SecuriDN: A Modeling Tool Supporting the Early Detection of Cyberattacks to Smart Energy Systems

Author:

Cerotti Davide12ORCID,Codetta Raiteri Daniele12ORCID,Dondossola Giovanna3ORCID,Egidi Lavinia1ORCID,Franceschinis Giuliana12ORCID,Portinale Luigi12ORCID,Savarro Davide4ORCID,Terruggia Roberta3ORCID

Affiliation:

1. Computer Science Institute, DiSIT, Università del Piemonte Orientale (UPO), 15121 Alessandria, Italy

2. Consorzio Nazionale Interuniversitario per le Telecomunicazioni (CNIT), 43124 Parma, Italy

3. Transmission and Distribution Technologies Department, Ricerca sul Sistema Energetico (RSE S.p.A.), 20134 Milano, Italy

4. Computer Science Department, Università di Torino, 10149 Torino, Italy

Abstract

SecuriDN v. 0.1 is a tool for the representation of the assets composing the IT and the OT subsystems of Distributed Energy Resources (DERs) control networks and the possible cyberattacks that can threaten them. It is part of a platform that allows the evaluation of the security risks of DER control systems. SecuriDN is a multi-formalism tool, meaning that it manages several types of models: architecture graph, attack graphs and Dynamic Bayesian Networks (DBNs). In particular, each asset in the architecture is characterized by an attack graph showing the combinations of attack techniques that may affect the asset. By merging the attack graphs according to the asset associations in the architecture, a DBN is generated. Then, the evidence-based and time-driven probabilistic analysis of the DBN permits the quantification of the system security level. Indeed, the DBN probabilistic graphical model can be analyzed through inference algorithms, suitable for forward and backward assessment of the system’s belief state. In this paper, the features and the main goals of SecuriDN are described and illustrated through a simplified but realistic case study.

Publisher

MDPI AG

Reference59 articles.

1. (2024, July 31). CEI0-16. Norma CEI 0-16:2022-03, Regola Tecnica di Riferimento per la Connessione di Utenti Attivi e Passivi alle reti AT e MT delle Imprese Distributrici di Energia Elettrica. CEI, Milano, Italy. Available online: https://static.ceinorme.it/strumenti-online/doc/18308.pdf.

2. (2024, July 31). CEI0-21. Variante V1 della Norma CEI 0-21:2022-03, Regola Tecnica di Riferimento per la Connessione di Utenti Attivi e Passivi alle reti BT delle Imprese Distributrici di Energia Elettrica CEI, Milano, Italy. Available online: https://static.ceinorme.it/strumenti-online/doc/18066.pdf.

3. (2024, July 31). ISA/IEC 62443. Standard IEC 62443-4-2:2019, Security for Industrial Automation and Control Systems-Part 4-2: Technical Security Requirements for IACS Components IEC, Geneva, Switzerland, 2019. Available online: https://webstore.iec.ch/en/publication/34421.

4. Cerotti, D., Codetta, D., Dondossola, G., Egidi, L., Franceschinis, G., Portinale, L., Savarro, D., and Terruggia, R. (2024, January 9–11). SecuriDN: A Customizable GUI Generating Cybersecurity Models for DER Control Architectures. Proceedings of the Italian Conference on Cybersecurity, ITASEC 2024, Salerno, Italy. Available online: http://ceur-ws.org/Vol-3731/.

5. The meta attack language—A formal description;Hacks;Comput. Secur.,2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3