Detection and Forensics against Stealthy Data Falsification in Smart Metering Infrastructure

Detection and Forensics against Stealthy Data Falsification in Smart Metering Infrastructure
复制标题

智能计量基础设施中隐形数据篡改的检测和取证

DOI:
10.1109/tdsc.2018.2889729
复制
发表时间:
2019
影响因子:
7.3
通讯作者:
Das, Sajal K.
Das, Sajal K.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Bhattacharjee, Shameek;Das, Sajal K.

文献摘要

参考文献

被引文献

相似文献

从智能电网高级计量基础设施 (AMI) 中受损的智能电表注入的虚假功耗数据是一种威胁,会对客户和公用事业产生负面影响。特别是,有组织且隐秘的对手可以使用智能或持久策略从多个仪表发起各种类型的数据伪造攻击。在本文中,我们提出了一种实时的两层攻击检测方案,用于检测去中心化微网格中复杂威胁模型下精心策划的数据伪造行为。第一检测层监视每日汇总功耗数据的谐波与算术平均比是否超出称为安全裕度的正常范围。为了确认第一检测层中的差异是否确实是攻击,第二检测层会监视多天范围内建议的比率指标与安全裕度之间的残差总和(差异)。如果残差之和超出标准限制范围,则确认存在数据篡改攻击。 “安全裕度”和“标准限值”都是通过“系统识别阶段”设计的,其中使用来自两个不同国家多年的真实 AMI 微电网数据集来研究正常条件下拟议指标的签名。随后,我们展示了所提出的指标如何在各种攻击下触发独特的签名,这有助于攻击重建并限制持续攻击的影响。与 CUSUM 或 EWMA 等指标不同,所提出的指标在正常条件下的稳定性允许成功实时检测各种隐秘攻击,并具有超低的误报。
False power consumption data injected from compromised smart meters in Advanced Metering Infrastructure (AMI) of smart grids is a threat that negatively affects both customers and utilities. In particular, organized and stealthy adversaries can launch various types of data falsification attacks from multiple meters using smart or persistent strategies. In this paper, we propose a real time, two tier attack detection scheme to detect orchestrated data falsification under a sophisticated threat model in decentralized micro-grids. The first detection tier monitors whether the Harmonic to Arithmetic Mean Ratio of aggregated daily power consumption data is outside a normal range known as safe margin. To confirm whether discrepancies in the first detection tier is indeed an attack, the second detection tier monitors the sum of the residuals (difference) between the proposed ratio metric and the safe margin over a frame of multiple days. If the sum of residuals is beyond a standard limit range, the presence of a data falsification attack is confirmed. Both the `safe margins' and the `standard limits' are designed through a `system identification phase', where the signature of proposed metrics under normal conditions are studied using real AMI micro-grid data sets from two different countries over multiple years. Subsequently, we show how the proposed metrics trigger unique signatures under various attacks which aids in attack reconstruction and also limit the impact of persistent attacks. Unlike metrics such as CUSUM or EWMA, the stability of the proposed metrics under normal conditions allows successful real time detection of various stealthy attacks with ultra-low false alarms.
无线传感器网络
DOI: 10.1007/978-3-642-11917-0_10
发表时间: 2010
期刊: --
影响因子: --
作者:
Cheng L
通讯作者: Cheng L
关于算术平均数与几何平均数之差的下限和上限
DOI: --
发表时间: 1975
期刊:
影响因子: --
作者:
S. Tung
通讯作者: S. Tung
针对智能电网高级计量基础设施中数据伪造的统计安全事件取证
DOI: 10.1145/3029806.3029833
发表时间: 2017
期刊: Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy
影响因子: --
作者:
Shameek Bhattacharjee;Aditya Thakur;S. Silvestri;Sajal K. Das
通讯作者: Sajal K. Das
智能电网中聚合的价值
DOI: --
发表时间: 2013
期刊: IEEE International Conference on Smart Grid Communications
影响因子: --
作者:
R. Sevlian;R. Rajagopal
通讯作者: R. Rajagopal
DOI: --
发表时间: 2014
影响因子: 9.6
作者:
A. Cárdenas;R. Berthier;R. Bobba;J. Huh;Jorjeta G. Jetcheva;David Grochocki;W. Sanders
通讯作者: W. Sanders