Power-Grid Controller Anomaly Detection with Enhanced Temporal Deep Learning

被引:14
|
作者
He, Zecheng [1 ]
Raghavan, Aswin [2 ]
Hu, Guangyuan [1 ]
Chai, Sek [2 ]
Lee, Ruby [1 ]
机构
[1] Princeton Univ, Princeton, NJ 08544 USA
[2] SRI Int, Princeton, NJ USA
关键词
D O I
10.1109/TrustCom/BigDataSE.2019.00030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Controllers of security-critical cyber-physical systems, like the power grid, are a very important class of computer systems. Attacks against the control code of a power-grid system, especially zero-day attacks, can be catastrophic. Earlier detection of the anomalies can prevent further damage. However, detecting zero-day attacks is extremely challenging because they have no known code and have unknown behavior. Furthermore, if data collected from the controller is transferred to a server through networks for analysis and detection of anomalous behavior, this creates a very large attack surface and also delays detection. In order to address this problem, we propose Reconstruction Error Distribution (RED) of Hardware Performance Counters (HPCs), and a data-driven defense system based on it. Specifically, we first train a temporal deep learning model, using only normal HPC readings from legitimate processes that run daily in these power-grid systems, to model the normal behavior of the power-grid controller. Then, we run this model using real-time data from commonly available HPCs. We use the proposed RED to enhance the temporal deep learning detection of anomalous behavior, by estimating distribution deviations from the normal behavior with an effective statistical test. Experimental results on a real power-grid controller show that we can detect anomalous behavior with high accuracy (>99.9%), nearly zero false positives and short (<360ms) latency.
引用
收藏
页码:160 / 167
页数:8
相关论文
共 50 条
  • [1] Evaluation of opaque deep-learning solar power forecast models towards power-grid applications
    Cheng, Lilin
    Zang, Haixiang
    Wei, Zhinong
    Zhang, Fengchun
    Sun, Guoqiang
    RENEWABLE ENERGY, 2022, 198 : 960 - 972
  • [2] Spatio-temporal complexity of power-grid frequency fluctuations
    Gorjao, Rydin
    Schaefer, Benjamin
    Witthaut, Dirk
    Beck, Christian
    NEW JOURNAL OF PHYSICS, 2021, 23 (07):
  • [3] Power-grid stability predictions using transferable machine learning
    Yang, Seong-Gyu
    Kim, Beom Jun
    Son, Seung-Woo
    Kim, Heetae
    CHAOS, 2021, 31 (12)
  • [4] Deep learning on temporal-spectral data for anomaly detection
    Ma, King
    Leung, Henry
    Jalilian, Ehsan
    Huang, Daniel
    GROUND/AIR MULTISENSOR INTEROPERABILITY, INTEGRATION, AND NETWORKING FOR PERSISTENT ISR VIII, 2017, 10190
  • [5] Smart Grid Anomaly Detection using a Deep Learning Digital Twin
    Danilczyk, William
    Sun, Yan
    He, Haibo
    2020 52ND NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2021,
  • [6] Intelligent Intrusion Detection Scheme for Smart Power-Grid Using Optimized Ensemble Learning on Selected Features
    Panthi, Manikant
    Das, Tanmoy Kanti
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 39
  • [7] Anomaly Detection in Satellite Power System using Deep Learning
    Preetha, S. B. Kavya
    Sai, Jalakam Venu Madhava
    Raj, V. Sowbaranic
    Sekhar, M. Jayan
    Lavanya, R.
    10TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTING AND COMMUNICATION TECHNOLOGIES, CONECCT 2024, 2024,
  • [8] Intelligent Intrusion Detection Scheme for Smart Power-Grid Using Optimized Ensemble Learning on Selected Features
    Panthi, Manikant
    Kanti Das, Tanmoy
    International Journal of Critical Infrastructure Protection, 2022, 39
  • [9] Deep Learning for Anomaly Detection
    Pang, Guansong
    Aggarwal, Charu
    Shen, Chunhua
    Sebe, Nicu
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2022, 33 (06) : 2282 - 2286
  • [10] Deep Learning for Anomaly Detection
    Wang, Ruoying
    Nie, Kexin
    Wang, Tie
    Yang, Yang
    Long, Bo
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING (WSDM '20), 2020, : 894 - 896