Securing the Smart Grid: A Comprehensive Compilation of Intrusion Detection and Prevention Systems

Защита интеллектуальной электросети: всесторонняя компиляция систем обнаружения и предотвращения вторжений
Panagiotis Sarigiannidis, Panagiotis Radoglou‐Grammatikis
2019-01-01

advanced metering infrastructure (AMI)intrusion detection and prevention system (IDPS)smart grid (SG)supervisory control and data acquisition (SCADA)synchrophasors
The smart grid (SG) paradigm is the next technological leap of the conventional electrical grid, contributing to the protection of the physical environment and providing multiple advantages such as increased reliability, better service quality, and the efficient utilization of the existing infrastructure and the renewable energy resources. However, despite the fact that it brings beneficial environmental, economic, and social changes, the existence of such a system possesses important security and privacy challenges, since it includes a combination of heterogeneous, co-existing smart, and legacy technologies. Based on the rapid evolution of the cyber-physical systems (CPS), both academia and industry have developed appropriate measures for enhancing the security surface of the SG paradigm using, for example, integrating efficient, lightweight encryption and authorization mechanisms. Nevertheless, these mechanisms may not prevent various security threats, such as denial of service (DoS) attacks that target on the availability of the underlying systems. An efficient countermeasure against several cyberattacks is the intrusion detection and prevention system (IDPS). In this paper, we examine the contribution of the IDPSs in the SG paradigm, providing an analysis of 37 cases. More detailed, these systems can be considered as a secondary defense mechanism, which enhances the cryptographic processes, by timely detecting or/and preventing potential security violations. For instance, if a cyberattack bypasses the essential encryption and authorization mechanisms, then the IDPS systems can act as a secondary protection service, informing the system operator for the presence of the specific attack or enabling appropriate preventive countermeasures. The cases we study focused on the advanced metering infrastructure (AMI), supervisory control and data acquisition (SCADA) systems, substations, and synchrophasors. Based on our comparative analysis, the limitations and the shortcomings of the current IDPS systems are identified, whereas appropriate recommendations are provided for future research efforts.
1
Comparative analysis identifies limitations and shortcomings of current smart grid IDPS and provides recommendations for future research directions.
2
IDPS provide timely detection and/or prevention of attacks such as denial of service that threaten availability, complementing lightweight encryption and authorization mechanisms.
3
Intrusion detection and prevention systems (IDPS) act as a secondary defense in smart grids, enhancing cryptographic measures by detecting or preventing security violations when primary defenses fail.
4
The survey analyzes 37 IDPS cases applied to smart grid components including AMI, SCADA, substations, and synchrophasors.

Intrusion detection and prevention systems (IDPS) applied within the smart grid infrastructure (including AMI, SCADA, substations, and synchrophasors)

The effectiveness, role, limitations, and comparative performance of IDPS as secondary defenses enhancing cryptographic measures to detect and prevent cyberattacks (e.g., DoS) in smart grid components

Publication Details
Publication Date
2019-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Panagiotis Sarigiannidis
Panagiotis Radoglou‐Grammatikis
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%