Locational Marginal Prices (LMPs) are central to electricity-market operations but are vulnerable to false data injection attacks (FDIAs) that can mislead dispatch decisions and distort prices. Although recent cybersecurity research has mainly focused on modelling profit-motivated attacks and analysing their financial impact, far less attention has been paid to developing robust, data-driven defence models. A key barrier is the lack of realistic, open datasets that capture stealthy attack behavior grounded in power system physics. To address this gap, we develop the Stealthy Manipulated LMP Timeseries (SMLT) dataset framework; an open-source benchmark for studying FDIAs on electricity markets. SMLT models eight different attack cases including attacks on topology, demand profiles, system parameters, and transmission limits. SMLT provides 20 weeks of hourly LMP timeseries with ground-truth labels, enabling detailed spatio-temporal analysis and facilitating the development of detection algorithms. We present statistical insights into manipulated LMP behaviors and demonstrate the dataset’s utility through a case study using a statistical anomaly detection method. SMLT aims to support reproducible, physics-aware research on securing electricity markets against evolving cyber threats.
Locational Marginal Prices (LMPs) are critical indicators in modern energy markets, representing the cost of delivering electricity at specific locations while considering the generation and transmission constraints. LMPs facilitate the transition to dynamic energy markets by providing real-time pricing signals that reflect supply and demand conditions, thereby incentivizing efficient resource allocation and encouraging investments in renewable energy sources. However, determining LMPs requires the processing of vast amounts of data, including real-time electricity demand, generation capacities, transmission line statuses, and market bids. Owing to vulnerabilities in the underlying sensors and communication infrastructure, adversaries can launch profit-driven stealthy False Data Injection Attacks (FDIAs) to manipulate LMPs. Such manipulations can have severe consequences, including inflated electricity prices, reduced market efficiency, distorted competition, and hindered integration of renewable energy sources. Although several studies have examined the operational consequences of FDIAs, their financial impact on energy market outcomes remains insufficiently explored. This work presents a comprehensive review of FDIAs aimed at manipulating LMPs, a key pricing mechanism in modern energy markets. A detailed analysis was conducted to identify vulnerabilities arising from both the energy system infrastructure and market operations. In addition, existing energy market threat models and defense mechanisms are systematically reviewed. Finally, key research gaps are identified, and future research directions are outlined to enhance the resilience of energy markets against FDIA threats.
The evolution of traditional electric markets into Smart Grids has ushered in a competitive environment driven by Locational Marginal Prices (LMPs), enabling market participants to bid and offer energy dynamically. However, this paradigm has been proven to be vulnerable to financially motivated False Data Injection Attacks (FDIAs). In these attacks, malicious actors manipulate the underlying measurement data to falsify market outcomes. Detecting anomalies in LMPs is challenging due to non-stationary characteristics stemming from operational system dynamics invoking inherent uncertainties. In addition, attack strategies are designed to mimic legitimate prices while achieving long-term financial gains. Recent studies have shown promising results in the detection of anomalies by analyzing error patterns generated by machine learning models. Likewise, in this work, we design an unsupervised Locational Marginal Pricing (LMP) manipulation detection model by statistically analyzing prediction error patterns from a Long Short-Term Memory (LSTM) model. Furthermore, we apply change point detection principles to detect changes in the prediction error pattern. Comprehensive experimental analysis and comparative assessments over real datasets highlight the efficiency of our proposed method in achieving a high attack detection rate whilst generating a low false alarm rate.
The energy market has undergone significant evolution, driven by modern energy systems. Nonetheless, the underlying infrastructure remains vulnerable to stealthy attack vectors and exploits, particularly False Data Injection Attacks (FDIAs). Profit-oriented FDIAs strategically manipulate Locational Marginal Prices (LMPs) to achieve long-term financial gains. The stealthy nature of such manipulations makes them difficult to distinguish from normal price fluctuations, posing severe threats to market stability. In parallel, the dynamic nature of energy markets shaped by seasonal variations, demand shifts, and generation changes adds complexity to the detection of these attacks. Given the aforementioned constraints, we introduce a novel market-level unsupervised model designed to detect stealthy LMP manipulations. We thus leverage non-parametric change-point detection principles to identify anomalous pricing behaviors without prior knowledge of attack patterns. In order to enhance robustness and higher confidence on our anomaly diagnosis, we propose a drift adaptive mechanism by adapting to evolving data distributions. Our extensive experiments on synthetic and real-world LMP datasets, showcase the effectiveness of our approach in reducing false alarm rates compared to state-of-the-art methods. Hence, we justify through our experimental outcomes the potential of adaptive unsupervised models in safeguarding modern energy markets against sophisticated and financially motivated cyber threat vectors.
