle the state space explosion faced by MDP models which are utilized for identifying potential physical consequences of attacks to integrate physical aspects of attacks into the threat modeling. Lastly, we evaluate the practicality of SecMonS through simulations using data both from a public data set and randomly generated events for different types of attacks.