Source-linked AI summary

Cyber-Security in Smart Grid: Survey and Challenges

Zakaria El Mrabet, Hassan El Ghazi, Naima Kaabouch, Hamid El Ghazi

arXiv:1809.02609v1cs.CRcs.NI

TL;DR

Smart-grid cybersecurity research lacks comprehensive coverage beyond confidentiality, integrity, and availability, while existing defenses inadequately address sophisticated blended attacks. This paper surveys security requirements and attacks, proposes a multi-mechanism cybersecurity strategy, and concludes that secure protocols, encryption, and authentication can avoid most attacks.

  • Problem

    Smart grids contain heterogeneous, resource-constrained components, while existing security mechanisms have limitations against sophisticated attacks targeting multiple communication layers.

  • Method

    The paper reviews security objectives, classifies attacks by four hacker-process stages, summarizes countermeasures, and proposes a coordinated cybersecurity strategy.

  • Results

    Most summarized attacks can be avoided using secure network protocols, encryption, and authentication mechanisms.

  • Takeaways & Limitations

    Smart-grid protection should combine multiple mechanisms to address vulnerabilities, detect malicious activity, secure communications, and protect customer privacy.

Abstract

from arXiv · show

Smart grid uses the power of information technology to intelligently deliver energy to customers by using a two-way communication, and wisely meet the environmental requirements by facilitating the integration of green technologies. Although smart grid addresses several problems of the traditional grid, it faces a number of security challenges. Because communication has been incorporated into the electrical power with its inherent weaknesses, it has exposed the system to numerous risks. Several research papers have discussed these problems. However, most of them classified attacks based on confidentiality, integrity, and availability, and they excluded attacks which compromise other security criteria such as accountability. In addition, the existed security countermeasures focus on countering some specific attacks or protecting some specific components, but there is no global approach which combines these solutions to secure the entire system. The purpose of this paper is to provide a comprehensive overview of the relevant published works. First, we review the security requirements. Then, we investigate in depth a number of important cyber-attacks in smart grid to diagnose the potential vulnerabilities along with their impact. In addition, we proposed a cyber security strategy as a solution to address breaches, counter attacks, and deploy appropriate countermeasures. Finally, we provide some future research directions.

I. INTRODUCTION · II. SMART GRID OVERVIEW · A. Smart grid’s features

The paper presents smart grid cyber-security challenges arising from communication-enabled power systems and surveys security requirements, attacks, countermeasures, and future research directions. It also situates smart grid development as a response to traditional-grid shortcomings, emphasizing resilience, reliability, flexibility, and environmental performance.

  • I. INTRODUCTION: Traditional grids cannot readily integrate diverse generation sources and suffer high costs, slow demand response, carbon emissions, and blackouts.These shortcomings motivate the transition toward smart grid technologies.
  • I. INTRODUCTION: $80 billion per year in estimated interruption costs—and other estimates of $150 billion per year—illustrate the economic impact of power failures.The figures refer to the American economy.
  • I. INTRODUCTION: Smart grid promises flexibility and reliability by integrating renewable, wind, and solar resources and enabling corrective capabilities when failures occur.These capabilities address critical problems that existing electricity grids cannot resolve.
  • I. INTRODUCTION: Prior surveys classify smart-grid attacks by network type, security requirements, or threat category and describe countermeasures including cryptography, secure protocols, and architecture.Categories include HAN, NAN, WAN; people and policy, platform, and network threats; and confidentiality, integrity, and availability.
  • I. INTRODUCTION: Most classifications emphasize confidentiality, integrity, or availability, while blended attacks can compromise all security parameters and evade these systems.Examples of blended and sophisticated attacks include Stuxnet, Duqu, and Flame.
  • I. INTRODUCTION: The paper reviews smart-grid cybersecurity objectives, proposes a hacker-method-based cyber-attack classification, and summarizes recommended security measures and future expectations.The hacker-oriented method is intended to clarify how attackers compromise smart-grid security.
  • A. Smart grid’s features: Smart grid’s expected benefits include greater grid resilience and improved environmental performance.Resilience is defined as resisting unexpected events and recovering quickly afterward.