Post-quantum cryptography (PQC) is expected to revolutionize secure communications in next-generation digital ecosystems. Previous and ongoing activities demonstrate that different PQC algorithms significantly impact traffic latency, but they do not yet provide a scheme to assess the existence of the PQC algorithm or its identification when encrypted traffic is analyzed for traffic engineering purposes. Hence, this work is the first to propose a novel PQClass pipeline for classifying encrypted Internet traffic of recently NIST-approved PQC algorithms. Hence, it establishes solid grounds for enabling engineers to optimize their networks and, in parallel, for cybersecurity practitioners to familiarise themselves with PQC algorithmic properties for enhancing or devising security architectures in diverse setups. Our pipeline demonstrates impressive performance on real-world data, achieving 86% accuracy in detecting the presence of a PQC algorithm and 91% and 98% accuracy in identifying the browser and OS, respectively, based on PQC-based traffic.
Due to the ever increasing inter-dependency across a variety of diverse software and hardware components in Information and Communications Technology (ICT) provisioning, Supply Chain Vulnerabilities (SCVs) targeting such dependencies have evolved as a primary choice for malicious actors to stealthy and complex cyber-attacks. The current modus operandi in the cyber threat spectrum is solely correlated with Advanced Persistent Threats (APTs) that have shown to be prevalent across diversified attacks underpinning cyberwarfare, and cybercrime. Hence, defense against such threats is undoubtedly considered as a high priority on a global scale. Nonetheless, the reliance on third-party supply chain software and device across diverse ICT ecosystems, combined with the current defense mechanisms’ inability to identify specific compromised entry points, results in an increased risk of APTs. This survey explores the state-of-the-art to stratify and showcase the properties of supply chain-based APTs, elaborate on reported risks from such APTs, and expand on existing defense methods. This study connects academic research with industry practices to highlight a new and growing problem. It examines supply chain compromises, offers unique insight into how these exploitations occur, and equips cybersecurity practitioners with the knowledge required to design next-generation APT defense mechanisms.
Industrial Control Systems (ICS) having their physical processes dictated commonly by Programmable Logic Controllers (PLCs) underpin Critical Infrastructure Systems (CIS) that constitute the basis for a number of vital sectors of our society such as energy, utilities, manufacturing, defense and healthcare. ICS were traditionally isolated but in the last two decades are strongly defined by the convergence of Internet-enabled Information Technologies (IT) with Operational Technologies (OT) adhering to the vision of Industry 4.0 and more recently Industry 5.0. Evidently, this convergence triggers a new vulnerability spectrum that naturally exposes CIS to stealthy attack vectors as parts of Advanced Persistent Threats (APTs) acting as foundations for a variety of modern cybercrime or cyberwarfare operations. Hence, highlighting the weakness of existing defense mechanisms and the need to develop sophisticated detection systems to ensure higher security assurance. In this paper we propose a novel PLCcentric and Machine Learning (ML)-driven anomaly detection framework for detecting stealthy attack vectors in ICS. The introduced framework incorporates network packet payload analysis leveraging information-theoretic metrics to profile PLC communication behaviour and further employs a two-class Support Vector Machine (SVM) model to distinguish normal from abnormal network behaviour. Moreover, a one-class SVM (OCSVM) is utilised to address data imbalance and compared with the two-class SVM implementation. We evaluate our framework over simulated data replicating real-world Modbus/TCP communication of a PLC with a physical process, encompassing both normal operational behavior and stealthy attack vector scenarios adhering to industry cybersecurity practices. The conducted evaluation reveals that while the two-class SVM outperforms the OCSVM formulation in terms of overall accuracy, the OCSVM remains a viable option when labeled anomaly data are unavailable.
