CPIndex: Cyber-Physical Vulnerability Assessment for Power-Grid Infrastructures
Title | CPIndex: Cyber-Physical Vulnerability Assessment for Power-Grid Infrastructures |
Publication Type | Journal Article |
Year of Publication | 2015 |
Authors | Vellaithurai, C., Srivastava, A., Zonouz, S., Berthier, R. |
Journal | Smart Grid, IEEE Transactions on |
Volume | 6 |
Pagination | 566-575 |
Date Published | March |
ISSN | 1949-3053 |
Keywords | Bayes methods, CPIndex, cyber-physical critical infrastructures, cyber-physical security indices, Cyber-physical security metrics, Cyber-physical systems, cyber-physical vulnerability assessment, cyber-side instrumentation probes, Generators, graph theory, graph-theoretic power system indexing algorithm, Indexes, interprocess communications, Intrusion Detection Systems, numerical indices, operating system assets, power engineering computing, power grids, Power measurement, power network configuration, power operators, power system control, power system security, power-grid control networks, power-grid Infrastructures, risk management, security, security assessment techniques, security-oriented stochastic risk management technique, situational awareness, Smart grids, stochastic Bayesian network models, Stochastic processes |
Abstract | To protect complex power-grid control networks, power operators need efficient security assessment techniques that take into account both cyber side and the power side of the cyber-physical critical infrastructures. In this paper, we present CPINDEX, a security-oriented stochastic risk management technique that calculates cyber-physical security indices to measure the security level of the underlying cyber-physical setting. CPINDEX installs appropriate cyber-side instrumentation probes on individual host systems to dynamically capture and profile low-level system activities such as interprocess communications among operating system assets. CPINDEX uses the generated logs along with the topological information about the power network configuration to build stochastic Bayesian network models of the whole cyber-physical infrastructure and update them dynamically based on the current state of the underlying power system. Finally, CPINDEX implements belief propagation algorithms on the created stochastic models combined with a novel graph-theoretic power system indexing algorithm to calculate the cyber-physical index, i.e., to measure the security-level of the system's current cyber-physical state. The results of our experiments with actual attacks against a real-world power control network shows that CPINDEX, within few seconds, can efficiently compute the numerical indices during the attack that indicate the progressing malicious attack correctly. |
URL | http://ieeexplore.ieee.org/document/6979242/ |
DOI | 10.1109/TSG.2014.2372315 |
Citation Key | 6979242 |
- risk management
- power grids
- Power measurement
- power network configuration
- power operators
- power system control
- power system security
- power-grid control networks
- power-grid Infrastructures
- power engineering computing
- security
- security assessment techniques
- security-oriented stochastic risk management technique
- situational awareness
- Smart Grids
- stochastic Bayesian network models
- Stochastic processes
- Bayes methods
- operating system assets
- numerical indices
- Intrusion Detection Systems
- interprocess communications
- Indexes
- graph-theoretic power system indexing algorithm
- graph theory
- Generators
- cyber-side instrumentation probes
- cyber-physical vulnerability assessment
- cyber-physical systems
- Cyber-physical security metrics
- cyber-physical security indices
- cyber-physical critical infrastructures
- CPIndex