B. Smart grid’s conceptual model · C. Smart grid’s systems

The smart grid is organized into seven interacting logical domains containing actors and applications that communicate through secure channels. Its systems include distributed applications, with AMI, SCADA, and automation substations identified as critical and vulnerable.

  • B. Smart grid’s conceptual model: Seven logical domains—generation, transmission, distribution, customer, markets, service provider, and operations—contain actors and applications.Actors include programs, devices, and systems, while applications are tasks performed by one or more actors.
  • B. Smart grid’s conceptual model: Actors from different smart-grid domains interact through secure channels.The conceptual model depicts these cross-domain interactions.
  • B. Smart grid’s conceptual model: Customer-domain users may consume, generate, store, and manage energy across home, commercial/building, and industrial settings.The customer domain communicates with distribution, operations, service provider, and market domains.
  • B. Smart grid’s conceptual model: The market domain balances electricity supply and demand by communicating with bulk-generation and distributed-energy-resource domains.The bulk-generation domain also interfaces with the market, transmission, and operations domains.
  • B. Smart grid’s conceptual model: Transmission carries generated power over long distances to distribution through multiple substations and is monitored and controlled by SCADA.SCADA includes a communication network, control devices, and monitoring devices.
  • C. Smart grid’s systems: Smart-grid systems are distributed and heterogeneous, including AMI, substation automation, demand response, SCADA, electric vehicles, and home energy management.The paper focuses on AMI, SCADA, and automation substations as three critical and vulnerable applications.
  • C. Smart grid’s systems: AMI collects, measures, and analyzes energy, water, and gas usage through two-way user-to-utility communication.Its three components are the smart meter, AMI headend, and communication network.
  • C. Smart grid’s systems: SCADA measures, monitors, and controls electrical grids in large-scale environments using RTUs, MTUs, and HMIs, while substations regulate distribution and limit power surges.Substations contain RTUs, GPS, HMIs, and IEDs and send operational data to SCADA.

D. Smart grid’s network protocols · III. SECURITY REQUIREMENTS OF SMART GRID · A. Confidentiality

Smart-grid communications use heterogeneous protocols across home, neighborhood, and critical-infrastructure networks, while security requirements include confidentiality, integrity, availability, and accountability. Confidentiality protects personal privacy and proprietary information from unauthorized access or disclosure.

  • D. Smart grid’s network protocols: Smart-grid applications use different communication protocols across heterogeneous networks, including ZigBee and Z-Wave in HAN and IEEE 802.11, IEEE 802.15.4, or IEEE 802.16 in NAN.The paper presents these protocols within the smart-grid network architecture.
  • D. Smart grid’s network protocols: Modbus is a seven-layer OSI protocol with ASCII, RTU, and TCP variants for controller communication.Modbus ASCII uses hexadecimal messages, Modbus RTU uses binary messages over RS232, and Modbus/TCP connects masters and slaves.
  • D. Smart grid’s network protocols: DNP3 is widely used in electricity infrastructure to connect master stations such as RTUs with outstations such as IEDs.It began in 1990 as a serial protocol for master–outstation communication and was extended in 1998.
  • III. SECURITY REQUIREMENTS OF SMART GRID: NIST identifies confidentiality, integrity, and availability as smart-grid information-security criteria, while accountability is also recognized as important.The paper introduces these criteria as requirements for maintaining protected smart-grid information.
  • A. Confidentiality: Confidentiality protects personal privacy and proprietary information from unauthorized access or disclosure by entities, individuals, or processes.Any unauthorized disclosure causes confidentiality to be lost.
  • A. Confidentiality: Confidentiality applies to information such as meter control, metering usage, and billing information sent between smart-grid components.The passage identifies these data as examples requiring protection from unauthorized disclosure.

C. Integrity

Integrity in a smart grid protects information from improper modification or destruction, including undetected unauthorized alterations. Power injection exemplifies this threat, as adversaries intelligently modify measurements relayed to the state estimator.

  • C. Integrity: Integrity protects smart-grid information against improper modification or destruction.A loss of integrity involves unauthorized alteration, modification, or destruction of information.
  • C. Integrity: Power injection attacks intelligently modify meter and power-flow measurements before relaying them to the state estimator.The adversary alters measurements and transmits the modified data from power injection meters and power flow.
  • C. Integrity: Both nonrepudiation and authenticity of information are required to maintain integrity.