Programmable Logic Controllers (PLCs) constitute the basis of Industrial Control Systems (ICSs) underpinning sectors ranging from nuclear, up to energy and manufacturing. Currently, PLC vulnerability assessment practices employed by ICS operators are limited due to their reliance on empirical observations of visible code crashes prompted by PLC compilers. In parallel, the prevalent PLC firmware dependency on proprietary vendor routines restricts the composition of generic vulnerability detection or discovery schemes for zero-day threat vectors. In this work, we propose Sizzler: a novel vendor-independent vulnerability discovery framework specific to PLC applications operating with logic realised through ladder diagrams. Sizzler extends the current state of the art by proposing the optimal synergy of a mutation-based fuzzing strategy using Sequential Generative Adversarial Network (SeqGAN). By virtue of critical vendor restrictions on emulating PLC firmware, we also refine the Quick Emulator (QEMU)’s General Purpose I/O (GPIO) and the Inter-Integrated Circuit (I2C) protocols to evaluate and compare Sizzler across 30 PLC ladder diagram programs compiled from LDmicro and OpenPLC projects over five widely used Micro-Controller Units (MCUs). It is noteworthy that Sizzler has successfully identified vulnerabilities in ladder diagrams within a relatively short time frame based on our proprietary dataset and secured a CVE-ID. Moreover, through a comparison of Sizzler with prevalent fuzzing techniques over the commonly used Magma and LAVA-M datasets we exhibit its wider applicability on embedded systems and identify its limitations.
Energy theft is an extremely prominent challenge causing significant energy and revenue losses for utility providers worldwide. The introduction of advanced metering infrastructures consisting of smart meter deployments has undeniably extended the attack surface, enabling individual consumers or prosumers to trigger composite energy theft attack vectors. In this work, we introduce an energy theft detection system capable of distinguishing properties of power consumption and generation theft with possible misconfigurations caused by nonmalicious intent. The proposed approach is adaptive through a self-learning operation that is updated continuously as new measurements become available. With the synergistic use of measurements collected by real PV installations and openly available weather information, the system achieves high accuracy and precision result in theft identification over streamed data measurements. Thus, it promotes low computational costs and its architecture can be easily integrated within smart grid infrastructures to realize next-generation cross-batch energy theft detection.
The ubiquitous integration of the IoT in current sociotechnical systems alongside the manufacturing of IoT devices and IoT-enabled services equipped with minimal security, has profoundly altered the cyber-threat landscape. Consequently, the overwhelming majority of cyberattacks utilise compromised IoT devices as a vessel for initiating large scale volumetric (e.g., DDoS) or stealthy Advanced Persistent Threats (APTs) such as ransomware through well orchestrated IoT botnets. Due to the constantly evolving nature of these botnets and their diverse structural characteristics, tracking their activities poses considerable challenges since malicious actors and botnet owners often adopt new strategies to evade detection and expand their botnet network. Evidently, Autonomous Systems (ASes) and their implied organisational and regulatory properties play a crucial role in botnet propagation. In this paper, we present a novel and extensive macroscopic measurement study quantifying AS-level tolerance in the context of IoT botnet behavioral dynamics across the global IPv4 address space. In order to verify and justify our hypotheses in terms of AS-level tolerance we conduct a longitudinal analysis over 3.8M malicious events triggered by IoT botnets across over 8K ASes using measurements gathered through globally distributed honeypots, IP blacklists and Internet regional registries for a three year period. We argue that the findings in the herein work can greatly benefit a range of stakeholders designing, operating, and managing current defense mechanisms as well as contributing significantly towards the evolution of next generation cyber defense mechanisms.
