Published November 8, 2023 | Version v1

Risk Assessment Method for 5G-oriented DLMS/COSEM Communications

  • 1. University of Thessaly, Geopolis Campus

Description

The Advanced Metering Infrastructure (AMI) is lately introduced to ensure the real-time exchange of smart meter measurements and their availability for both utilities as well as their customers. DLMS/COSEM is the mostly used protocol for AMI systems as well as allows the integration in 5G-enabled network slices to increase the reliability of energy measurement exchange and availability of sufficient data to calculate energy demand. Nevertheless, such integration augments the threat landscape and increases the probability of cyber-attacks by malicious entities, which aim at the exploitation of vulnerabilities. In this paper, we propose a risk assessment method based on the NIST SP 800-30 standard, for identifying such vulnerabilities as well as to classify them according to a risk matrix based also on their impact on the AMI system. The method is then applied to the DLMS/COSEM, in order to identify its vulnerabilities, which may be later be exploited within a cyber-attack aiming in disruption the AMI system operation. Moreover, it is demonstrated through a 5G-enabled emulated smart home network which is used to exploit smart meter vulnerabilities and then through a lateral movement to conduct attacks causing fluctuations on PhotoVoltaic (PV) systems and energy storage batteries.

Files

RiskDLMS-v1.pdf

Files (4.7 MB)

Name Size Download all
md5:3053f5d9bbd5a1f79422cd1e335d0958
4.7 MB Preview Download

Additional details

Dates

Accepted
2023