A Data-Driven Approach to Distinguish Cyber-Attacks from Physical Faults in a Smart Grid

A Data-Driven Approach to Distinguish Cyber-Attacks from Physical Faults in a Smart Grid
复制标题

区分智能电网中的网络攻击和物理故障的数据驱动方法

DOI:
--
复制
发表时间:
2015
期刊:
International Conference on Information and Knowledge Management
影响因子:
--
通讯作者:
Zubair Shah
Zubair Shah
中科院分区:
--
文献类型:
--
作者:
A. Anwar;A. Mahmood;Zubair Shah

文献摘要

被引文献

相似文献

近年来,人们对智能电网安全的兴趣显著增加。研究人员已经提出了各种技术来使用传感器数据检测网络攻击。然而,很少有工作来区分网络攻击和电力系统物理故障。如果故障被错误地归类为网络攻击,则缓解策略可能会导致物理电网中的严重运行故障,反之亦然。在本文中,我们利用数据驱动的方法来准确区分物理故障和网络攻击。首先,我们通过在IEEE 30总线基准测试系统上生成不同类型的故障和网络攻击来创建一个真实的数据集。通过大量的实验,我们观察到大多数已建立的监督方法对故障和网络攻击的分类效果不佳,特别是对于实际数据集。因此,我们提供了一个数据驱动的方法,标记的数据投影在一个新的低维子空间使用主成分分析(PCA)。接下来,使用原始数据集的新投影来训练基于顺序最小优化(SMO)的支持向量。通过模拟和实际数据集,我们观察到所提出的分类方法在考虑网络攻击和故障数据集的情况下优于其他现有的流行监督分类方法。
Recently, there has been significant increase in interest on Smart Grid security. Researchers have proposed various techniques to detect cyber-attacks using sensor data. However, there has been little work to distinguish a cyber-attack from a power system physical fault. A serious operational failure in physical power grid may occur from the mitigation strategies if fault is wrongly classified as a cyber-attack or vice-versa. In this paper, we utilize a data-driven approach to accurately differentiate the physical faults from cyber-attacks. First, we create a realistic dataset by generating different types of faults and cyber-attacks on the IEEE 30 bus benchmark test system. With extensive experiments, we observe that most of the established supervised methods perform poorly for the classification of faults and cyber-attacks specially for the practical datasets. Hence, we provide a data-driven approach where labelled data are projected in a new low-dimensional subspace using Principal Component Analysis (PCA). Next, Sequential Minimal Optimization (SMO) based Support Vectors are trained using the new projection of the original dataset. With both simulated and practical datasets, we have observed that the proposed classification method outperforms other existing popular supervised classification approaches considering the cyber-attack and fault datasets.