A Firewall Optimization for Threat-Resilient Micro-Segmentation in Power System Networks
Abhijeet Sahu, Patrick Wlazlo, Nastassja Gaudet, Ana Goulart, Edmond, Rogers, and Katherine Davis

TL;DR
This paper introduces a meta-heuristic method to optimize firewall placement and rules for securing power system networks, specifically targeting cyber-physical infrastructure vulnerabilities in critical electric grids.
Contribution
It proposes a novel meta-heuristic approach for optimal security zone formation and a prototype tool for auto-configuring firewalls in large-scale power systems.
Findings
Optimized security perimeters reduce firewall count and costs.
The approach enhances cyber-physical security in power grids.
Results show improved risk management in synthetic 2000-bus models.
Abstract
Electric power delivery relies on a communications backbone that must be secure. SCADA systems are essential to critical grid functions and include industrial control systems (ICS) protocols such as the Distributed Network Protocol-3 (DNP3). These protocols are vulnerable to cyber threats that power systems, as cyber-physical critical infrastructure, must be protected against. For this reason, the NERC Critical Infrastructure Protection standard CIP-005-5 specifies that an electronic system perimeter is needed, accomplished with firewalls. This paper presents how these electronic system perimeters can be optimally found and generated using a proposed meta-heuristic approach for optimal security zone formation for large-scale power systems. Then, to implement the optimal firewall rules in a large scale power system model, this work presents a prototype software tool that takes the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Packet Processing and Optimization · Smart Grid Security and Resilience · Network Security and Intrusion Detection
