Differentiation Between Faults and Cyberattacks through Combined Analysis of Cyberspace Logs and Physical Measurements
Mohammad Shamim Ahsan, Haizhou Wang, Venkateswara Reddy Motakatla, Minghui Zhu, and Peng Liu

TL;DR
This paper presents a novel automated approach combining cyber and physical data analysis to accurately differentiate between undetected faults and cyberattacks in DER systems, improving detection and root cause analysis.
Contribution
It introduces a dependency graph construction with PVOTA, node pruning, and pattern matching techniques for integrated cyber-physical analysis, addressing limitations of prior methods.
Findings
Successfully distinguished faults from cyberattacks in case studies
Enhanced accuracy in root cause identification
Reduced manual analysis efforts
Abstract
In recent years, cyberattacks - along with physical faults - have become an increasing factor causing system failures, especially in DER (Distributed Energy Resources) systems. In addition, according to the literature, a number of faults have been reported to remain undetected. Consequently, unlike anomaly detection works that only identify abnormalities, differentiating undetected faults and cyberattacks is a challenging task. Although several works have studied this problem, they crucially fall short of achieving an accurate distinction due to the reliance on physical laws or physical measurements. To resolve this issue, the industry typically conducts an integrated analysis with physical measurements and cyberspace information. Nevertheless, this industry approach consumes a significant amount of time due to the manual efforts required in the analysis. In this work, we focus on…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Software System Performance and Reliability · Network Security and Intrusion Detection
