Cyber risk assessment is a critical step in securing the digital systems that support modern society. Typically this is a manual process carried out by consultants or working groups with little or no software support outside of spreadsheet tools. As cybersecurity threats and digital systems themselves become more complex and dynamic, there is a need for greater tool support in the risk assessment process to document and trace assumptions and facilitate the revision or extension of a threat and risk assessment throughout a system’s lifecycle. The Cyber Security Argument Graph Evaluation (CyberSAGE) tool provides a platform for model-based cybersecurity analysis of cyber failure and attack scenarios. It combines models of high-level workflow, system architecture, device properties, attacker capability and skill, to compute holistic, quantitative security metrics. In this paper we describe the models, algorithms, and software architecture of the CyberSAGE tool. To illustrate its application, we describe an assessment carried out on communication systems in two railway lines with the support of an industry partner. Finally, we summarize feedback on the CyberSAGE tool from the railway case study partner, as well as over 40 interviews with practitioners and domain experts and a multinational electronics company who carried out a one year independent evaluation.
People always pay attention to the security of the network. This paper mainly analyzed the problem of network security situation prediction (NSSP). The radial basis function neural network was improved by the particle swarm optimization algorithm, and a modified particle swarm optimization‐radial basis function algorithm was obtained, which was used as the prediction model. Then, the data from National Internet Emergency Center were used as the experimental data, and the modified particle swarm optimization‐radial basis function algorithm was compared with radial basis function and particle swarm optimization‐radial basis function algorithms. The results showed that the modified particle swarm optimization‐radial basis function algorithm could achieve convergence in about 50 times of iterations, showing a high calculation efficiency and a short operation time, and the mean absolute percentage error value, mean square error value, and root‐mean‐square error value were small (2.13%, 0.0005, and 0.0224), showing that the algorithm had good prediction performance. The results verify the reliability of the modified particle swarm optimization‐radial basis function algorithm in NSSP, which is conducive to further improve network security.
The digitisation of modern power grid substations allows them to better support various advanced operations. However, it also poses greater risk of cyber-related attacks. There is an array of cybersecurity solutions (e.g., intrusion detection systems) available in the market to prevent, detect, or respond to cyberattacks. This calls for the creation of datasets and test cases for the validation of those cybersecurity solutions. In our recent work, we have generated a synthesized dataset for testing of cybersecurity solutions of IEC 61850 based substations. Our dataset contained traces for some typical attack-free disturbance scenarios and cyberattack scenarios in a substation. In this work, we present the toolchain we have developed to allow easy generation of such traces. We discuss the design considerations behind our toolchain and provide step-by-step guide to potential users on how to create customized trace files for specific scenarios using our toolchain. By open-sourcing the project for the broad community, we hope our toolchain will enrich the body of testing datasets for substation cyber security solutions.
Cyber attacks pose a major threat to smart grid infrastructures where communication links bind physical devices to provide critical measurement, protection, and control functionalities. Substation is an integral part of a power system. Modern substations with intelligent electronic devices and remote access interface are more prone to cyber attacks. Hence, there is an urgent need to consider cybersecurity at the electrical substation level. This paper makes a systematic effort to develop a synthesized dataset focusing on IEC 61850 GOOSE communication that is essential for automation and protection in smart grid. The dataset is intended to facilitate the research community to study the cybersecurity of substations. We present the physical system of a typical distribution level substation and several of its critical electrical protection operation scenarios under different disturbances, followed by several cyber-attack scenarios. We have generated a dataset with multiple traces that correspond to these scenarios and demonstrated how the dataset can be used to support substation cybersecurity research.
In order to implement and fine-tune cyber defense mechanisms, it is crucial to know who are the potential enemies and what tactics they are using. In the general cyber security area, honeypot, a decoy system intended to attract cyber attackers, is considered as an effective measure to collect such threat intelligence. However, publication analysing such data is scarce, especially in industrial control systems and smart grid domain. In this paper, we discuss our findings based on the empirical study with 6-month network traces collected in low-interaction smart grid honeypot systems deployed in geographically different regions on Amazon cloud platform. In particular, we discuss actual attack patterns observed as well as insights from the data-driven study on access/attack patterns, correlations among different locations, and dynamics in access sources, some of which are considered effective when configuring security mechanisms such as firewall and intrusion detection systems.