Multi-Source Multi-Domain Data Fusion for Cyberattack Detection in Power Systems

被引:43
|
作者
Sahu, Abhijeet [1 ]
Mao, Zeyu [1 ]
Wlazlo, Patrick [2 ]
Huang, Hao [1 ]
Davis, Katherine [1 ]
Goulart, Ana [2 ]
Zonouz, Saman [3 ]
机构
[1] Texas A&M Univ, Dept Elect & Comp Engn, College Stn, TX 77843 USA
[2] Texas A&M Univ, Elect Syst Engn Technol Program, College Stn, TX 77843 USA
[3] Rutgers State Univ, Dept Elect & Comp Engn, New Brunswick, NJ 08854 USA
关键词
Data integration; Power systems; Cyberattack; Sensors; Sensor fusion; Intrusion detection; Feature extraction; Multi-sensor data fusion; intrusion detection system; co-training; supervised learning; unsupervised learning; cyber-physical systems; power systems; NETWORK INTRUSION DETECTION;
D O I
10.1109/ACCESS.2021.3106873
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern power systems equipped with advanced communication infrastructure are cyber-physical in nature. The traditional approach of leveraging physical measurements for detecting cyber-induced physical contingencies is insufficient to reflect the accurate cyber-physical states. Moreover, deploying conventional rule-based and anomaly-based intrusion detection systems for cyberattack detection results in higher false positives. Hence, independent usage of detection tools of cyberattacks in cyber and physical sides has a limited capability. In this work, a mechanism to fuse real-time data from cyber and physical domains, to improve situational awareness of the whole system is developed. It is demonstrated how improved situational awareness can help reduce false positives in intrusion detection. This cyber and physical data fusion results in cyber-physical state space explosion which is addressed using different feature transformation and selection techniques. Our fusion engine is further integrated into a cyber-physical power system testbed as an application that collects cyber and power system telemetry from multiple sensors emulating real-world data sources found in a utility. These are synthesized into features for algorithms to detect cyber intrusions. Results are presented using the proposed data fusion application to infer False Data and Command Injection (FDI and FCI)-based Man-in-The-Middle attacks. Post collection, the data fusion application uses time-synchronized merge and extracts features. This is followed by pre-processing such as imputation, categorical encoding, and feature reduction, before training supervised, semi-supervised, and unsupervised learning models to evaluate the performance of the intrusion detection system. A major finding is the improvement of detection accuracy by fusion of features from cyber, security, and physical domains. Additionally, it is observed that the semi-supervised co-training technique performs at par with supervised learning methods with the proposed feature vector. The approach and toolset, as well as the dataset that is generated can be utilized to prevent threats such as false data or command injection attacks from being carried out by identifying cyber intrusions accurately.
引用
收藏
页码:119118 / 119138
页数:21
相关论文
共 50 条
  • [21] A Situation Analysis Method for Specific Domain Based on Multi-source Data Fusion
    Wang, Haijian
    Zhang, Zhaohui
    Wang, Pengwei
    INTELLIGENT COMPUTING THEORIES AND APPLICATION, PT I, 2018, 10954 : 160 - 171
  • [22] Multi-Domain Information Fusion for Insider Threat Detection
    Eldardiry, Hoda
    Bart, Evgeniy
    Liu, Juan
    Hanley, John
    Price, Bob
    Brdiczka, Oliver
    IEEE CS SECURITY AND PRIVACY WORKSHOPS (SPW 2013), 2013, : 45 - 51
  • [23] Multi-Domain Grooming in Power Source Aware Networks
    Schondienst, Thilo
    Vokkarane, Vinod M.
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 1980 - 1985
  • [24] Data Fabrics for Multi-Domain Information Systems
    Habibi, Pooyan
    Moghaddassian, Morteza
    Shafaghi, Shayan
    Leon-Garcia, Alberto
    2023 19TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT, CNSM, 2023,
  • [25] MDFD: A multi-source data fusion detection framework for Sybil attack detection in VANETs
    Chen, Ye
    Lai, Yingxu
    Zhang, Zhaoyi
    Li, Hanmei
    Wang, Yuhang
    COMPUTER NETWORKS, 2023, 224
  • [26] MHDF: Multi-source Heterogeneous Data Progressive Fusion for Fake News Detection
    Yu, Yongxin
    Ji, Ke
    Gao, Yuan
    Chen, Zhenxiang
    Ma, Kun
    Wu, Jun
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PT V, PAKDD 2024, 2024, 14649 : 28 - 39
  • [27] Unsupervised multi-source domain adaptation with no observable source data
    Jeon, Hyunsik
    Lee, Seongmin
    Kang, U.
    PLOS ONE, 2021, 16 (07):
  • [28] A multi-source information fusion model for outlier detection
    Zhang, Pengfei
    Li, Tianrui
    Wang, Guoqiang
    Wang, Dexian
    Lai, Pei
    Zhang, Fan
    INFORMATION FUSION, 2023, 93 : 192 - 208
  • [29] Small Object Detection Based on Multi-source Data Learning Fusion Network
    Liu, Huanyu
    Li, Lu
    Jiang, Hejun
    Yang, Yi
    Liu, Yanyan
    ADVANCES IN INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING (IIH-MSP 2021 & FITAT 2021), VOL 1, 2022, 277 : 59 - 67
  • [30] Multi-source data fusion based on iterative deformation
    Xu, Zhi
    Dai, Ning
    Zhang, Changdong
    Song, Yinglong
    Sun, Yuchun
    Yuan, Fusong
    Jixie Gongcheng Xuebao/Journal of Mechanical Engineering, 2014, 50 (07): : 191 - 198