...
首页> 外文期刊>Computer networks >A survey on intrusion detection and prevention systems in digital substations
【24h】

A survey on intrusion detection and prevention systems in digital substations

机译:数字变电站入侵检测和预防系统调查

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

© 2020 Elsevier B.V.Smart Grids integrate the traditional power grid with information processing and communication technologies. In particular, substation intelligent devices can now communicate with each other digitally to enable remote information gathering, monitoring, and control. There have been many efforts to promote global communication standards. The IEC–61850 international standard addresses substation communication networks and systems. Despite the many benefits, this standardized communication poses new cyber-security challenges. Also, traditional Intrusion Detection Systems (IDSs) may not be suitable for digital substations, given their critical components and stringent time requirements. We present an in-depth analysis of attacks exploiting IEC–61850 substations and recent research efforts for detecting and preventing them. Our main contribution is an original taxonomy comprising design and evaluation aspects for substation-specific IDSs. This taxonomy includes IDS's architectures, detection approaches, analysis, actions, data sources, detection range, validation strategies, and metrics. Additionally, we present a compilation of the detection rules deployed by the state-of-art IDSs and assess their resiliency to five types of attacks. Our assessment reveals that some attacks are covered by currently-deployed IDSs, but, particularly, further advancement is necessary to deal with masquerade attacks. Finally, we discuss trends, open issues, and future research topics.
机译:©2020 elestvier b.v.smart网格与信息处理和通信技术集成了传统的电网。特别地,变电站智能设备现在可以以数字方式彼此通信,以实现远程信息收集,监控和控制。促进全球沟通标准有很多努力。 IEC-61850国际标准解决了变电站通信网络和系统。尽管有很多好处,但这种标准化的通信造成了新的网络安全挑战。此外,鉴于其关键组件和严格的时间要求,传统的入侵检测系统(IDS)可能不适合数字变电站。我们对利用IEC-61850变电站的攻击和最近的研究努力进行了深入分析,用于检测和防止它们。我们的主要贡献是原始分类,包括用于特定变电站的设计和评估方面。该分类系统包括IDS的架构,检测方法,分析,操作,数据源,检测范围,验证策略和指标。此外,我们撰写了由最先进的IDS部署的检测规则,并评估其弹性至五种类型的攻击。我们的评估表明,目前部署的IDS涵盖了一些攻击,但特别是,需要进一步的进步来处理化妆舞会攻击。最后,我们讨论趋势,开放问题和未来的研究主题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号