An intrusion detection framework for the smart grid
Imtiaz Ullah, Qusay H. Mahmoud · 2017
Conventional power network capabilities have improved and enhanced by the smart grid but at the same time making it more vulnerable to different types of attacks. These vulnerabilities allow an attacker to breakdown integrity and confidentiality and permit access to the network. Intrusion Detection System (IDS) is one of the significant ways to provide secure and reliable services in a smart grid environment. In this paper, we propose intrusion detection framework for the smart grid. We consider the three-layer architecture of smart grid system. The proposed framework has an IDS in each HAN and NAN and many IDS sensors in WAN. Any malicious activity will be sent to the central management unit; the central management unit correlates and investigates alerts produced by various distributed sensors using anomaly based detection methodology. IDS management system will collect and preprocess the alerts of all sensors and correlate these alerts to distinguish symptoms of attack and contravention of security policy. The ISCX2012 dataset was used to analyze and select the most efficient classifier for anomaly based intrusion detection.