Grid-STIX: A STIX 2.1-Compliant Cyber-Physical Security Ontology for Power Grid
Benjamin Blakely, Daniel Karcz

TL;DR
Grid-STIX is a comprehensive, open-source cybersecurity ontology tailored for power grids, extending STIX 2.1 to include physical assets, cyber-physical relationships, and nuclear safeguards, enabling advanced threat modeling and risk assessment.
Contribution
It introduces a modular, domain-specific extension of STIX 2.1 for electrical power grid cybersecurity, covering physical, cyber, and cyber-physical assets and relationships.
Findings
Validated through use cases in threat sharing and risk assessment.
Supports nuclear safeguards and non-proliferation verification.
Provides tools for visualization and Python code generation.
Abstract
Modern electrical power grids represent complex cyber-physical systems requiring specialized cybersecurity frameworks beyond traditional IT security models. Existing threat intelligence standards such as STIX 2.1 and MITRE ATT\&CK lack coverage for grid-specific assets, operational technology relationships, and cyber-physical interdependencies essential for power system security. We present Grid-STIX, a domain-specific extension of STIX 2.1 for electrical grid cybersecurity applications. Grid-STIX employs a modular architecture encompassing physical assets, operational technology components, cyber-physical relationships, and security policies that capture modern power systems including distributed energy resources, advanced metering infrastructure, and nuclear energy facilities. The framework provides threat modeling capabilities through systematic representation of attack patterns,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Information and Cyber Security · Power Systems and Technologies
