Published August 23, 2022 | Version v1
Conference paper Open

Substation-Aware. An intrusion detection system for the IEC 61850 protocol

  • 1. TECNALIA, Basque Research and Technology Alliance (BRTA)

Description

The number of cyberattacks against the Smart Grid has increased in the last years. Considered as a critical infrastructure, power system operators must improve the cybersecurity countermeasures of their installations. Intrusion Detection Systems (IDS) appears as a promising solution to detect hidden activity of the hackers before launching the attack. Most detection tools are generalist, designed to find predefined patterns such as frequency of messages, well-known malware packets, source and destination of the messages or the content of each packet itself. These tools also allow plugging modules for different protocols, offering a better understanding of the analysed data, such as the protocol action (read, write, reset...) or data model/schema understanding. However, the semantics of the data transmitted cannot be inferred. The Substation-Aware (SBT-Aware) tool adds the latest feature for primary and secondary substations, taking into account not only the protocols defined in the IEC 61850 standard, but the substation topology as well. In this paper we present the SBT-Aware, an IDS that has been developed and tested in the course of the H2020 SDN-microSENSE project.

Files

ARES 2022 - SDN-microSENSE - SBT-Aware (v1).pdf

Files (624.5 kB)

Name Size Download all
md5:aff4210b57cff0c71a2e773c3f416e7c
624.5 kB Preview Download

Additional details

Funding

European Commission
SDN-microSENSE - SDN - microgrid reSilient Electrical eNergy SystEm 833955