Ontology-based approach for malicious behaviour detection in synchrophasor networks

Abdullah Albalushi, Rafiullah Khan, Kieran McLaughlin, Sakir Sezer
2017 2017 IEEE Power & Energy Society General Meeting  
Synchrophasor systems are becoming a vital requirement for real-time monitoring, control and protection of emerging Smart Grids that need cyber security issues be carefully analysed and mitigated. This paper proposes a behaviourbased ontology on the Syncrophasor communications for the detection of malicious system behaviours. Syncrophasor activities are represented with their causal relationships using a flexible semantic model. The developed model bridges the gap between system behaviours and
more » ... he exchanged data and commands in the network. A set of semantic rules are created to assist in identifying malicious activities that are deviating from the expected behaviour in the model. The proposed approach is prototyped and tested for its applicability in detecting cyber-attacks. Furthermore, a use case for valuable information extraction is described using query-based engine over the ontology knowledge. The presented results demonstrate the usefulness and flexibility of the proposed approach in detecting malicious activities that could improve Syncrophasor network security.
doi:10.1109/pesgm.2017.8274684 fatcat:gvtwsa5tnjhs5jkmfzco4i5xve