Cyber Physical Security Analytics for Anomalies in Transmission Protection Systems

Cyber Physical Security Analytics for Anomalies in Transmission Protection Systems
复制标题

DOI:
10.1109/tia.2019.2928500
复制
发表时间:
2019-11-01
影响因子:
4.4
通讯作者:
Suresh, Sindhu
Suresh, Sindhu
中科院分区:
工程技术2区
文献类型:
--
作者:
Ahmed, Arman;Krishnan, Vignesh V. G.;Suresh, Sindhu

文献摘要

被引文献

相似文献

保护系统是传输系统中最关键的组件之一,随着自动化的不断发展,保护系统变得越来越数字化。这些数字系统容易受到漏洞/攻击,利用这些漏洞可能会对电网性能造成重大影响。控制中心报告的多个警报可能是故障(预期操作)或保护系统故障(异常/意外操作)的结果。通过相量测量单元(PMU)等传感器获得的态势感知和通过网络系统获取的数据为开发系统的连续网络物理监测提供了机会。请注意,继电器数据不会连续报告到控制中心。本文提出了一种基于网络物理数据分析的技术来监控传输保护系统并检测恶意活动。最初,PMU数据的连续监控用于数据异常检测,包括使用长短期记忆(LSTM)的坏数据或丢失数据。然后,PMU数据的利益被用于故障诊断,使用半监督深度自动编码器模型。在这项研究中,通过操纵保护设备的设置/逻辑设计来模拟网络异常,并使用具有特征工程管道的基于岭回归的分类器来检测网络异常。来自深度自动编码器模型和基于岭回归的分类器的结果然后被用于详细调查,以在来自保护设备的网络日志数据的帮助下找到观察到的事件的根本原因。该算法是使用IEEE测试系统的工业硬件继电器和PMU在回路中的实时仿真进行验证。在服务器上运行的数据分析算法持续利用这些实时数据进行异常检测,并对开发的用例进行分类。
Protection systems are one of the most critical components in the transmission system and are becoming more digital with ongoing automation. These digital systems are prone to vulnerabilities/attacks, and exploitation of these vulnerabilities may cause major impacts on the electric grid performance. Multiple alarms reported in the control center could be a result of the faults (expected operations) or failures in the protection system (anomalies/unexpected operation). Situational awareness gained through sensors such as a phasor measurement unit (PMU) and data acquired through the cyber system provide an opportunity to develop continuous cyber-physical monitoring of the system. Note that relay data are not reported in the control center continuously. This paper presents a cyber-physical data analytics based technique to monitor transmission protection system and detect malicious activity. Initially, continuous monitoring of PMU data is utilized for data anomaly detection, which includes bad or missing data using long short-term memory (LSTM). Then, PMU data of interest are utilized for failure diagnosis, using a semisupervised deep autoencoder model. In this research, cyber anomalies are modeled by manipulating the setting/logic design of protective devices, and a ridge regression based classifier with a feature engineering pipeline is used to detect cyber anomalies. The results from the deep autoencoder model and ridge regression based classifier are then utilized for detailed investigation to find the root causes of the observed events assisted by the cyber log data from the protection devices. The algorithm is validated using a real-time simulation of the IEEE test system with industrial hardware relays and PMUs in the loop. Data analytics algorithm running on server utilizes these real-time data continuously for anomaly detection and classification for the developed use cases.