Programmable Logic Controllers (PLCs) constitute the functioning basis of Industrial Control Systems (ICS) and hence are often a focal point for attackers to exploit. Previous attacks have seen PLC memory maliciously altered in order to disrupt the underlying physical process. Different types of memory attack can cause a similar impact on the PLC's operation and result in indistinguishable physical manifestations. Consequently, delays in triaging attacks through digital forensic practices can induce significant financial loss, physical damage to the infrastructure, and degradation of safety. In this work, we propose PLCPrint, a novel vendor-independent fingerprinting approach that utilises PLC memory artefacts to perform detection and classification of memory attacks. PLCPrint uses PLC memory register mapping, a novel method exploiting the relationship between PLC registers and memory artefacts including the PLC application code. Through this, registers are assigned a Mapping Condition (MC) to indicate how they exist within the PLC memory artefacts. We evaluate the performance of PLCPrint over realistic emulations conducted at a real testbed emulating water filtration and distribution. Through PLCPrint we depict how MC deviations are utilised within supervised learning schemes such as to adequately classify PLC memory attacks with high accuracy performance. In general, we demonstrate that PLCPrint fills the gap in the context of attack technique triaging since this has been a missing element within current ICS forensics schemes.
Evidently, centralised botnets are nowadays considered as easy targets for take-down efforts by law enforcement and computer security researchers. Hence, malicious actors transitioned towards the implementation of Peer-to-Peer (P2P) IoT botnets such to solidify their infrastructures, avoid single points of failure and further evade back tracking. Consequently, due to the highly distributed persona of modern P2P botnets, the detection of critical nodes to aid for the effective capturing of emerging threat vectors in such setups evolved into a challenging task. In this work, we conduct a novel 24-month longitudinal study based on real Internet measurements from globally distributed honeypots focusing on propagation trends of P2P IoT botnets. In order to achieve this, we develop graph-based centrality metrics to attribute AS-level connectivity characteristics to botnet and malware propagation as well as relating AS-level tolerance for botnet malware hosts we refer to as loaders. In general, we argue that the proposed methodology and outcomes of the herein study, can significantly benefit security experts and network operators towards the design of mitigation measures against present and future P2P botnets.
Operational Technology (OT) systems have become increasingly interconnected and automated, consequently resulting in them becoming targets of cyber attacks, with the threat towards a range of critical national infrastructure (CNI) sectors becoming heightened. This is particularly the case for Industrial Control Systems (ICS), which control and operate the physical processes in CNI sectors such as water treatment, electrical generation and manufacturing. Unlike information technology (IT) systems, ICS have unique cyber-physical characteristics and related safety requirements, making them an attractive target for attacks given the physical consequences that can occur. As a result, the requirement to respond and learn from previous and new attacks is also increasing, with digital forensics playing a significant role in this process. The aim of this paper is to discuss the main issues and existing limitations related to ICS digital forensic. The field of ICS digital forensics is relatively under-developed and does not have the same levels of maturity as IT digital forensics. Although the amount of research on cyber security for ICS is increasing, many unique challenges still exist that pose as barriers to the development and deployment of ICS forensic capabilities. We provide an extensive discussion on these challenges, categorising them into technical, socio-technical, and operational and legal themes. Furthermore, the relationship between these challenge themes as well as the inter-challenge dependencies are also examined. Furthermore, this work discusses ICS forensic advances in relation to the digital forensics life chain, specifically forensic readiness and investigations. The areas of digital forensic training and processes models for ICS are given particular focus. Moreover, we assess the technologies and tools that have been either applied to or developed for ICS components and networks, giving special attention to forensic acquisition and analysis methods. An examination into the specific ICS digital forensic data sources and artefacts is also presented, highlighting that until recently, this was limited to descriptions of generic data formats. In addition, this paper provides an overview of several key ICS attacks, summarising the specific techniques used, data artefacts of interest, and proposing lessons learnt. Finally, this paper presents open discussions on future ICS digital forensics research directions and on-going issues, covering both short and long-term areas that can be addressed to improve the ICS digital forensics capability.
