用户名: 密码: 验证码:
A new methodology for real-time detection of attacks in IEC 61850-based systems
详细信息    查看全文
文摘
This paper presents a new methodology to detect spoofing attacks concerning Generic Object Oriented Substation Event (GOOSE) messages in IEC 61850 communication systems. The methodology is based on anomaly detection, in which GOOSE messages are characterized by observing the correct operation of the power system and any variation of the normal behavior is classified as an intrusion. To validate this methodology, a pulse generation logic was configured to communicate among Intelligent Electronic Devices (IEDs), which were prone to replication attacks and tampering messages. The results show that the IEDs are vulnerable to such attacks, and that the Intrusion Detection Systems (IDS) of corporate networks are not able to deal with specific attacks in IEC 61850. Considering this, real time tools are needed to analyze GOOSE messages in order to identify intrusion. The software proposed in this paper was very efficient in detecting replication and falsification messages.

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700