Evidence Theory based Decision Fusion for Masquerade Detection in IEC61850 Automated Substations
Upeka Kanchana Premaratne, Jagath K. Samarabandu, Tarlochan Sidhu, Bob Beresh, Jiancheng Tan · 2008
This paper details the use of decision fusion from the outputs of different types of classifiers used for analyzing network traffic to detect masquerading within an IEC61850 automated substation. Data on network traffic is collected under simulated scenarios of a genuine user casually browsing data and an attacker rapidly downloading restricted data. The logarithm of the time difference between two successive packets is calculated and the histogram of this is used for classification using support vector machines and nearest neighbor classifiers. Decision fusion of the outputs of the best classifiers is done using evidence theory and possibility theory in order to reduce the number of input data and increase the reliability.