Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

A Novel Architecture for Attack-Resilient Wide-Area Protection and Control System in Smart Grid

Conference · · 2020 Resilience Week (RWS)

Wide-area protection and control (WAPAC) systems are widely applied in the energy management system (EMS) that rely on a wide-area communication network to maintain system stability, security, and reliability. As technology and grid infrastructure evolve to develop more advanced WAPAC applications, however, so do the attack surfaces in the grid infrastructure. This paper presents an attack-resilient system (ARS) for the WAPAC cybersecurity by seamlessly integrating the network intrusion detection system (NIDS) with intrusion mitigation and prevention system (IMPS). In particular, the proposed NIDS utilizes signature and behavior-based rules to detect attack reconnaissance, communication failure, and data integrity attacks. Further, the proposed IMPS applies state transition-based mitigation and prevention strategies to quickly restore the normal grid operation after cyberattacks. As a proof of concept, we validate the proposed generic architecture of ARS by performing experimental case study for wide-area protection scheme (WAPS), one of the critical WAPAC applications, and evaluate the proposed NIDS and IMPS components of ARS in a cyber-physical testbed environment. Our experimental results reveal a promising performance in detecting and mitigating different classes of cyberattacks while supporting an alert visualization dashboard to provide an accurate situational awareness in real-time.

Research Organization:
Iowa State University
Sponsoring Organization:
USDOE Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
Contributing Organization:
Iowa State University
DOE Contract Number:
OE0000830
OSTI ID:
1985671
Report Number(s):
DOE-ISU-0000830-9
Journal Information:
2020 Resilience Week (RWS), Journal Name: 2020 Resilience Week (RWS)
Country of Publication:
United States
Language:
English

References (13)

Model-Based Attack Detection and Mitigation for Automatic Generation Control journal March 2014
Malicious Corruption Resilience in PMU Data and Wide-Area Damping Control journal March 2020
Self-Healing Attack-Resilient PMU Network for Power System Operation journal May 2018
Testbed-based Evaluation of SIEM Tool for Cyber Kill Chain Model in Power Grid SCADA System conference October 2019
An Adaptive Resilient Load Frequency Controller for Smart Grids With DoS Attacks journal May 2020
Cyber-Physical Attack-Resilient Wide-Area Monitoring, Protection, and Control for the Power Grid journal July 2017
SHARP-Net: Platform for Self-Healing and Attack Resilient PMU Networks conference February 2020
HIDES: Hybrid Intrusion Detector for Energy Systems conference February 2020
Cyber-Attack Resilient Design of Wide-Area PSS Considering Practical Communication Constraints journal June 2020
Multi-Agent Based Attack-Resilient System Integrity Protection for Smart Grid journal July 2020
Decision Tree Based Anomaly Detection for Remedial Action Scheme in Smart Grid using PMU Data conference August 2018
Security Evaluation of Two Intrusion Detection Systems in Smart Grid SCADA Environment conference September 2018
Wide-Area Protection and Emergency Control journal May 2005

Similar Records

Attack-resilient algorithms and testbed federation for wide-area protection and control in smart grid
Other · Tue Dec 31 23:00:00 EST 2019 · OSTI ID:1985640

SHARP-Net: Platform for Self-Healing and Attack Resilient PMU Networks
Conference · Thu May 07 00:00:00 EDT 2020 · OSTI ID:1669497

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation
Conference · Mon Jul 26 00:00:00 EDT 2021 · 2021 IEEE Power & Energy Society General Meeting (PESGM) · OSTI ID:1985655