Multi-Source Multi-Domain Data Fusion for Cyberattack Detection in Power Systems

被引:43
|
作者
Sahu, Abhijeet [1 ]
Mao, Zeyu [1 ]
Wlazlo, Patrick [2 ]
Huang, Hao [1 ]
Davis, Katherine [1 ]
Goulart, Ana [2 ]
Zonouz, Saman [3 ]
机构
[1] Texas A&M Univ, Dept Elect & Comp Engn, College Stn, TX 77843 USA
[2] Texas A&M Univ, Elect Syst Engn Technol Program, College Stn, TX 77843 USA
[3] Rutgers State Univ, Dept Elect & Comp Engn, New Brunswick, NJ 08854 USA
关键词
Data integration; Power systems; Cyberattack; Sensors; Sensor fusion; Intrusion detection; Feature extraction; Multi-sensor data fusion; intrusion detection system; co-training; supervised learning; unsupervised learning; cyber-physical systems; power systems; NETWORK INTRUSION DETECTION;
D O I
10.1109/ACCESS.2021.3106873
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern power systems equipped with advanced communication infrastructure are cyber-physical in nature. The traditional approach of leveraging physical measurements for detecting cyber-induced physical contingencies is insufficient to reflect the accurate cyber-physical states. Moreover, deploying conventional rule-based and anomaly-based intrusion detection systems for cyberattack detection results in higher false positives. Hence, independent usage of detection tools of cyberattacks in cyber and physical sides has a limited capability. In this work, a mechanism to fuse real-time data from cyber and physical domains, to improve situational awareness of the whole system is developed. It is demonstrated how improved situational awareness can help reduce false positives in intrusion detection. This cyber and physical data fusion results in cyber-physical state space explosion which is addressed using different feature transformation and selection techniques. Our fusion engine is further integrated into a cyber-physical power system testbed as an application that collects cyber and power system telemetry from multiple sensors emulating real-world data sources found in a utility. These are synthesized into features for algorithms to detect cyber intrusions. Results are presented using the proposed data fusion application to infer False Data and Command Injection (FDI and FCI)-based Man-in-The-Middle attacks. Post collection, the data fusion application uses time-synchronized merge and extracts features. This is followed by pre-processing such as imputation, categorical encoding, and feature reduction, before training supervised, semi-supervised, and unsupervised learning models to evaluate the performance of the intrusion detection system. A major finding is the improvement of detection accuracy by fusion of features from cyber, security, and physical domains. Additionally, it is observed that the semi-supervised co-training technique performs at par with supervised learning methods with the proposed feature vector. The approach and toolset, as well as the dataset that is generated can be utilized to prevent threats such as false data or command injection attacks from being carried out by identifying cyber intrusions accurately.
引用
收藏
页码:119118 / 119138
页数:21
相关论文
共 50 条
  • [1] Challenges and Recommended Solutions in Multi-Source and Multi-Domain Sentiment Analysis
    Abdullah, Nor Aniza
    Feizollah, Ali
    Sulaiman, Ainin
    Anuar, Nor Badrul
    IEEE ACCESS, 2019, 7 : 144957 - 144971
  • [2] Multi-source Data Fusion Technology for Power Wearable System
    Liu Guanke
    Liu, Junjie
    Wei Rongtao
    Wang Jinshuai
    2018 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION ENGINEERING TECHNOLOGY (CCET), 2018, : 118 - 122
  • [3] Multi-source Heterogeneous Data Fusion
    Zhang, Lili
    Xie, Yuxiang
    Luan Xidao
    Zhang, Xin
    2018 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND BIG DATA (ICAIBD), 2018, : 47 - 51
  • [4] A framework for multi-source data fusion
    Yager, RR
    INFORMATION SCIENCES, 2004, 163 (1-3) : 175 - 200
  • [5] Multi-source domain adaptation of GPR data for IED detection
    Mehmet Oturak
    Seniha Esen Yuksel
    Sefa Kucuk
    Signal, Image and Video Processing, 2023, 17 : 1831 - 1839
  • [6] Multi-source domain adaptation of GPR data for IED detection
    Oturak, Mehmet
    Yuksel, Seniha Esen
    Kucuk, Sefa
    SIGNAL IMAGE AND VIDEO PROCESSING, 2023, 17 (05) : 1831 - 1839
  • [7] Multi-source Multi-domain Sentiment Analysis with BERT-based Models
    Roccabruna, Gabriel
    Azzolin, Steve
    Riccardi, Giuseppe
    LREC 2022: THIRTEEN INTERNATIONAL CONFERENCE ON LANGUAGE RESOURCES AND EVALUATION, 2022, : 581 - 589
  • [8] Application of multi-source data fusion on intelligent prediction of photovoltaic power
    Tan, Ling
    Kang, Ruixing
    Xia, Jingming
    Wang, Yue
    SOLAR ENERGY, 2024, 277
  • [9] Multi-source Information Fusion for Depression Detection
    Wang, Rongquan
    Wang, Huiwei
    Hu, Yan
    Wei, Lin
    Ma, Huimin
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT V, 2024, 14429 : 517 - 528
  • [10] Multi-Source Data Fusion Study in Scientometrics
    Xu, Hai-Yun
    Wang, Chao
    Pang, Hong-shen
    Ru, Li-jie
    Fang, Shu
    QUALITATIVE & QUANTITATIVE METHODS IN LIBRARIES, 2016, : 611 - 626