首页> 外文会议>IEEE International Conference on Power and Energy >A retrofit network transaction data logger and intrusion detection system for transmission and distribution substations
【24h】

A retrofit network transaction data logger and intrusion detection system for transmission and distribution substations

机译:一种改造网络交易数据记录器和用于传输和分配变电站的入侵检测系统

获取原文

摘要

SCADA systems are widely used in electricity generation, distribution, and transmission control systems. NERC CIP 002–009 requires bulk electric providers to secure critical cyber assets electronically and physically. Transmission and distribution substations contain cyber critical assets including remote terminal units (RTU), intelligent electronic devices (IED) such as relays, phasor measurement units (PMU) and phasor data concentrators (PDC). Substation critical cyber assets are isolated in electronic security perimeters using firewalls. In this paper a retrofit data logger solution for serial communication based MODBUS and DNP3 network appliances is offered. The retrofit data logger allows existing control systems to be updated to log network transactions in support of substation based network intrusion detection. Substation based intrusion detection supports a defense in depth approach to cyber security in which multiple overlapping layers of security are used to protect critical cyber assets. The data logger is an embedded bump-in-the-wire retrofit device which captures, time stamps, cryptographically signs, encrypts, and store network traffic. Network traffic is forwarded to the existing network. Additionally, the data logger architecture supports use of signature based and statistics based intrusion detection algorithms at the network appliance edge.
机译:SCADA系统广泛用于发电,分配和传输控制系统。 NERC CIP 002-009需要批量电力提供商以电子方式和物理安全地保护重要的网络资产。传输和分配变电站包含网络关键资产,包括远程终端单元(RTU),智能电子设备(IED),如继电器,PHASOR测量单元(PMU)和PHASOR数据集中器(PDC)。变电站关键网络资产使用防火墙在电子安全外围隔离。在本文中,提供了一种用于基于串行通信的Modbus和DNP3网络设备的改造数据记录器解决方案。改造数据记录器允许将现有的控制系统更新以对基于变电站的网络入侵检测的支持来记录网络交易。基于变电站的入侵检测支持深度探索网络安全性,其中多个重叠的安全层用于保护关键网络资产。数据记录器是嵌入式凸点的跨线改装设备,其捕获,时间戳,加密标志,加密和存储网络流量。网络流量转发到现有网络。此外,数据记录器架构支持使用基于签名和基于统计的入侵检测算法在网络设备边缘。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号