Abnormal Message Logic & Sequence Detection for Process Layer Network in Digital Substation

Kangyi Li,Hang Mu,Caiming Yang,Jianmin Zhang,Naizheng Jin,Ji Xu
DOI: https://doi.org/10.1109/ispec53008.2021.9735648
2021-01-01
Abstract:Logic target attack and sequence target attack are two types of sophisticated and vicious cyber-attacks, which have not been paid a necessary attention in most critical part, i.e., the process layer network in digital substation. The relationships of such two types attack are explored, and networked structure of an intrusion detection & prevention system for the process layer network is proposed. A whitelist-based detection scheme is also proposed; firstly, the corresponding packets are described from the packet transfer path and the circuit breaker action packet; then, the different detection methods are used to check the packets; the simulation test results and verification show that the proposed method can detect an abnormal transmission path message and a replay attack with inserted circuit breaker action packet.
What problem does this paper attempt to address?