Hybrid Intrusion Detection System Design for Distributed Energy Resource Systems

A. Chavez,N. Jacobs,C. B. Jones,J. Johnson,A. Summers,S. Hossain‐McKenzie,C. Lai
DOI: https://doi.org/10.1109/CyberPELS.2019.8925064
2019-04-01
Abstract:The integration of communication-enabled grid-support functions in distributed energy resources (DER) and other smart grid features will increase the U.S. power grid's exposure to cyber-physical attacks. Unwanted changes in DER system data and control signals can damage electrical infrastructure and lead to outages. To protect against these threats, intrusion detection systems (IDSs) can be deployed, but their implementation presents a unique set of challenges in industrial control systems (ICSs), New approaches need to be developed that not only sense cyber anomalies, but also detect undesired physical system behaviors. For DER systems, a combination of cyber security data and power system and control information should be collected by the IDS to provide insight into the nature of an anomalous event. This allows joint forensic analysis to be conducted to reveal any relationships between the observed cyber and physical events. In this paper, we propose a hybrid IDS approach that monitors and evaluates both physical and cyber network data in DER systems, and present a series of scenarios to demonstrate how our approach enables the cyber-physical IDS to achieve more robust identification and mitigation of malicious events on the DER system.
Environmental Science,Engineering,Computer Science
What problem does this paper attempt to address?