Multidimensional Intrusion Detection System for IEC 61850-Based 61850 SCADA Networks
Abstract: Emerging cybersecurity vulnerabilities in supervisory control and data acquisition (SCADA) systems are becoming urgent engineering issues for modern substations. This paper proposes a novel intrusion detection system (IDS) tailored for cybersecurity of IEC 61850 based substatio substations. ns. The proposed IDS integrates physical knowledge, protocol specifications, and logical behaviors to provide a comprehensive and effective solution that is able to mitigate various cyberattacks. The proposed approach comprises access control detection, protocol otocol whitelisting, model model-based based detection, and multiparameter-based multiparameter detection. This SCADA-specific specific IDS is implemented and validated using a comprehensive and realistic cyber cyber-physical test-bed bed and data from a real 500 kV smart substation.