Machine Learning-Based Intrusion Detection for Energy Substations
Open Access DepositedEnergy systems are fundamental to modern economies and essential for daily life, thus earning them critical infrastructure designation. Other critical infrastructures depend on energy (White House, 2013). Therefore, disruptions in energy supply have significant impacts beyond blackouts. These impacts extend to health and welfare, and an economy cannot function without energy (CISA, 2023). Energy generation relies on multiple sources, including conventional ones like coal and natural gas, as well as clean energy sources such as solar, nuclear, hydro, and wind energy. Energy generation output is transmitted over high-voltage channels to substations. The high voltage is then stepped down to manageable levels and safely distributed to end users. This process makes substations pivotal in energy distribution. Over time, to boost efficiency and reliability, innovative technologies have been introduced to substation components, hence inheriting the vulnerabilities from these technologies. For instance, the introduction of Supervisory Control and Data Acquisition (SCADA) systems to substations (Boakye-Boateng, 2023). SCADA provides centralized monitoring and control of processes in the substation. However, this digitalization of substations exposes new attack surfaces associated with technologies they integrate with. Moreover, energy systems have been the subject of continuous cyber-attacks leading to outages. Such an incident has an estimated average impact exceeding USD 4 million (Casanovas & Nghiem, 2023). Several factors contribute to these attacks. One significant reason is the increased number of published vulnerabilities, and performance constraints, which make substations uniquely challenging environments for implementing intrusion detection systems (Boakye-Boateng, 2023). Additionally, there are instances of attacks during tense geopolitical situations such as those reported by (White, T., 2016) and (Baggott, 2020), which underscore the vulnerability of these systems. This praxis focuses on applying machine learning to detect intrusions in energy substations, as under-detection has been identified as a key factor in failing to fully identify the scope of these attacks (Casanovas & Nghiem, 2023). This study is focused on a machine learning approach for intrusion detection using neural network models. It utilizes various techniques, including Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), Gated Recurrent Units (GRU), mini-LSTM, and mini-GRU, to identify attacks targeting energy substations." The goal is to develop a strong intrusion detection system for energy substations, with the capability to spot various attack patterns, including reconnaissance, query flooding, false data injection, denial of service (DoS), fuzzing attack, port scanning, packet starvation attack, etc. The dataset being used is called SANDI-2024 (Substation Anomaly Network Data for Intrusion Detection 2024) which shows attack scenarios at two real energy substations that use IEC 104 and IEC61850 communication protocols, respectively. The dataset is a combination of two real datasets representing benign behavior and synthesized data obtained from a test representing attack scenarios. The adopted approach follows stages of the data mining lifecycle, including data collection, data preprocessing, data exploration and analysis, data modelling, and interpretation. It compares and checks which detection method works best and suggests that GRU and LSTM models outperform other methods, exhibiting superior accuracy in detecting substation intrusion attacks.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.