vix.ing · top · new · best · stats

Towards anomaly detection in smart grids by combining Complex Events Processing and SNMP objects

2021/06/28 by Massimiliano Leone Itria, Itria, Massimiliano Leone, Enrico Schiavone +3
Computer Science · Engineering · #Caching and Content Delivery #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Network Security and Intrusion Detection #Smart Grid Security and Resilience #cs.CR

paper · pdf · doi:10.48550/arxiv.2106.14508

Version submitted for review at the 2021 IEEE International Conference on Cyber Security and Resilience

arxiv created 2021/06/28 · openalex publication_date 2021/06/28 · arxiv updated 2021/06/29 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28

Abstract

This paper describes the architecture and the fundamental methodology of an anomaly detector, which by continuously monitoring Simple Network Management Protocol data and by processing it as complex-events, is able to timely recognize patterns of faults and relevant cyber-attacks. This solution has been applied in the context of smart grids, and in particular as part of a security and resilience component of the Information and Communication Technologies (ICT) Gateway, a middleware-based architecture that correlates and fuses measurement data from different sources (e.g., Inverters, Smart Meters) to provide control coordination and to enable grid observability applications. The detector has been evaluated through experiments, where we selected some representative anomalies that can occur on the ICT side of the energy distribution infrastructure: non-malicious faults (indicated by patterns in the system resources usage), as well as effects of typical cyber-attacks directed to the smart grid infrastructure. The results show that the detection is promisingly fast and efficient.

Related