D. Accountability

Accountability requires that actions by people, devices, and authorities be traceable and recordable, while meter tampering can undermine the reliability of billing information.

  • D. Accountability: Accountability makes actions by people, devices, and public authorities recordable and traceable, preventing denial and supporting evidence in court to identify attackers.Such records establish tractability of the system and can be used as legal evidence.
  • D. Accountability: Altered smart-meter data can produce conflicting electricity bills, with different amounts reported by the meter and the utility.This discrepancy arises because attacked meters no longer provide reliable billing information.

IV. SECURITY PROBLEMS AND COUNTERMEASURES IN SMART GRID · A. Smart grid attacks

Smart-grid attackers follow a four-step cycle—reconnaissance, scanning, exploitation, and maintaining access—using varied techniques that compromise different security criteria. The paper classifies attacks by this cycle and security impact, highlighting vulnerabilities in industrial protocols, communication networks, devices, and data.

  • A. Smart grid attacks: Attackers use reconnaissance, scanning, exploitation, and maintain access to gain control over smart-grid systems.Reconnaissance gathers target information, while scanning identifies vulnerabilities, open ports, and running services.
  • A. Smart grid attacks: Smart-grid attacks are classified by the attacking-cycle step in which attackers use different techniques to compromise security criteria.Numerous attack types can occur during exploitation.
  • A. Smart grid attacks: Modbus/TCP and DNP3 are vulnerable to scanning attacks that discover connected devices, open ports, slave IDs, and IP addresses.Modbus network scanning sends benign messages to connected devices to gather information; Modscan detects open Modbus/TCP devices.
  • A. Smart grid attacks: Stuxnet exploited undisclosed software vulnerabilities and infected at least 14 industrial sites in Iran, including a uranium-enrichment plant.Duqu and Flame subsequently targeted industrial control systems, with Duqu designed to gather and steal information.
  • A. Smart grid attacks: Puppet attacks targeting AMI networks by exploiting DSR can exhaust bandwidth and reduce packet delivery between 10% and 20%.Other denial-of-service methods include SYN, buffer overflow, teardrop, smurf, TDS, and TSA attacks.
  • A. Smart grid attacks: MITM, replay, jamming, and device-exploitation attacks can intercept or alter traffic, inject false measurements, block communication, or enable unauthorized control.Replay attacks exploit plaintext industrial-control traffic, while jamming keeps wireless channels busy and degrades time-critical grid performance.
  • A. Smart grid attacks: Integrity, privacy, and masquerade attacks can alter meter or RTU data, expose customer occupancy patterns, or enable unauthorized actions through impersonation.These attacks can affect confidentiality, integrity, accountability, and availability depending on the attacker’s objective.
  • A. Smart grid attacks: Smart-grid security criteria rank availability, integrity, accountability, and confidentiality, making availability-compromising attacks more severe than confidentiality attacks.Attack likelihood also contributes to assessing overall risk.

B. Smart grid countermeasures

The paper proposes a three-phase cyber-security strategy for smart grids: pre-attack preparation, under-attack detection and mitigation, and post-attack response. Countermeasures combine network security, cryptography, authentication and key management, device protection, and attack-specific techniques.

  • Cyber security strategy: The proposed strategy comprises pre-attack, under-attack, and post-attack phases, with published solutions mapped to each phase.The under-attack phase includes attack detection and mitigation tasks.
  • Network security: Secure network protocols, including IPsec, TLS, SSL, and secure DNP3, strengthen network security against interception and attacks.Secure DNP3 adds encryption and authentication; authentication can protect against MITM attacks, while encryption reduces eavesdropping and replay attacks.
  • Cryptography and authentication: Cryptography protects confidentiality, integrity, and nonrepudiation through symmetric or asymmetric encryption, while authentication verifies identities across smart-grid components.Multicast authentication methods include secret-info asymmetry, time asymmetry, and hybrid asymmetry.
  • Cryptography and authentication: Key management supports secure communication through PKI or shared secret keys and should provide efficiency, evolve-ability, scalability, and secure management.Shared-secret key management includes key generation, distribution, storage, and update.
  • Device security: Device security uses host IDS, anti-virus, host DLP, compliance checks, and firmware diversity to limit endpoint and large-scale attacks.Firmware diversity prevents exploitation of the same firmware vulnerability across different devices.
  • Under attack: Attack mitigation includes pushback and network reconfiguration for denial-of-service attacks, anti-jamming schemes, and classifier combinations for malicious-traffic detection.Pushback blocks traffic from an attacker’s IP address, while reconfiguration changes network topology to isolate the attacker; SVM and AIS produced satisfactory malicious-traffic detection.