Cyber-Physical Systems (CPS) constitute the operational basis for a number of critical national infrastructure (CNI) sectors including but not limited to manufacturing, smart electrical grids and water utilities, where programmable networked systems enable physical processes. Programmable Logic Controllers (PLCs) play a vital role in this by controlling CPS processes and consequently have become a primary target for cyber attacks that aim to disrupt CPS. By contrast with conventional networked setups, the operational and safety-critical importance of PLCs introduce challenges for CNI operators on empirically determining if an incident is a cyber-attack or a system fault as both occurrences can display similar outputs on the physical process. Moreover, existing anomaly detection techniques explicit to PLCs primarily give indication of an incident rather than attempting to categorise what the incident is. In this paper, we introduce a novel PLC anomaly diagnosis framework defined by a two-stage identification and classification approach based on novelty detection. Through the use of PLC run-time and network communication data generated by physical processes on a representational CPS testbed, we achieve an average of 99.35% on anomaly profiling accuracy and highlight the distinctions between system faults and cyber-attacks. In general, we demonstrate a practical approach that can be adopted by next generation CPS cyber defence tools.
Smart Grids are electrical grids that require a decentralised way of controlling electric power conditioning and thereby control the production and distribution of energy. Yet, the integration of Distributed Renewable Energy Sources (DRESs) in the Smart Grid introduces new challenges with regards to electrical grid balancing and storing of electrical energy, as well as additional monetary costs. Furthermore, the future smart grid also has to take over the provision of Ancillary Services (ASs). In this paper, a distributed ICT infrastructure to solve such challenges, specifically related to ASs in future Smart Grids, is described. The proposed infrastructure is developed on the basis of the Smart Grid Architecture Model (SGAM) framework, which is defined by the European Commission in Smart Grid Mandate M/490. A testbed that provides a flexible, secure, and low-cost version of this architecture, illustrating the separation of systems and responsibilities, and supporting both emulated DRESs and real hardware has been developed. The resulting system supports the integration of a variety of DRESs with a secure two-way communication channel between the monitoring and controlling components. It assists in the analysis of various inter-operabilities and in the verification of eventual system designs. To validate the system design, the mapping of the proposed architecture to the testbed is presented. Further work will help improve the architecture in two directions; first, by investigating specific-purpose use cases, instantiated using this more generic framework; and second, by investigating the effects a realistic number and variety of connected devices within different grid configurations has on the testbed infrastructure.
The Internet of Things (IoT), in combination with advancements in Big Data, communications and networked systems, offers a positive impact across a range of sectors including health, energy, manufacturing and transport. By virtue of current business models adopted by manufacturers and ICT operators, IoT devices are deployed over various networked infrastructures with minimal security, opening up a range of new attack vectors. Conventional rule-based intrusion detection mechanisms used by network management solutions rely on pre-defined attack signatures and hence are unable to identify new attacks. In parallel, anomaly detection solutions tend to suffer from high false positive rates due to the limited statistical validation of ground truth data, which is used for profiling normal network behaviour. In this work we go beyond current solutions and leverage the coupling of anomaly detection and Cyber Threat Intelligence (CTI) with parallel processing for the profiling and detection of emerging cyber attacks. We demonstrate the design, implementation, and evaluation of Citrus: a novel intrusion detection framework which is adept at tackling emerging threats through the collection and labelling of live attack data by utilising diverse Internet vantage points in order to detect and classify malicious behaviour using graph-based metrics as well as a range of machine learning (ML) algorithms. Citrus considers the importance of ground truth data validation and its flexible software architecture enables both the real-time and offline profiling, detection and classification of emerging cyber-attacks under optimal computational costs. Thus, establishing it as a viable and practical solution for next generation network defence and resilience strategies.
The adoption of the IoT by modern sociotechnical systems in synergy with the rapid deployment of insecure IoT devices and services has transformed the cyber-threat landscape. Thus, the vast majority of cyberattacks are underpinned by the orchestration of compromised IoT devices that are globally distributed and controlled through carefully designed IoT botnets. Contrary to conventional belief, cybersecurity vectors instrumented by such botnets are not always uniformly distributed across Internet Autonomous Systems (ASes). By virtue of network structural characteristics imposed by each individual Autonomous System (AS) as well as the diversity in terms of AS-level cybersecurity policies, the spatiotemporal manifestation of IoT botnets differs. In this work, we provide a novel measurement study that empirically quantifies AS tolerance of IoT botnet propagation in the global IPv4 Internet. We assess and correlate measurements gathered by globally distributed honeypots, Internet regional registries and IP blacklists for a 15-month period and observe more than 3.2M malicious events triggered by IoT botnets spanning 9.5K ASes. Our work demonstrates that ASes connected to a low number of providers are prone to embrace a high portion of malicious activities. Hence, we provide evidence on concentrated botnet activities and determine the effectiveness of widely used IP blacklists. In general, this study contributes towards empowering knowledge on large-scale cyber-attacks as being crucial for the composition of next generation data-driven cybersecurity defence applications.
