Real-time detection of insider attacks on substation automation systems using short length orthogonal wavelet filters and OPAL-RT
Notice bibliographique
Résumé
• This paper presents a method for detecting insider attacks and disturbances in substation automation systems (SASs) using short length orthogonal filters. • The method uses a set of custom designed wavelets to provide effective and fast detection of the attacks and the disturbances. • The physical and the network features relevant to the insider attacks are identified in the time-frequency domain and deep learning is used to automate the classification. • An experimental dataset is developed using OPAL-RT that implements several types of attacks. • The results demonstrate that the use of the short-length custom-designed filters achieves a detection accuracy of 97.04% as well as a low runtime of 33.786 ms. Substation Automation Systems (SASs) integrate communication networks with physical equipment and are vulnerable to cyberattacks. A subset of these attacks, namely Insider attacks, are launched from knowledgeable insiders and therefore they are typically difficult to detect. This paper presents a new method for detecting and classifying Insider cyberattacks as well as power disturbances on SASs using short-length orthogonal wavelet filters in real-time using an OPAL-Real-Time (OPAL-RT) simulator. An Intrusion Detection System (IDS) is proposed in which custom-designed wavelet filters of short length are developed to better extract both the network and physical data of the SASs into time–frequency spectrograms. The advantage of using the short length filters is to provide fast detection of these time-sensitive Insider attacks and disturbances in real-time, which is a key requirement for mitigation to be possible. The generated spectrograms are fed to a Convolutional Neural Network (CNN) that automates the classification process. An experimental dataset is developed from real-time testing using OPAL-RT that implements several types of cyberattacks including Insider attacks and other popular attacks such as Denial-of-Service and False Data Injection as well as challenging attacks such as Replay and Message Suppression attacks. The results of experimentally testing the proposed method in real-time using OPAL-RT demonstrate that the use of the short-length custom-designed orthogonal wavelet filters achieves a detection accuracy of 97.37 % compared to other methods as well as a low runtime of 33.786 ms.
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction distillée sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Apprise à partir de 10 348 étiquettes directes de Codex et de 10 348 étiquettes directes de Gemma. Le mode candidate est l'union des têtes enseignantes seuillées; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont ni des étiquettes humaines ni des étiquettes directes de modèles de pointe.
Scores Codex et Gemma par catégorie
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,000 | 0,000 |
| Méta-épidémiologie (sens strict) | 0,000 | 0,000 |
| Méta-épidémiologie (sens large) | 0,000 | 0,000 |
| Bibliométrie | 0,001 | 0,000 |
| Études des sciences et des technologies | 0,000 | 0,000 |
| Communication savante | 0,000 | 0,000 |
| Science ouverte | 0,000 | 0,000 |
| Intégrité de la recherche | 0,000 | 0,000 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,000 | 0,000 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule tête enseignante, pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».