TY - GEN
T1 - Comparison of approaches for intrusion detection in substations using the IEC 60870-5-104 protocol
AU - Egger, M.
AU - Eibl, G.
AU - Engel, D.
N1 - Cited By :7
Export Date: 14 December 2023
Correspondence Address: Egger, M.; Austrian Power Grid AG, Wagramer Str. 19, Austria; email: [email protected]
Funding details: Bundesamt für Energie, UFE
Funding details: Salzburger Landesregierung
Funding text 1: Günther Eibl and Dominik Engel gratefully acknowledge funding by the Federal State of Salzburg under the WISS2025 program. Publication costs were covered by the DACH+ Energy Informatics Conference Organizers, supported by the Swiss Federal Office of Energy.
References: Ang, C.K.G., Utomo, N.P., Cyber security in the energy world (2017) 2017 Asian Conference on Energy, Power and Transportation Electrification (ACEPT), , IEEE, Singapore; Berthier, R., Sanders, W.H., Khurana, H., Intrusion detection for advanced metering infrastructures: Requirements and architectural directions (2010) 2010 First IEEE International Conference on Smart Grid Communications, , IEEE, Gaithersburg; Butt, U.J., Abbod, M., Lors, A., Jahankhani, H., Jamal, A., Kumar, A., Ransomware threat and its impact on SCADA (2019) 2019 IEEE 12th International Conference on Global Security, Safety and Sustainability (ICGS3), , IEEE, London; Win32/industroyer a new threat for industrial control systems. Techreport (2017) ESET, , https://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf; Mar-17-352-01 hatman - safety system targeted malware (Update b). techreport, U.S (2019) Department of Homeland Security, , https://us-cert.cisa.gov/sites/default/files/documents/MAR-17-352-01%20HatMan%E2%80%94Safety%20System%20Targeted%20Malware_S508C.pdf; Czechowski, R., Wicher, P., Wiecha, B., Cyber security in communication of SCADA systems using IEC 61850 (2015) 2015 Modern Electric Power Systems (MEPS), , IEEE, Wroclaw; Falliere, N., Murchu, L.O., Chien, E., (2011); Feng, C., Li, T., Chana, D., Multi-level Anomaly Detection in Industrial Control Systems via Package Signatures and LSTM Networks (2017) 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 261-272. , IEEE, Denver; Hoeve, M., Detecting intrusions in encrypted control traffic (2013) Proceedings of the First ACM Workshop on Smart Energy Grid Security - SEGS 2013, , ACM Press, New York; (2006) Telecontrol equipment and systems - Part 5-104: Transmission protocols - Network access for IEC 60870-5-101 using standard transport profiles. IEC 60870-5-104:2006, , IEC, Geneva; Jiang, J., Yasakethu, L., Anomaly detection via one class SVM for protection of SCADA systems (2013) 2013 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery, , IEEE, Beijing; Khodabakhsh, A., Yayilgan, S.Y., Houmb, S.H., Hurzuk, N., Foros, J., Istad, M., Cyber-security gaps in a digital substation: From sensors to SCADA (2020) 2020 9th Mediterranean Conference on Embedded Computing (MECO), , IEEE, Budva; Matoušek, P., (2017) Description and Analysis of Iec 104 Protocol. Techreport. Faculty of Information Technology BUT; Maynard, P., McLaughlin, K., Haberler, B., Towards understanding man-in-the-middle attacks on IEC 60870-5-104 SCADA networks (2014) 2nd International Symposium for ICS & SCADA Cyber Security Research 2014, , BCS Learning & Development, Niederösterreich; MITRE (2020) ATT&CK for Industrial Control Systems. https://collaborate.mitre.org/attackics/index.php/Main_Page. Accessed 01 June 2020; Pacho, C., (2016) IEC 60870-5-104 Protocol Detection Rules, , https://blog.snort.org/2016/12/iec60870-5-104-protocol-detection-rules.html.Accessed22May2020; Peterson, D., Quickdraw: Generating security log events for legacy SCADA and control system devices (2009) 2009 Cybersecurity Applications & Technology Conference for Homeland Security, , IEEE, Washington; Phillips, B., Gamess, E., Krishnaprasad, S., An evaluation of machine learning-based anomaly detection in a SCADA system using the modbus protocol (2020) Proceedings of the 2020 ACM Southeast Conference, , ACM, Tampa; Pliatsios, D., Sarigiannidis, P., Lagkas, T., Sarigiannidis, A.G., A survey on SCADA systems: Secure protocols, incidents, threats and tactics (2020) IEEE Commun Surv Tutor, 22, p. 1; Roesch, M., Green, C., Cisco, T.S., (2020) SNORT Users Manual 2.9, p. 16. , https://www.snort.org/#documents.Accessed22May2020; Schölkopf, B., Williamson, R., Smola, A., Shawe-Taylor, J., Piatt, J., Support vector method for novelty detection (2000) Advances in Neural Information Processing Systems, pp. 582-588. , Proceedings of the 12th International Conference on Neural Information Processing, Denver; Skoko, V., Atlagic, B., Isakov, N., Comparative realization of IEC 60870-5 industrial protocol standards (2014) 22nd Telecommunications Forum Telfor (TELFOR), , IEEE, Belgrade; Vadari, M., (2020) Electric System Operations: Evolving to the Modern Grid, , Artech House, Boston; Yan, Y., Qian, Y., Sharif, H., Tipper, D., A survey on cyber security for smart grid communications (2012) IEEE Commun Surv Tutor, 14 (4), pp. 998-1010; Yang, Y., McLaughlin, K., Littler, T., Sezer, S., Pranggono, B., Wang, H.F., Intrusion detection system for IEC 60870-5-104 based SCADA networks (2013) 2013 IEEE Power & Energy Society General Meeting, , IEEE, Vancouver; Yoon, M.-K., Ciocarlie, G., Communication Pattern Monitoring: Improving the Utility of Anomaly Detection for Industrial Control Systems In: NDSS Workshop on Security of Emerging Networking Technologies, 1–10 (2014) San Diego, , https://doi.org/10.14722/sent.2014.23012
PY - 2020/10/28
Y1 - 2020/10/28
N2 - Electrical networks of transmission system operators are mostly built up as isolated networks without access to the Internet. With the increasing popularity of smart grids, securing the communication network has become more important to avoid cyber-attacks that could result in possible power outages. For misuse detection, signature-based approaches are already in use and special rules for a wide range of protocols have been developed. However, one big disadvantage of signature-based intrusion detection is that zero-day exploits cannot be detected. Machine-learning-based anomaly detection methods have the potential to achieve that. In this paper, various such methods for intrusion detection in substations, which use the asynchronous communication protocol International Electrotechnical Commission (IEC) 60870-5-104, are tested and compared. The evaluation of the proposed methods is performed by applying them to a data set which includes normal operation traffic and four different attacks. While the results of supervised and semi-supervised machine learning approaches are rather encouraging, the unsupervised and signature-based methods suffer from general bad performance and had difficulties to detect some attacks. © 2020, The Author(s).
AB - Electrical networks of transmission system operators are mostly built up as isolated networks without access to the Internet. With the increasing popularity of smart grids, securing the communication network has become more important to avoid cyber-attacks that could result in possible power outages. For misuse detection, signature-based approaches are already in use and special rules for a wide range of protocols have been developed. However, one big disadvantage of signature-based intrusion detection is that zero-day exploits cannot be detected. Machine-learning-based anomaly detection methods have the potential to achieve that. In this paper, various such methods for intrusion detection in substations, which use the asynchronous communication protocol International Electrotechnical Commission (IEC) 60870-5-104, are tested and compared. The evaluation of the proposed methods is performed by applying them to a data set which includes normal operation traffic and four different attacks. While the results of supervised and semi-supervised machine learning approaches are rather encouraging, the unsupervised and signature-based methods suffer from general bad performance and had difficulties to detect some attacks. © 2020, The Author(s).
KW - IEC 60870-5-104
KW - Intrusion detection
KW - SCADA
KW - Anomaly detection
KW - Electric power transmission
KW - Electric power transmission networks
KW - Machine learning
KW - Outages
KW - Smart power grids
KW - Zero-day attack
KW - Communications networks
KW - Electrical networks
KW - International electro-technical commissions
KW - International Electrotechnical Commission
KW - International electrotechnical commission 60870-5-104
KW - Intrusion-Detection
KW - Isolated networks
KW - Power outage
KW - Transmission system operators
U2 - 10.1186/s42162-020-00118-4
DO - 10.1186/s42162-020-00118-4
M3 - Conference contribution
VL - 3
T3 - Energy. Inform.
BT - Proceedings of the 9th DACH+ Conference on Energy Informatics
T2 - The 9th DACH+ Conference on Energy Informatics
Y2 - 29 October 2020 through 30 October 2020
ER -