Tracking Real-time Anomalies in Cyber-Physical Systems Through Dynamic Behavioral Analysis
Prashanth Krishnamurthy, Ali Rasteh, Ramesh Karri, Farshad Khorrami

TL;DR
This paper introduces a real-time anomaly detection framework for cyber-physical systems like smart grids, using semantic analysis of network packets and temporal logic to identify and localize cyber-attacks effectively.
Contribution
A novel real-time monitoring method combining semantic event extraction with temporal logic evaluation for anomaly detection in power system CPS.
Findings
Effective detection of cyber-attacks on power systems
High accuracy in anomaly localization
Validated on hardware-in-the-loop testbed
Abstract
Increased connectivity and remote reprogrammability/reconfigurability features of embedded devices in current-day power systems (including interconnections between information technology -- IT -- and operational technology -- OT -- networks) enable greater agility, reduced operator workload, and enhanced power system performance and capabilities. However, these features also expose a wider cyber-attack surface, underscoring need for robust real-time monitoring and anomaly detection in power systems, and more generally in Cyber-Physical Systems (CPS). The increasingly complex, diverse, and potentially untrustworthy software and hardware supply chains also make need for robust security tools more stringent. We propose a novel framework for real-time monitoring and anomaly detection in CPS, specifically smart grid substations and SCADA systems. The proposed method enables real-time signal…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Network Security and Intrusion Detection · Anomaly Detection Techniques and Applications
