A packet payload anomaly detection approach for cyber-physical power systems

Tao Yang,Bingjing Yan,Qiang Yang,Wenhai Wang
DOI: https://doi.org/10.17775/CSEEJPES.2022.06550
IF: 6.014
2023-01-01
CSEE Journal of Power and Energy Systems
Abstract:Cyber-Physical Power Systems (CPSSs) are the integration of state-of-the-art Information and Communication Technologies (ICT) and power systems. A sophisticated attacker can launch cyber-physical attacks on CPPS, i.e. invading the cyber system illegally to cause catastrophes in the physical power systems. Therefore, effective and timely anomaly detection is critical for ensuring the normal operation of CPPS. This paper proposed a network traffic packet payload anomaly detection approach for CPPS, consisting of a data preprocessing model, a Self-Adaptive Dynamic Segmentation (SADS) model and a classification model. The data preprocessing model can filter massive packets and convert the payloads into characters based on American Standard Code for Information Interchange (ASCII) codes. The SADS model is composed of a language method and an optimization method that can calculate the maximum probability path and obtain the segmented payload as the input of the classification model. The packet payload contains complex semantic information. A classification model is developed to learn the long-term and short-term dependence relationships by combining Bidirectional Encoder Representation from Transformers (BERT) with a 1D-Convolutional Neural Network (1D-CNN). The proposed packet payload anomaly detection approach is evaluated in a CPPS testbed. The experiments demonstrate that the proposed detection approach achieves real-time detection and better classification results compared with two existing anomaly detection models.
What problem does this paper attempt to address?