Multi-Source Multi-Domain Data Fusion for Cyberattack Detection in Power Systems

被引:43
|
作者
Sahu, Abhijeet [1 ]
Mao, Zeyu [1 ]
Wlazlo, Patrick [2 ]
Huang, Hao [1 ]
Davis, Katherine [1 ]
Goulart, Ana [2 ]
Zonouz, Saman [3 ]
机构
[1] Texas A&M Univ, Dept Elect & Comp Engn, College Stn, TX 77843 USA
[2] Texas A&M Univ, Elect Syst Engn Technol Program, College Stn, TX 77843 USA
[3] Rutgers State Univ, Dept Elect & Comp Engn, New Brunswick, NJ 08854 USA
关键词
Data integration; Power systems; Cyberattack; Sensors; Sensor fusion; Intrusion detection; Feature extraction; Multi-sensor data fusion; intrusion detection system; co-training; supervised learning; unsupervised learning; cyber-physical systems; power systems; NETWORK INTRUSION DETECTION;
D O I
10.1109/ACCESS.2021.3106873
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern power systems equipped with advanced communication infrastructure are cyber-physical in nature. The traditional approach of leveraging physical measurements for detecting cyber-induced physical contingencies is insufficient to reflect the accurate cyber-physical states. Moreover, deploying conventional rule-based and anomaly-based intrusion detection systems for cyberattack detection results in higher false positives. Hence, independent usage of detection tools of cyberattacks in cyber and physical sides has a limited capability. In this work, a mechanism to fuse real-time data from cyber and physical domains, to improve situational awareness of the whole system is developed. It is demonstrated how improved situational awareness can help reduce false positives in intrusion detection. This cyber and physical data fusion results in cyber-physical state space explosion which is addressed using different feature transformation and selection techniques. Our fusion engine is further integrated into a cyber-physical power system testbed as an application that collects cyber and power system telemetry from multiple sensors emulating real-world data sources found in a utility. These are synthesized into features for algorithms to detect cyber intrusions. Results are presented using the proposed data fusion application to infer False Data and Command Injection (FDI and FCI)-based Man-in-The-Middle attacks. Post collection, the data fusion application uses time-synchronized merge and extracts features. This is followed by pre-processing such as imputation, categorical encoding, and feature reduction, before training supervised, semi-supervised, and unsupervised learning models to evaluate the performance of the intrusion detection system. A major finding is the improvement of detection accuracy by fusion of features from cyber, security, and physical domains. Additionally, it is observed that the semi-supervised co-training technique performs at par with supervised learning methods with the proposed feature vector. The approach and toolset, as well as the dataset that is generated can be utilized to prevent threats such as false data or command injection attacks from being carried out by identifying cyber intrusions accurately.
引用
收藏
页码:119118 / 119138
页数:21
相关论文
共 50 条
  • [31] Application of information fusion technologies for multi-source data
    Wu, Hao
    Seng, Dewen
    Fang, Xujian
    Xu, Haitao
    Journal of Chemical and Pharmaceutical Research, 2013, 5 (12) : 560 - 564
  • [32] Multi-source Information Fusion Based on Data Driven
    Zhang Xin
    Yang Li
    Zhang Yan
    ADVANCES IN SCIENCE AND ENGINEERING, PTS 1 AND 2, 2011, 40-41 : 121 - 126
  • [33] Using granular objects in multi-source data fusion
    Yager, RR
    ROUGH SETS AND CURRENT TRENDS IN COMPUTING, PROCEEDINGS, 2002, 2475 : 324 - 330
  • [34] A multi-source heterogeneous data fusion method for intelligent systems in the Internet of Things
    Sun, Rongrong
    Ren, Yuemei
    INTELLIGENT SYSTEMS WITH APPLICATIONS, 2024, 23
  • [35] Study of Multi-source Data Fusion in Topic Discovery
    Xu, Hai Yun
    Wang, Chao
    Ru, Li Jie
    Yue, Zeng Hui
    Wei, Ling
    Fang, Shu
    ADVANCED MULTIMEDIA AND UBIQUITOUS ENGINEERING: FUTURETECH & MUE, 2016, 393 : 729 - 735
  • [36] Multi-source Anomaly Detection in Distributed IT Systems
    Bogatinovski, Jasmin
    Nedelkoski, Sasho
    SERVICE-ORIENTED COMPUTING, ICSOC 2020, 2021, 12632 : 201 - 213
  • [37] The dynamic fusion representation of multi-source fuzzy data
    Qin, Chaoxia
    Guo, Bing
    Zhang, Yun
    Shen, Yan
    APPLIED INTELLIGENCE, 2023, 53 (22) : 27226 - 27248
  • [38] The dynamic fusion representation of multi-source fuzzy data
    Chaoxia Qin
    Bing Guo
    Yun Zhang
    Yan Shen
    Applied Intelligence, 2023, 53 : 27226 - 27248
  • [39] Multi-source unsupervised domain adaptation for object detection
    Zhang, Dan
    Ye, Mao
    Liu, Yiguang
    Xiong, Lin
    Zhou, Lihua
    INFORMATION FUSION, 2022, 78 : 138 - 148
  • [40] Multi-Source Domain Adaptation with Distribution Fusion and Relationship Extraction
    Li, Keqiuyin
    Lu, Jie
    Zuo, Hua
    Zhang, Guangquan
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,