首页> 外文学位 >Cyber security of substation automation systems.
【24h】

Cyber security of substation automation systems.

机译:变电站自动化系统的网络安全。

获取原文
获取原文并翻译 | 示例

摘要

Cyber intrusions into substations of a power grid are a source of vulnerability since most substations are unmanned and with limited protection of the cyber and physical security. In the worst case, simultaneous cyber intrusions into multiple substations can lead to severe cascading events, causing catastrophic power outages. In addition, substation communication protocols do not include cyber security features in their original standard. Generic Object Oriented Substation Event (GOOSE) contains the circuit breaker trip command whereas Sampled Measured Value (SMV) includes measured analog values such as currents and voltages. Due to the importance of substation automation multicast messages, IEC 62351 standards proposed the authentication method as a primary security measure for GOOSE and SMV messages since they required fast transmission time. However, performance testing for the application of the authentication method to GOOSE and SMV is in an early stage, and there is presently no solution to detection of the GOOSE and SMV related error, anomaly and intrusion. Cyber security technologies for anomaly detection at a substation are in an early stage of development. Technologies to detect anomalies for substation automation multicast protocols and applications are critically needed. This dissertation is concerned with anomaly detection in the computer network environment of a substation. The proposed integrated Anomaly Detection System (ADS) contains host- and network-based anomaly detection systems for the substations, and simultaneous anomaly detection for multiple substations. Potential scenarios of simultaneous intrusions into the substations have been simulated using a substation automation testbed based on the IEEE 39 and modified IEEE 118-bus systems. The host-based anomaly detection considers temporal anomalies in the substation facilities. The malicious behaviors of substation automation based on multicast messages are incorporated in the proposed network-based anomaly detection. The proposed impact evaluation method can help operators find the most critical substation among the anomaly detected substations. In addition, the proposed simultaneous intrusion detection method is able to identify the same type of attacks at multiple substations and their locations. The result is a new integrated tool for detection and mitigation of cyber intrusions at a single substation or multiple substations of a power grid.
机译:由于大多数变电站是无人值守的,并且对网络和物理安全的保护有限,因此网络入侵电网变电站是造成漏洞的原因。在最坏的情况下,同时侵入多个变电站的网络会导致严重的级联事件,从而导致灾难性的停电。此外,变电站通信协议在其原始标准中不包含网络安全功能。面向对象的通用变电站事件(GOOSE)包含断路器跳闸命令,而采样测量值(SMV)包括测量的模拟值,例如电流和电压。由于变电站自动化多播消息的重要性,IEC 62351标准提出了将身份验证方法作为GOOSE和SMV消息的主要安全措施,因为它们需要快速的传输时间。但是,将认证方法应用于GOOSE和SMV的性能测试尚处于早期阶段,目前还没有解决方案来检测与GOOSE和SMV相关的错误,异常和入侵。用于变电站异常检测的网络安全技术处于开发的早期阶段。迫切需要检测变电站自动化多播协议和应用程序异常的技术。本文涉及变电站计算机网络环境中的异常检测。提议的集成异常检测系统(ADS)包含用于变电站的基于主机和网络的异常检测系统,以及用于多个变电站的同时异常检测。使用基于IEEE 39和改进的IEEE 118总线系统的变电站自动化测试平台,可以模拟同时入侵变电站的潜在情况。基于主机的异常检测考虑了变电站设施中的时间异常。基于多播消息的变电站自动化的恶意行为被并入提出的基于网络的异常检测中。提出的影响评估方法可以帮助操作员在异常检测到的变电站中找到最关键的变电站。另外,提出的同时入侵检测方法能够在多个变电站及其位置识别相同类型的攻击。结果是提供了一个新的集成工具,用于检测和缓解电网中单个变电站或多个变电站的网络入侵。

著录项

  • 作者

    Hong, Junho.;

  • 作者单位

    Washington State University.;

  • 授予单位 Washington State University.;
  • 学科 Electrical engineering.
  • 学位 Ph.D.
  • 年度 2014
  • 页码 111 p.
  • 总页数 111
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号