基于攻击重构的实时计量基础设施攻击检测

REAL-TIME METERING INFRASTRUCTURE ATTACK DETECTION BASED ON ATTACK RECONSTRUCTION

  • 摘要: 为了降低误报率,提高实际应用的扩展性,提出一种基于攻击重构的实时智能计量基础设施两层攻击检测方法。其中:第一层使用总功耗数据的谐波平均值与算术平均值比率度量,以识别时间序列行为中的差异;第二层使用比率曲线度量下的残差之和来确认第一层中的差异是否与攻击有关。该攻击重构方案使用所提出度量的方向、符号和大小的观测变化,将签名与不同的攻击类型相关联,从而指导站点安全员或要求控制机制做出适当的响应。在两个真实AMI(Advanced Metering Infrastructure)数据集上的实验结果验证了该方法的有效性。

     

    Abstract: In order to reduce the false alarm rate and improve the scalability of practical application, a real-time advanced metering infrastructure attack detection method with two layers based on attack reconstruction is proposed. The first layer used the ratio of harmonic mean to arithmetic mean of total power consumption data to identify differences in time series behavior. The second layer used the sum of residuals under the ratio curve measurement to confirm whether the difference in the first layer was related to the attack. The attack reconstruction scheme used the observed changes of the direction, symbol and size of the proposed measurement to associate the signature with different attack types, so as to guide the site security officer or require the control mechanism to make an appropriate response. The experimental results of two real AMI (Advanced Metering Infrastructure) datasets show the effectiveness of the proposed method.

     

/

返回文章
返回