Energy theft is an old and multifaceted phenomenon affecting our society on a global scale from both an operational as well as from a monetary perspective. The relatively recent decentralisation of the grid infrastructure with the integration of Distributed Renewable Energy Resources (DRES) in synergy with the widely adopted demand-response business model, has undoubtedly broadened the spectrum of attack surface enabling energy theft. Conventional data-driven energy theft detection schemes have a strong dependency on assessing the spatio-temporal patterns of SCADA measurements aggregated at the Distribution System Operator (DSO) or Transmission System Operator (TSO) with minimal consideration of the intrinsic weather patterns related to individual DRES deployments. Hence, theft scenarios instrumented by DRES owners consuming the energy they produce (i.e., prosumers) can effectively be stealthy and hard to spot. Therefore, in this work we introduce a data-driven, SCADA-agnostic energy theft detection framework explicit to DRES-based scenarios. We provide a comprehensive formalisation of a DRES-based theft attack model and further assess the performance of our framework by utilising and relating freely available third-party weather measurements with real solar and wind turbine deployments in Australia and France. Evidently, our proposed framework yields an energy theft detection accuracy rate of over 98% with optimal computational costs. Thus, reasonably addressing the highly demanding requirements of low-cost and accurate real-time energy theft detection in modern power grids.
A smart grid ecosystem requires intelligent Home Energy Management Systems (HEMSs) that allow the adequate monitoring and control of appliance-level energy consumption in a given household. They should be able to: i) profile highly non-stationary and non-linear measurements and ii) conduct correlations of such measurements with diverse inputs (e.g. environmental factors) in order to improve the end-user experience, as well as to aid the overall demand-response optimisation process. However, traditional approaches in HEMS lack the ability to capture diverse variations in appliance-level energy consumption due to unpredictable human behavior and also require high computation to process large datasets. In this article, we go beyond current profiling schemes by proposing Deep COLA; a novel Deep COmpetitive Learning Algorithm that addresses the limitations of existing work in terms of high dimensional data and enables more efficient and accurate clustering of appliance-level energy consumption. The proposed approach reduces human intervention by automatically selecting load profiles and models variations and uncertainty in human behavior during appliance usage. We demonstrate that our proposed scheme is far more computationally efficient and scalable data-wise than three popular conventional clustering approaches namely, K-Means, DBSCAN and SOM, using real household datasets. Moreover, we exhibit that Deep COLA identifies per-household behavioral associations that could aid future HEMSs.
The convergence of legacy power system components with advanced networking and communication facilities have led towards the development of smart grids. Smart grids are envisioned to be the next generation innovative power systems, guaranteeing resilience, reliability and sustainability and to facilitate energy production, distribution and management. Nonetheless, the development of such systems entails challenges covering a broad spectrum ranging from operational management up to data-driven power accounting and network security. Given the highly distributed properties of the modern grid, energy theft can now be observed at various transmission and distribution levels. Apart from the financial gain for a malicious actor, energy theft can also affect critical grid processes with a direct impact on its overall resilience and safety. This survey reviews recent energy theft strategies as well as detection methods from a data-driven perspective. By considering various operational and functional layers within modern smart grids we critically assess how energy theft can be formulated. Moreover, we provide an overview of the grid demand, supply and control chain with a focus on energy theft and associated security flaws that currently exist in the smart grid ecosystem. Different attack detection models for theft detection in the smart grid are categorized. Lastly, we discuss various open issues in the scope of data-driven energy theft detection methods and provide future directions to carry out research in this field.
David W. Hutchison合作论文数Faculty of Science and Technology;Lancaster University;Computing Department19