首页> 外文会议>Conference on Resilience Week >A Hierarchical Multi-Agent Based Anomaly Detection for Wide-Area Protection in Smart Grid
【24h】

A Hierarchical Multi-Agent Based Anomaly Detection for Wide-Area Protection in Smart Grid

机译:基于分层的多代理基于智能电网广域保护的异常检测

获取原文

摘要

Future smart grid capabilities provide assurance to expand the advanced information and communication technologies to evolve into densely interconnected cyber physical system. Remedial Action Scheme (RAS), widely used for wide-area protection, relies on the interconnected networks and data sharing devices, which are exposed to the multitude of vulnerabilities. This paper presents our proposed approach to developing multi-agent based RAS scheme against the system-aware stealthy cyber-attacks. Specifically, we propose the two-level hierarchical architecture which consists of distributed local RAS controllers (RAScs) as local agents, operating at different zones/ areas, which are constantly monitored by an overseer, the central agent. The local controllers receive local and randomly changing outside zonal measurements and cyclically forwards to the overseer. The overseer identifies the corrupted controller using the anomaly detection algorithm which processes the measurements coming from the local controllers, compute measurement errors using local and outside zonal measurements, perform validation checks, and finally detect anomalies based on the two-step verification. Next, as a proof of concept, we have implemented and validated the proposed methodology in cyber physical environment at Iowa State's PowerCyber testbed. We have also implemented the coordinated attack vectors which involve corrupting the local controller and later performing stealthy attacks on the system's generator. We have evaluated its performance during the online testing in terms of detection rate and Iatency. The experimental results show that it is efficient in detecting different classes of attacks, including ramp and pulse attacks.
机译:未来的智能电网功能提供保证,以扩展高级信息和通信技术,以发展到密集的互连网络物理系统。用于广域保护广泛保护的补救措施方案(RAS)依赖于互连的网络和数据共享设备,这些设备暴露于众多漏洞。本文介绍了我们提出了对系统意识的隐身网络攻击开发基于多智能体的RAS方案的方法。具体而言,我们提出了由分布式本地RAS控制器(RASCS)作为本地代理商组成的两级分层架构,在不同的区域/地区运行,这些地区由监督者,中央代理商不断监控。本地控制器接收局部和随机改变在区域外部测量外,并循环向前转发到监督者。监督者使用异常检测算法识别损坏的控制器,该控制器处理来自本地控制器的测量值,使用本地和外部测量计算测量误差,执行验证检查,最后检测基于两步验证的异常。接下来,作为概念证明,我们已经实施并验证了Iowa州Powercyber试验台的网络物理环境中所提出的方法。我们还实施了协调攻击向量,涉及损坏本地控制器,后来对系统发电机进行隐身攻击。在检测率和国际性方面,我们在在线测试期间评估了其性能。实验结果表明,在检测不同类别的攻击方面是有效的,包括斜坡和脉冲攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号