An End-to-End Infrastructure for Cyber-Physical Intrusion Detection
REINHARD GENTZ, MAHDI JAMEI, ANNA SCAGLIONE
ARIZONA STATE UNIVERSITY, USA
CREDC Workshop 2017
1
An End-to-End Infrastructure for Cyber-Physical Intrusion Detection - - PowerPoint PPT Presentation
An End-to-End Infrastructure for Cyber-Physical Intrusion Detection REINHARD GENTZ, MAHDI JAMEI, ANNA SCAGLIONE ARIZONA STATE UNIVERSITY, USA CREDC Workshop 2017 1 What is Cyber Physical Intrusion Detection CPS Cyber Physical System
REINHARD GENTZ, MAHDI JAMEI, ANNA SCAGLIONE
ARIZONA STATE UNIVERSITY, USA
CREDC Workshop 2017
1
CPS – Cyber Physical System In a system Cyber & Physical environment is connected
detection CPS-IDS goes beyond the traditional monitoring solutions adopted in EDS-operations. It requires new elements :
Challenge: Big Data Problem
2
Cyber and Physical System
System Physical Properties (Physical) Control & Monitoring (Cyber)
We propose hierarchical architecture:
3
Do as much of the processing locally and only ship what is necessary
Stage 2 Server Central Server Grid
μPMU DSCADA DSCADA μPMU
Stage 1 Server
Stage 1
4
a uPMU with a BBB attached Analytics
Data Analytics
Hi Prio Queue Low Prio Queue
Sensor Data
Analytics Decide the Queue
Local Rules e.g.,:
Limits
Message
Stage 1
5
The BBB minicomputer shields the sensor from the
One minicomputer system to maintain – Not one per sensor type Independence from sensor vendor security updates Modular Design The analytics systems are plug-in modules
programmer (Only API knowledge needed)
a uPMU with a BBB attached
Local Rules e.g.,:
Limits
Analytics
Data Analytics
Hi Prio Queue Low Prio Queue
Sensor Data
Analytics Decide the Queue Message
Stage 2
6
Publisher Subscriber Messaging Database for Search
(Elasticsearch)
Database for Archiving
(Cassandra)
Aggregated Analytics Frontend Local Analytics and prioritization (BBB)
1 2 3 4 5 6 7 R1 8 9 10 11 12 13 14 15 16 17 18 19 R2 20 T1 23 24 34 33 32 31 30 25 21 22 26 27 28 29 Substation
Power Distribution Grid Cyber-Physical Security Architecture
Local Analytics and prioritization (BBB) Local Analytics and prioritization (BBB)
generate actionable alarms with low latency
Messaging System Analytics Results Raw Data & Preprocessed Analytics Analytics 1 Analytics N From Downstream To Upstream
Central Stage
7
Publisher Subscriber Messaging Database for Search
(Elasticsearch)
Database for Archiving
(Cassandra)
Aggregated Analytics Frontend Local Analytics and prioritization (BBB)
1 2 3 4 5 6 7 R1 8 9 10 11 12 13 14 15 16 17 18 19 R2 20 T1 23 24 34 33 32 31 30 25 21 22 26 27 28 29 Substation
Power Distribution Grid Cyber-Physical Security Architecture
Local Analytics and prioritization (BBB) Local Analytics and prioritization (BBB)
Search for properties? Elasticsearch Retrieve lots
Cassandra Different databases have different strengths
8
No Alarm Voltage Sag BBB 1 BBB 2 BBB 3 Results found from data analysis. Priority for transmission No Alarm Stage 2’s View No Alarm No Alarm Voltage Sag => Fault localized downstream of uPMU 3 Threshold crossed
9
10
Sensor 1 2nd floor Sensor 2 Basement ServerRack
11
Min/Max Sensor 1 2nd floor Min/Max Sensor 2 Basement ServerRack Voltage Dip in the whole building
Question: Is this pattern possible with the specific electrical grid in place? => Further validation