Intrusion Threat Detection of Power Control Terminals in Digital Substation Power Industrial Control Systems Based on Recurrent Neural Network

Ge Minhui,Zhang Liang,Qu Gang,Zou Futai
DOI: https://doi.org/10.1109/iccasit58768.2023.10351736
2023-01-01
Abstract:Power control terminals are an important part of digital substation power industrial control system. Once invaded, they can pose significant security threats to the system. Therefore, researching intrusion detection for power control devices is crucial to safeguard the security of the entire power industrial control system. In digital substations, most power control terminals are composed of IoT devices, and a significant portion of them are non-involved devices. Currently, the threat of botnet invasions to non-involved IoT terminals in digital substations has become more prominent. On the one hand, due to the evolution of botnets in recent years, there are more and more types of botnets, increasing destructive power and increasing threats to cybersecurity. On the other hand, the features of them differ significantly from that of traditional internet bots, rendering conventional detection technologies less effective. In this paper, we propose an innovative botnet detection framework for power control terminals in digital substation power industrial control systems using a recurrent neural network. Considering the spatial and temporal consistency in the binary packages of IoT botnets, we extract features based on abnormal behavior and network flow. Subsequently, we employ recurrent neural network models for the detection process. Our experimental results demonstrate an impressive F1 score of 95.80%, presenting a practical and significant solution for identifying IoT zombies in power industrial control systems.
What problem does this paper attempt to address?