Exploration of the Potential of Process Mining for Intrusion Detection in Smart Metering

G. Eibl, C. Ferner, T. Hildebrandt, F. Stertz, S. Burkhart, S. Rinderle-Ma, D. Engel

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Process mining is a set of data mining techniques that learn and analyze processes based on event logs. While process mining has recently been proposed for intrusion detection in business processes, it has never been applied to smart metering processes. The goal of this paper is to explore the potential of process mining for the detection of intrusions into smart metering systems. As a case study the remote shutdown process has been modeled and a threat analysis was conducted leading to an extensive attack tree. It is shown that currently proposed process mining techniques based on conformance checking do not suffice to find all attacks of the attack tree; an inclusion of additional perspectives is necessary. Consequences for the design of a realistic testing environment based on simulations are discussed. Copyright © 2017 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved.
Original languageEnglish
Title of host publication Proceedings of the 3rd International Conference on Information Systems Security and Privacy
PublisherSCITEPRESS
Pages38-46
Number of pages9
Volume1
ISBN (Print)978-989-758-209-7
DOIs
Publication statusPublished - 2017
Event3rd International Conference on Information Systems Security and Privacy, ICISSP 2017 - Porto, Portugal
Duration: 19 Feb 201721 Feb 2017
https://icissp.scitevents.org/?y=2017

Conference

Conference3rd International Conference on Information Systems Security and Privacy, ICISSP 2017
Abbreviated titleICISSP 2017
Country/TerritoryPortugal
CityPorto
Period19/02/1721/02/17
Internet address

Keywords

  • Intrusion Detection
  • Process Mining
  • Smart Grids
  • Smart Metering
  • Data mining
  • Electric measuring instruments
  • Forestry
  • Information systems
  • Information use
  • Attack tree
  • Business Process
  • Conformance checking
  • Process mining
  • Smart grid
  • Smart metering
  • Testing environment
  • Threat analysis
  • Intrusion detection

Fingerprint

Dive into the research topics of 'Exploration of the Potential of Process Mining for Intrusion Detection in Smart Metering'. Together they form a unique fingerprint.

Cite this