V. CHALLENGES AND FUTURE DIRECTION

The section identifies system heterogeneity and protocol translation as smart-grid security challenges that can create vulnerabilities. It also lists attack examples and associated countermeasures, including protections for protocols, authentication, encryption, monitoring, and intrusion detection.

  • Challenges: Heterogeneous devices and network protocols require data aggregation and protocol translation, which can introduce accidental breaches when features are translated improperly.This heterogeneity is described as both a security challenge and a potential threat.
  • Challenges: Attack examples include phishing, password pilfering, scanning of Modbus and DNP3 protocols, compromised applications or protocols, and man-in-the-middle attacks.The supplied attack table fragments associate phishing with password pilfering and identify Modbus, DNP3, compromised applications or protocols, and MITM.
  • Future Direction: Listed protections include securing DNP3, PKI mechanisms such as SKMA and SMOCK, TLS, SSL, encryption, and authentication.These measures appear in the supplied countermeasure fragments.
  • Future Direction: Monitoring and response mechanisms include DLP, IDS, SIEM, flow entropy, signal strength, sensing-time measurement, transmission-failure counts, pushback, and reconfiguration.The passages list these as security or response techniques.

(FHSS, DSSS) [38]

The section lists security measures and technologies associated with smart-grid cybersecurity, including DLP, IDS, SIEM, anti-virus, automated security compliance, TLS, SSL, encryption, and authentication.

  • The listed measures include DLP, IDS, SIEM, and anti-virus.
  • Automated security compliance is also identified as a cybersecurity measure.
  • Additional technologies include SIEM, TLS, SSL, encryption, and authentication.

[1], PKI (SKMA,

Smart-grid security is constrained by insecure or incompatible legacy protocols, vulnerable operating systems and devices, and conventional defenses that do not suit distributed, evolving environments. The paper therefore advocates a cyber-security strategy combining mechanisms to address vulnerabilities, detect attacks, deploy countermeasures, and identify involved entities.

  • Protocol vulnerabilities: Most industrial smart-grid protocols prioritize connectivity over security, creating attack surfaces and preventing secure communication; secure versions such as DNP3 remain incompatible with legacy installations.Examples include DNP3, ICCP, Modbus, and Profibus; secure DNP3 does not resolve compatibility problems with legacy deployments.
  • System and device limitations: Vulnerable operating systems and constrained or obsolete physical equipment cannot reliably support advanced security mechanisms.Operating systems lack security features, while many devices have insufficient memory or limited computational capacity.
  • Countermeasure limitations: IDS, firewalls, and encryption have limitations in distributed smart grids with diverse latency and bandwidth requirements and cannot counter emerging blended attacks.The cited defenses were developed for conventional networks, whereas smart-grid attacks are increasingly blended, sophisticated, and complex.
  • Cyber-security strategy: A cyber-security strategy can combine several mechanisms to address vulnerabilities, detect attacks, deploy appropriate countermeasures, and identify involved entities.The paper argues that this combined approach is more effective than applying a simple security approach or deploying a specific technology.

VI. CONCLUSION

The paper surveys smart-grid cybersecurity, examining major attacks against infrastructure, network protocols, and applications. It also proposes a cybersecurity strategy to address the system’s security weaknesses.

  • Conclusion: Smart grid integrates distributed, heterogeneous components to deliver electricity intelligently and support renewable technologies.The system nevertheless suffers from security weaknesses.
  • Conclusion: The paper provides a comprehensive overview of smart-grid cybersecurity and investigates major cyber-attacks threatening its infrastructure, network protocols, and applications.
  • Conclusion: The paper proposes a cybersecurity strategy for addressing smart-grid security weaknesses.
Loading 1809.02609v1…