Feature Selection for Precise Anomaly Detection in Substation Automation Systems

Xuelei Wang, Colin J. Fidge, G. Nourbakhsh, Ernest Foo, Z. Jadidi, Calvin Li
{"title":"Feature Selection for Precise Anomaly Detection in Substation Automation Systems","authors":"Xuelei Wang, Colin J. Fidge, G. Nourbakhsh, Ernest Foo, Z. Jadidi, Calvin Li","doi":"10.1109/APPEEC50844.2021.9687629","DOIUrl":null,"url":null,"abstract":"With the rapid advancement of the electrical grid, substation automation systems (SASs) have been developing continuously. However, with the introduction of advanced features, such as remote control, potential cyber security threats in SASs are also increased. Additionally, crucial components in SASs, such as protection relays, usually come from third-party vendors and may not be fully trusted. Untrusted devices may stealthily perform harmful or unauthorised behaviours which could compromise or damage SASs, and therefore, bring adverse impacts to the primary plant. Thus, it is necessary to detect abnormal behaviours from an untrusted device before it brings about catastrophic impacts. Anomaly detection techniques are suitable to detect anomalies in SASs as they only bring minimal side-effects to normal system operations. Many researchers have developed various machine learning algorithms and mathematical models to improve the accuracy of anomaly detection. However, without prudent feature selection, it is difficult to achieve high accuracy when detecting attacks launched from internal trusted networks, especially for stealthy message modification attacks which only modify message payloads slightly and imitate patterns of benign behaviours. Therefore, this paper presents choices of features which improve the accuracy of anomaly detection within SASs, especially for detecting “stealthy” attacks. By including two additional features, Boolean control data from message payloads and physical values from sensors, our method improved the accuracy of anomaly detection by decreasing the false-negative rate from 25% to 5% approximately.","PeriodicalId":345537,"journal":{"name":"2021 13th IEEE PES Asia Pacific Power & Energy Engineering Conference (APPEEC)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 13th IEEE PES Asia Pacific Power & Energy Engineering Conference (APPEEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/APPEEC50844.2021.9687629","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

With the rapid advancement of the electrical grid, substation automation systems (SASs) have been developing continuously. However, with the introduction of advanced features, such as remote control, potential cyber security threats in SASs are also increased. Additionally, crucial components in SASs, such as protection relays, usually come from third-party vendors and may not be fully trusted. Untrusted devices may stealthily perform harmful or unauthorised behaviours which could compromise or damage SASs, and therefore, bring adverse impacts to the primary plant. Thus, it is necessary to detect abnormal behaviours from an untrusted device before it brings about catastrophic impacts. Anomaly detection techniques are suitable to detect anomalies in SASs as they only bring minimal side-effects to normal system operations. Many researchers have developed various machine learning algorithms and mathematical models to improve the accuracy of anomaly detection. However, without prudent feature selection, it is difficult to achieve high accuracy when detecting attacks launched from internal trusted networks, especially for stealthy message modification attacks which only modify message payloads slightly and imitate patterns of benign behaviours. Therefore, this paper presents choices of features which improve the accuracy of anomaly detection within SASs, especially for detecting “stealthy” attacks. By including two additional features, Boolean control data from message payloads and physical values from sensors, our method improved the accuracy of anomaly detection by decreasing the false-negative rate from 25% to 5% approximately.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
变电站自动化系统中精确异常检测的特征选择
随着电网的快速发展,变电站自动化系统得到了不断的发展。然而,随着远程控制等先进功能的引入,SASs中潜在的网络安全威胁也在增加。此外,SASs中的关键组件,如保护继电器,通常来自第三方供应商,可能不完全可信。不受信任的设备可能会暗中执行有害或未经授权的行为,这些行为可能会危及或损坏SASs,从而对主工厂产生不利影响。因此,有必要在不受信任的设备带来灾难性影响之前检测其异常行为。异常检测技术适合检测SASs中的异常,因为它们对系统正常运行的副作用很小。许多研究人员开发了各种机器学习算法和数学模型来提高异常检测的准确性。然而,在检测可信网络内部发起的攻击时,如果不进行谨慎的特征选择,很难达到较高的准确率,特别是对于仅对消息有效载荷进行轻微修改并模仿良性行为模式的隐形消息修改攻击。因此,本文提出了可以提高SASs异常检测准确性的特征选择,特别是在检测“隐身”攻击方面。通过包含两个额外的特征,即来自消息有效载荷的布尔控制数据和来自传感器的物理值,我们的方法通过将假阴性率从25%降低到大约5%来提高异常检测的准确性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Neural Networks-Based Detection of Cyber-Physical Attacks Leading to Blackouts in Smart Grids Limits of Electromagnetic Environment for Electric Vehicle Wireless Power Transfer Retrofitting of Conventional Two-wheelers to Electric Two-Wheelers Short-Term Solar and Wind Generation Forecasting for the Western Region of India Measurement of Real Time Energy Consumption using Low-Cost High-Speed Microcontroller
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1