AMINet: An Industrial Honeynet for AMI Systems.

2023 IEEE International Conference on Big Data (BigData)(2023)

引用 0|浏览1
暂无评分
摘要
Advanced Metering Infrastructure (AMI) systems constitute a vital part for the interconnection of the electrical grid towards enabling the smart grid area. They enable real-time electrical measurement exchange through a utility platform, in order to activate billing and load demand forecasting processes. However, the cyber-attack surface of such systems has increased over the latest years. The attacks are becoming highly sophisticated and cannot be detected by the existing cyber-security mechanisms. To cope with this challenge, these mechanisms should start incorporating knowledge about adversarial Tactics, Techniques are Procedures (TTPs). To achieve this, deception tools are used to lure adversaries by introducing an environment that resembles the actual system. In this paper we propose AMINet, which builds on a composition of well-known deception tools as honeypots to form a honeynet for AMI systems. Specifically, this work focuses on AMINet first architectural design with an emphasis on its emulation capabilities on the behavior and interactions between smart meters and the utility platform using the DLMS/COSEM protocol. Furthermore, AMINet is deployed in an production-level AMI infrastructure and compared against the actual AMI system that is available on the utility business side. The comparison results demonstrate a similar behavior, which is validated through initial tests on functional and non-functional requirements. Additionally, the existing small set of static attacks running in the infrastructure is enriched by more sophisticated attacks and AMINet aids towards the development of dedicated detection tools by logging the adversarial interactions.
更多
查看译文
关键词
Advanced Metering Infrastructure,Activation Of System,Power Grid,Electrical Measurements,Smart Grid,Smart Meters,Non-functional Requirements,Set Of Attacks,Data Exchange,Communication Protocol,Release In Response,Denial Of Service,Potential Attacks,Energy Meter,Game Model,Service Requests,Industrial Internet Of Things,Intrusion Detection System,Solid-state Drives,False Data Injection,Distributed Denial Of Service,Separate Libraries,JavaScript Object Notation,File Transfer Protocol
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要