MétaCan
Menu
Back to cohort
Record W4403480700 · doi:10.1016/j.ijepes.2024.110311

Real-time detection of insider attacks on substation automation systems using short length orthogonal wavelet filters and OPAL-RT

2024· article· en· W4403480700 on OpenAlexfundno aff
Matthew Oinonen, Walid G. Morsi

Bibliographic record

VenueInternational Journal of Electrical Power & Energy Systems · 2024
Typearticle
Languageen
FieldEngineering
TopicSmart Grid Security and Resilience
Canadian institutionsnot available
FundersNatural Sciences and Engineering Research Council of Canada
KeywordsWaveletInsiderAutomationWavelet transformComputer scienceReal-time computingEngineeringPattern recognition (psychology)Embedded systemArtificial intelligenceMechanical engineering

Abstract

fetched live from OpenAlex

• This paper presents a method for detecting insider attacks and disturbances in substation automation systems (SASs) using short length orthogonal filters. • The method uses a set of custom designed wavelets to provide effective and fast detection of the attacks and the disturbances. • The physical and the network features relevant to the insider attacks are identified in the time-frequency domain and deep learning is used to automate the classification. • An experimental dataset is developed using OPAL-RT that implements several types of attacks. • The results demonstrate that the use of the short-length custom-designed filters achieves a detection accuracy of 97.04% as well as a low runtime of 33.786 ms. Substation Automation Systems (SASs) integrate communication networks with physical equipment and are vulnerable to cyberattacks. A subset of these attacks, namely Insider attacks, are launched from knowledgeable insiders and therefore they are typically difficult to detect. This paper presents a new method for detecting and classifying Insider cyberattacks as well as power disturbances on SASs using short-length orthogonal wavelet filters in real-time using an OPAL-Real-Time (OPAL-RT) simulator. An Intrusion Detection System (IDS) is proposed in which custom-designed wavelet filters of short length are developed to better extract both the network and physical data of the SASs into time–frequency spectrograms. The advantage of using the short length filters is to provide fast detection of these time-sensitive Insider attacks and disturbances in real-time, which is a key requirement for mitigation to be possible. The generated spectrograms are fed to a Convolutional Neural Network (CNN) that automates the classification process. An experimental dataset is developed from real-time testing using OPAL-RT that implements several types of cyberattacks including Insider attacks and other popular attacks such as Denial-of-Service and False Data Injection as well as challenging attacks such as Replay and Message Suppression attacks. The results of experimentally testing the proposed method in real-time using OPAL-RT demonstrate that the use of the short-length custom-designed orthogonal wavelet filters achieves a detection accuracy of 97.37 % compared to other methods as well as a low runtime of 33.786 ms.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame distilled prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.

metaresearch head score (Codex)0.000
metaresearch head score (Gemma)0.000
Version: codex-gemma-dda1882f352aValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Simulation or modeling · Consensus signal: Simulation or modeling
GenreCandidate signal: Empirical · Consensus signal: Empirical
Teacher disagreement score0.400
Threshold uncertainty score0.588

Codex and Gemma teacher scores by category

CategoryCodexGemma
Metaresearch0.0000.000
Meta-epidemiology (narrow)0.0000.000
Meta-epidemiology (broad)0.0000.000
Bibliometrics0.0010.000
Science and technology studies0.0000.000
Scholarly communication0.0000.000
Open science0.0000.000
Research integrity0.0000.000
Insufficient payload (model declined to judge)0.0000.000

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.009
GPT teacher head0.242
Teacher spread0.233 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one teacher head, not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designSimulation or modeling
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations5
Published2024
Admission routes1
Has abstractyes

Explore more

Same venueInternational Journal of Electrical Power & Energy SystemsSame topicSmart Grid Security and ResilienceFrench-language works237,207