On Evasion of Machine Learning-based Intrusion Detection in Smart Grids

Aneeqa Mumrez, Gustavo Sánchez, Ghada Elbez, Veit Hagenmeyer · 2023

Artificial intelligence techniques play a significant role in the cybersecurity of smart grids (SGs). Machine learning (ML) algorithms can successfully differentiate between normal behaviour and attacks, even if the anomalies are a by-product of malicious techniques never seen before. However, malicious actors successfully evade ML-based intrusion detection systems (IDSs) with attacks that mimic normal operation. In the present paper, we proactively test ML-based intrusion detection algorithms against adversarial scenarios for a better understanding of malicious capabilities. We start with the implementation of attacks (reconnaissance, data modification on the fly, and denial of service against Modbus TCP) in our testbed at KASTEL Security Lab Energy. Then, we develop a prototype ML-based IDS that monitors Modbus TCP traffic. We explicitly discuss the feasibility of evasion attacks in the problem space of Modbus TCP. Finally, we report our findings and discuss challenges from the attacker’s point of view. Additionally, considering the scarcity of available datasets for effective evaluation of IDS approaches, we release our dataset which includes Modbus TCP network traffic.

Read the paper · More papers on PaperTik