Attack Detection and Mitigation Techniques in Industrial Control System -Smart Grid DNP3

Ihab Darwish, Tarek Saadawi · 2018

Detection and mitigation strategies using statistical Bayesian approach is performed to analyze attacks on Distributed Network Protocol 3 (DNP3) environment related to Industrial Control Systems (ICS) and the smart power grid. Our novel approach in this research paper is to create an attack detection model based on the Round Trip Time Delay (RTTD) for DNP3 transactions. Likelihood distribution for both legitimate and hacked transactions are modeled using Bayesian analysis. Both Maximum A Posterior probability (MAP) and the loss functions are utilized to optimize our threshold to ensure an improved attack detection accuracy. Receiver Operating Characteristics (ROC) is also performed to show the effectiveness and the optimally of our detection mechanism.

Read the paper · More papers on PaperTik