Multi-Source Data Fusion for Cyberattack Detection in Power Systems
Cyberattacks can cause a severe impact on power systems unless detected early. However, accurate and timely detection in critical infrastructure systems presents challenges, e.g., due to zero-day vulnerability exploitations and the cyber-physical nature of the system coupled with the need for high reliability and resilience of the physical system. Conventional rule-based and anomaly-based intrusion detection system (IDS) tools are insufficient for detecting zero-day cyber intrusions in the industrial control system (ICS) networks. Hence, in this work, we show that fusing information from multiple data sources can help identify cyber-induced incidents and reduce false positives. Specifically, we present how to recognize and address the barriers that can prevent the accurate use of multiple data sources for fusion-based detection. We perform multi-source data fusion for training IDS in a cyber-physical power system testbed where we collect cyber and physical side data from multiple sensors emulating real-world data sources that would be found in a utility and synthesizes these into features for algorithms to detect intrusions. Results are presented using the proposed data fusion application to infer False Data and Command injection-based Man-in- The-Middle (MiTM) attacks. Post collection, the data fusion application uses time-synchronized merge and extracts features followed by pre-processing such as imputation and encoding before training supervised, semi-supervised, and unsupervised learning models to evaluate the performance of the IDS. A major finding is the improvement of detection accuracy by fusion of features from cyber, security, and physical domains. Additionally, we observed the co-training technique performs at par with supervised learning methods when fed with our features.
Code (0)
등록된 구현이 없습니다.
Tasks
ImputationIntrusion DetectionSimilar Papers 제목 키워드 기반
Cyberattack Detection for Nonlinear Leader-Following Multi-Agent Systems Using Set-Membership Fuzzy Filtering
This paper is concerned with cyberattack detection in discrete-time, leader-following, nonlinear, multi-agent systems subject to unknown but bounded (UBB) system noises. The Takagi-Sugeno (T-S) fuzzy model is employed to…
PredictionHybrid Machine Learning Approach for Cyberattack Mitigation of Parallel Converters in a DC Microgrid
Cyberattack susceptibilities are introduced as the communication requirement increases with the incorporation of more renewable energy sources into DC microgrids. Parallel DC-DC converters are utilized to provide high cu…
Hybrid Machine LearningCyberattack Detection in Large-Scale Smart Grids using Chebyshev Graph Convolutional Networks
As a highly complex and integrated cyber-physical system, modern power grids are exposed to cyberattacks. False data injection attacks (FDIAs), specifically, represent a major class of cyber threats to smart grids by tar…
Detection and Mitigation of Cyberattacks on Volt-Var Control
Cyberattacks are becoming more frequent, and attackers can use different mechanisms, such as denial of service (DoS) and false data injection (FDI). Furthermore, multiple attack types can be launched simultaneously, know…
A Cyberattack Detection-Isolation Scheme For CAV Under Changing Driving Environment
Under a changing driving environment, a Connected Autonomous Vehicle (CAV) platoon relies strongly on the acquisition of accurate traffic information from neighboring vehicles as well as reliable commands from a centrali…