SDN-Based Smart Cyber Switching (SCS) for Cyber Restoration of a Digital Substation

Mansi Girdhar,Kuchan Park,Wencong Su,Junho Hong,Akila Herath,Chen-Ching Liu
2024-11-12
Abstract:In recent years, critical infrastructure and power grids have increasingly been targets of cyber-attacks, causing widespread and extended blackouts. Digital substations are particularly vulnerable to such cyber incursions, jeopardizing grid stability. This paper addresses these risks by proposing a cybersecurity framework that leverages software-defined networking (SDN) to bolster the resilience of substations based on the IEC-61850 standard. The research introduces a strategy involving smart cyber switching (SCS) for mitigation and concurrent intelligent electronic device (CIED) for restoration, ensuring ongoing operational integrity and cybersecurity within a substation. The SCS framework improves the physical network's behavior (i.e., leveraging commercial SDN capabilities) by incorporating an adaptive port controller (APC) module for dynamic port management and an intrusion detection system (IDS) to detect and counteract malicious IEC-61850-based sampled value (SV) and generic object-oriented system event (GOOSE) messages within the substation's communication network. The framework's effectiveness is validated through comprehensive simulations and a hardware-in-the-loop (HIL) testbed, demonstrating its ability to sustain substation operations during cyber-attacks and significantly improve the overall resilience of the power grid.
Cryptography and Security,Emerging Technologies
What problem does this paper attempt to address?
The problem that this paper attempts to solve is the cyber - security threats faced by modern digital substations. Specifically, as critical infrastructures and power grids are increasingly becoming targets of cyber - attacks, especially digital substations under the IEC - 61850 standard, their communication networks are vulnerable to malicious Sampled Value (SV) and Generic Object - Oriented Substation Event (GOOSE) message attacks, which can lead to system failures and large - scale power outages. To solve these problems, this paper proposes an intelligent network switching (Smart Cyber Switching, SCS) framework based on Software - Defined Networking (SDN), aiming to enhance the resilience and cyber - security of substations. The following are the main problems presented in the paper and their solutions: ### 1. **Limitations of Existing Cyber - security Measures** - **Lack of a comprehensive cyber - security solution**: Many existing methods only address certain aspects of cyber - security and do not provide a comprehensive solution to deal with all known vulnerabilities. - **Challenges in attack location and isolation**: Current methods often focus on intrusion detection but lack the ability to effectively locate and isolate attacks within substations. - **Insufficient real - time response capabilities**: Existing solutions usually lack the ability to dynamically reconfigure the network and cannot effectively respond to real - time network threats. ### 2. **Proposed Solutions** - **Smart Cyber Switching (SCS) framework**: This framework realizes dynamic port management by introducing an Adaptive Port Controller (APC) module and combines with an Intrusion Detection System (IDS) to detect and block malicious SV and GOOSE messages. - **Concurrent Intelligent Electronic Device (CIED)**: When a Physical Intelligent Electronic Device (PIED) is attacked, the CIED can take over its protection functions to ensure the continuity and security of substation operations. ### 3. **Specific Technical Details** - **Adaptive Port Controller (APC)**: Dynamically manage OpenFlow table rules and policies to achieve real - time network reconfiguration and isolate attacked devices. - **Intrusion Detection System (IDS)**: The advanced IDS is designed to detect severe cyber - attacks and trigger the SCS to isolate the attacked devices while invoking the CIED to take over critical protection functions. - **Real - time simulation and verification**: Verify the effectiveness of the framework through a Hardware - in - the - Loop (HIL) test platform and demonstrate its performance in抵御SV and GOOSE network attacks. ### 4. **Objectives** - **Minimize the impact of cyber - attacks on substation operations**: Ensure the functionality and reliability of substation networks through rapid detection, isolation, and recovery mechanisms. - **Improve the resilience and reliability of the overall power grid**: Provide an advanced, integrated solution to deal with complex cyber - attacks by integrating SCS and CIED technologies. In conclusion, this paper provides a comprehensive solution to address the cyber - security challenges faced by digital substations by introducing the SCS framework and CIED technology, ensuring the stable operation and safety and reliability of the power grid.