首页> 外文会议>Conference on Resilience Week >A Hierarchical Multi-Agent Based Anomaly Detection for Wide-Area Protection in Smart Grid
【24h】

A Hierarchical Multi-Agent Based Anomaly Detection for Wide-Area Protection in Smart Grid

机译:基于分层Agent的智能电网广域保护异常检测

获取原文

摘要

Future smart grid capabilities provide assurance to expand the advanced information and communication technologies to evolve into densely interconnected cyber physical system. Remedial Action Scheme (RAS), widely used for wide-area protection, relies on the interconnected networks and data sharing devices, which are exposed to the multitude of vulnerabilities. This paper presents our proposed approach to developing multi-agent based RAS scheme against the system-aware stealthy cyber-attacks. Specifically, we propose the two-level hierarchical architecture which consists of distributed local RAS controllers (RAScs) as local agents, operating at different zones/ areas, which are constantly monitored by an overseer, the central agent. The local controllers receive local and randomly changing outside zonal measurements and cyclically forwards to the overseer. The overseer identifies the corrupted controller using the anomaly detection algorithm which processes the measurements coming from the local controllers, compute measurement errors using local and outside zonal measurements, perform validation checks, and finally detect anomalies based on the two-step verification. Next, as a proof of concept, we have implemented and validated the proposed methodology in cyber physical environment at Iowa State's PowerCyber testbed. We have also implemented the coordinated attack vectors which involve corrupting the local controller and later performing stealthy attacks on the system's generator. We have evaluated its performance during the online testing in terms of detection rate and Iatency. The experimental results show that it is efficient in detecting different classes of attacks, including ramp and pulse attacks.
机译:未来的智能电网功能可确保扩展高级信息和通信技术,从而发展为紧密互连的网络物理系统。补救措施方案(RAS)广泛用于广域保护,它依赖于互连网络和数据共享设备,这些设备面临许多漏洞。本文提出了针对基于系统的隐身网络攻击开发基于多代理的RAS方案的建议方法。具体来说,我们提出了一个两级分层体系结构,该体系结构由作为本地代理的分布式本地RAS控制器(RAScs)组成,它们在不同的区域/区域中运行,并由监督者(中央代理)不断地进行监控。本地控制器接收本地和随机变化的外部区域测量值,并周期性地转发给监督者。监督者使用异常检测算法识别损坏的控制器,该算法处理来自本地控制器的测量值,使用本地和外部区域测量值计算测量误差,执行验证检查,最后基于两步验证来检测异常。接下来,作为概念验证,我们已经在爱荷华州立大学PowerCyber​​测试平台上实施并验证了所建议的网络物理环境中的方法。我们还实现了协调的攻击向量,其中包括破坏本地控制器,然后对系统的生成器执行隐式攻击。我们已经在在线测试过程中根据检测率和Iatency对其性能进行了评估。实验结果表明,它可以有效地检测包括斜波和脉冲攻击在内的不同类型的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号