Statistical Security Incident Forensics against Data Falsification in Smart Grid Advanced Metering Infrastructure

Statistical Security Incident Forensics against Data Falsification in Smart Grid Advanced Metering Infrastructure
复制标题

针对智能电网高级计量基础设施中数据伪造的统计安全事件取证

DOI:
10.1145/3029806.3029833
复制
发表时间:
2017
期刊:
Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Sajal K. Das
Sajal K. Das
中科院分区:
--
文献类型:
--
作者:
Shameek Bhattacharjee;Aditya Thakur;S. Silvestri;Sajal K. Das

文献摘要

被引文献

相似文献

在高级计量基础设施(AMI)中,被入侵的智能电表报告虚假的电力消耗数据可能会对智能电网的运行产生严重后果。大多数现有研究仅涉及客户的窃电行为。然而,当电表被有组织的对手入侵时,还可能存在其他几种类型的数据篡改攻击。在本文中,我们首先提出了AMI微电网中可能的数据篡改策略分类,例如加法、减法、伪装和冲突。然后,我们设计了一种统计异常检测技术,通过研究它们对观测数据的影响来识别所提出的攻击类型的发生情况。随后,提出了一种基于库尔贝克 - 莱布勒散度的信任模型,用于识别加法和减法攻击中被入侵的智能电表。通过基于检测到的攻击类型计算的稳健综合度量,并成功区分合法变化和恶意变化,将最终的检测率和误报率降至最低。对于冲突和伪装攻击,在信任分数上使用基于广义线性模型和威布尔函数的核技巧,以促进更准确的分类。利用从AMI收集的真实数据集,我们研究了攻击者的收益和成本之间以及虚假数据的幅度和被入侵节点的比例之间出现的几种权衡。实验结果表明,对于大多数实际的攻击策略,我们的模型具有较高的真阳性检测率,而平均误报率仅为8%,且不依赖昂贵的基于硬件的监测。
Compromised smart meters reporting false power consumption data in Advanced Metering Infrastructure (AMI) may have drastic consequences on a smart grid's operations. Most existing works only deal with electricity theft from customers. However, several other types of data falsification attacks are possible, when meters are compromised by organized rivals. In this paper, we first propose a taxonomy of possible data falsification strategies such as additive, deductive, camouflage and conflict, in AMI micro-grids. Then, we devise a statistical anomaly detection technique to identify the incidence of proposed attack types, by studying their impact on the observed data. Subsequently, a trust model based on Kullback-Leibler divergence is proposed to identify compromised smart meters for additive and deductive attacks. The resultant detection rates and false alarms are minimized through a robust aggregate measure that is calculated based on the detected attack type and successfully discriminating legitimate changes from malicious ones. For conflict and camouflage attacks, a generalized linear model and Weibull function based kernel trick is used over the trust score to facilitate more accurate classification. Using real data sets collected from AMI, we investigate several trade-offs that occur between attacker's revenue and costs, as well as the margin of false data and fraction of compromised nodes. Experimental results show that our model has a high true positive detection rate, while the average false alarm rate is just 8%, for most practical attack strategies, without depending on the expensive hardware based monitoring.