MétaCan
Menu
Back to cohort
Record W4396877687 · doi:10.1109/tim.2024.3400328

Measuring and Improving the Security Posture of IEC 61850 Substations Against Supply Chain Attacks

2024· article· en· W4396877687 on OpenAlexafffund
Onur Duman, Azadeh Tabiban, Lingyu Wang, Mourad Debbabi

Bibliographic record

VenueIEEE Transactions on Instrumentation and Measurement · 2024
Typearticle
Languageen
FieldEngineering
TopicSmart Grid Security and Resilience
Canadian institutionsUniversity of ManitobaConcordia University
FundersNatural Sciences and Engineering Research Council of Canada
KeywordsIEC 61850Supply chainComputer securityComputer scienceReliability engineeringChain (unit)Embedded systemSystems engineeringEngineeringElectrical engineeringBusinessAutomationMechanical engineering

Abstract

fetched live from OpenAlex

The measurement of security is essential for defending critical infrastructures like smart grid substations against emerging threats of supply chain attacks. However, security measurement in general is still in its infancy and especially lacks tool support. In particular, supply chain attacks exploit vulnerabilities injected into devices before their shipment or during firmware updates, and represent a significant security threat to substations. Preventing such attacks through the naïve solution of purchasing devices only from trusted vendors may not always be feasible (e.g., due to operational constraints of an operator being bound to particular vendors). Furthermore, in many cases, the effectiveness of applying ad-hoc hardening options can be limited, while it may not be feasible to deploy all possible security mechanisms due to budget constraints. Finally, manually assessing and applying different hardening options while respecting a given budget is usually very challenging for system operators and can be prone to human error. In this paper, we develop a hardening system, namely Hardening Framework for Substations (HFS), to measure and optimally improve the security posture of substations against supply chain attacks. First, HFS provides a hardening mechanism for securing substations while considering the budget and operational constraints. Second, HFS provides a visual framework that allows operators to generate attack graphs and manually experiment with various hardening options. We validate the effectiveness of HFS based on several scenarios including the case in which supply chain attacks are mitigated by fixing non-supply chain vulnerabilities. Our simulation results demonstrate that HFS improves the security postures of substations against supply chain attacks even with limited supply chain-related hardening options by reducing the number of successful supply chain attackers. Finally, we discuss how our work may be improved through leveraging existing concepts and techniques from instrumentation and measurement.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame distilled prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.

metaresearch head score (Codex)0.000
metaresearch head score (Gemma)0.000
Version: codex-gemma-dda1882f352aValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Bench or experimental · Consensus signal: Bench or experimental
GenreCandidate signal: Empirical · Consensus signal: Empirical
Teacher disagreement score0.440
Threshold uncertainty score0.459

Codex and Gemma teacher scores by category

CategoryCodexGemma
Metaresearch0.0000.000
Meta-epidemiology (narrow)0.0000.000
Meta-epidemiology (broad)0.0000.000
Bibliometrics0.0000.000
Science and technology studies0.0000.000
Scholarly communication0.0000.000
Open science0.0000.000
Research integrity0.0000.000
Insufficient payload (model declined to judge)0.0000.000

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.020
GPT teacher head0.214
Teacher spread0.194 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one teacher head, not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designBench or experimental
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations7
Published2024
Admission routes2
Has abstractyes

Explore more

Same venueIEEE Transactions on Instrumentation and MeasurementSame topicSmart Grid Security and ResilienceFrench-language works237,207