Publication Details

Outlier Detection in Smart Grid Communication

MUTUA Nelson Makau and MATOUŠEK Petr. Outlier Detection in Smart Grid Communication. In: Fast Abstracts and Student Forum Proceedings, 17th European Dependable Computing Conference. Munich, 2021, pp. 1-4. Available from: https://arxiv.org/abs/2108.12781
Czech title
Detekce odlehlých hodnot v komunikaci chytrých sítí
Type
conference paper
Language
english
Authors
URL
Keywords

detekce anomálií, komunikační vzory, chytré rozvodné sítě, IEC 104, statistický model, průmyslová řidící komunikace ICS, metoda LOF.

Abstract

Industrial Control System (ICS) networks transmit control and monitoring data in critical environments such as smart grid. Cyber attacks on smart grid communication may cause fatal consequences on energy production, distribution, and eventually the lives of people. Since the attacks can be initiated from both the inside and outside of the network, traditional smart grid security tools like firewalls or Intrusion Detection Systems (IDS), which are typically deployed on the edge of the network, are not able to detect internal threats. For this reason, we also need to analyze behavior of internal ICS communication.

Due to its nature, ICS traffic exhibits stable and predictable communication patterns.  These patterns can be described using statistical models. By observing selected features of ICS network communication like packet inter arrival times, we can create a statistical profile of the communication based on the patterns observed in the normal communication traffic. This technique is effective, fast and easy to implement. As our experiments show, statistical-based anomaly detection is able to detect common security incidents in ICS communication. This paper employs selected network packet attributes to create a statistical model for anomaly detection using the Local Outlier Factor (LOF) algorithm. The proof-of-concept is demonstrated on IEC 60870-5-104 (a.k.a.  IEC 104) protocol.

Published
2021
Pages
1-4
Proceedings
Fast Abstracts and Student Forum Proceedings, 17th European Dependable Computing Conference
Conference
17th European Dependable Computing Conference, Mnichov, DE
Place
Munich, DE
BibTeX
@INPROCEEDINGS{FITPUB12536,
   author = "Makau Nelson Mutua and Petr Matou\v{s}ek",
   title = "Outlier Detection in Smart Grid Communication",
   pages = "1--4",
   booktitle = "Fast Abstracts and Student Forum Proceedings, 17th European Dependable Computing Conference",
   year = 2021,
   location = "Munich, DE",
   language = "english",
   url = "https://www.fit.vut.cz/research/publication/12536"
}
Files
Back to top