This paper describes the architecture and the fundamental methodology of an anomaly detector, which by continuously monitoring Simple Network Management Protocol data and by processing it as complex-events, is able to timely recognize patterns of faults and relevant cyber-attacks. This solution has been applied in the context of smart grids, and in particular as part of a security and resilience component of the Information and Communication Technologies (ICT) Gateway, a middleware-based architecture that correlates and fuses measurement data from different sources (e.g., Inverters, Smart Meters) to provide control coordination and to enable grid observability applications. The detector has been evaluated through experiments, where we selected some representative anomalies that can occur on the ICT side of the energy distribution infrastructure: non-malicious faults (indicated by patterns in the system resources usage), as well as effects of typical cyber-attacks directed to the smart grid infrastructure. The results show that the detection is promisingly fast and efficient.
翻译:本文件描述了异常探测器的结构和基本方法,通过不断监测简单的网络管理协议数据并将这些数据作为复杂活动处理,能够及时识别故障模式和相关网络攻击,这一解决办法适用于智能网格,特别是作为信息和通信技术网关安全和复原力组成部分的一部分,该网关是一个中软件结构,与来自不同来源(如Inverters, Smart Meters)的测量数据相关并结合,以提供控制协调并促成电网可观察性应用。该探测器是通过实验进行评估的,我们通过实验选择了能源分配基础设施信通技术方面可能发生的一些具有代表性的异常现象:非恶意的故障(由系统资源使用模式所说明),以及针对智能网格基础设施的典型网络攻击的影响。结果显示,探测工作有望迅速而有效。