GooseFlowMeter: A Flow Extractor for the Analysis of GOOSE Messages
摘要
Power substations are a crucial element within Critical Infrastructures (CIs) since the operation of these infrastructures, to support vital social functions, depends on them. As time passes, there is an increase in the emergence of cyberattacks targeting the communication infrastructure of CIs. IEC 61850 is a standard that defines guidelines for communications and security measures in power substations. Nevertheless, there are some vulnerabilities in the IEC 61850 standard, especially in the messages of the GOOSE protocol. In that matter, it is crucial to understand the different aspects of GOOSE in order to propose security solutions through the development of different tools and security measures. In this paper, we introduce the GooseFlowMeter extractor, a tool that allows capturing GOOSE packets and aggregating them into network flows for further analysis. To demonstrate the value of the extractor, we proposed a two-step experiment. The first step deployed the extractor in a physical network in order to generate a dataset. In the second step, we implemented a set of classification algorithms to label GOOSE flows as benign or as part of a False Data Injection Attack (FDIA). In the proposed experiment we obtained an accuracy higher than 93% for the task of classification considering different algorithms, thus through GOOSE flows it is possible to identify patterns of FDIA in order to detect this type of attack.