AI 中文总结
本文提出基于HMM的SubCASP方法,融合IDS数据推断变电站网络攻击阶段,经攻击图数据集验证,可在不同IDS场景下实现攻击阶段的鲁棒推断。
AI 中文摘要
符合IEC 61850标准的数字化变电站提升了现代电力系统的运行效率,但攻击者可滥用IEC 61850通信操纵变电站的断路器操作,造成严重的系统影响。这类网络攻击基于更广泛的多阶段策略设计,现有入侵检测系统(IDS)通常仅标记孤立症状,缺乏攻击阶段的上下文信息以支持缓解措施的部署。本文提出Substation Cyber Attack Strategy Phasing(SubCASP),一种基于隐马尔可夫模型(HMM)的方法,融合IDS数据日志以推断当前攻击阶段、下一攻击阶段及回溯攻击路径。攻击阶段基于ATT&CK威胁建模推导,SubCASP模型在可复现的攻击图数据集上进行训练与评估,测试结果表明,SubCASP在不同IDS可观测性水平及IDS数据日志缺失场景下均具有鲁棒性。
英文摘要
Digital substations that comply with IEC 61850 have improved the operational efficiency of modern power systems. However, adversaries can abuse IEC 61850 communication to manipulate circuit breaker operations in substations, which can result in severe system impacts. These cyber attacks are crafted based on broader multi-phase strategies. The existing intrusion detection systems (IDSs) often flag only isolated symptoms. Thus, there is a lack of context in the attack phase to support the deployment of mitigation measures. This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path. The attack phases are derived from an ATT&CK-based threat modeling. The SubCASP model is trained and evaluated on a reproducible attack-graph dataset. Test results are presented to demonstrate the robustness of SubCASP for various IDS observability levels and missing IDS data logs scenarios.
Comments2026 IEEE Power and Energy Society General Meeting (PESGM)