Info: Zenodo’s user support line is staffed on regular business days between Dec 23 and Jan 5. Response times may be slightly longer than normal.

Published September 18, 2020 | Version v1
Conference paper Open

An Anomaly Detection Mechanism for IEC 60870-5-104

  • 1. Department of Electrical and Computer Engineering, University of Western Macedonia, Kozani, Greece
  • 2. SIDROCO, Anaximandrou, Limassol, Cyprus
  • 3. 0INF, Imperial Offices, London, UK

Description

The transformation of the conventional electricity grid into a new paradigm called smart grid demands the appropriate cybersecurity solutions. In this paper, we focus on the security of the IEC 60870-5-104 (IEC-104) protocol which is commonly used by Supervisory Control and Data Acquisition (SCADA) systems in the energy domain. In particular, after investigating its security issues, we provide a multivariate Intrusion Detection System (IDS) which adopts both access control and outlier detection mechanisms in order to detect timely possible anomalies against IEC-104. The efficiency of the proposed IDS is reflected by the Accuracy and F1 metrics that reach 98% and 87%, respectively.

Files

[16] An Anomaly Detection Mechanism for IEC 60870-5-104.pdf

Files (280.5 kB)

Additional details

Funding

SPEAR – SPEAR: Secure and PrivatE smArt gRid 787011
European Commission