Search arXivSearch

arXiv · 1011.1828

A Cyber Security Study of a SCADA Energy Management System: Stealthy Deception Attacks on the State Estimator

Abstract

The electrical power network is a critical infrastructure in today's society, so its safe and reliable operation is of major concern. State estimators are commonly used in power networks, for example, to detect faulty equipment and to optimally route power flows. The estimators are often located in control centers, to which large numbers of measurements are sent over unencrypted communication channels. Therefore cyber security for state estimators becomes an important issue. In this paper we analyze the cyber security of state estimators in supervisory control and data acquisition (SCADA) for energy management systems (EMS) operating the power network. Current EMS state estimation algorithms have bad data detection (BDD) schemes to detect outliers in the measurement data. Such schemes are based on high measurement redundancy. Although these methods may detect a set of basic cyber attacks, they may fail in the presence of an intelligent attacker. We explore the latter by considering scenarios where stealthy deception attacks are performed by sending false information to the control center. We begin by presenting a recent framework that characterizes the attack as an optimization problem with the objective specified through a security metric and constraints corresponding to the attack cost. The framework is used to conduct realistic experiments on a state-of-the-art SCADA EMS software for a power network example with 14 substations, 27 buses, and 40 branches. The results indicate how state estimators for power networks can be made more resilient to cyber security attacks.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

André Teixeira, György Dán, Henrik Sandberg, Karl H. Johansson. 2010-11-08. A Cyber Security Study of a SCADA Energy Management System: Stealthy Deception Attacks on the State Estimator. https://arxiv.org/abs/1011.1828

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Dynamic Programming-Compatible Uncertainty Sets in Robust Markov Decision Processes

In this paper, we investigate the compatibility of robust Markov Decision Processes (RMDPs) with dynamic programming under various assumptions on the uncertainty set, i.e., we investigate when one can solve an RMDP by solving a fixed point equation. We show that in all generality, s-rectangular and sa-rectangular uncertainty sets are the only models of uncertainty that are compatible with dynamic programming. Our analysis shows that existing non-rectangular models, including r-rectangularity, are only weakly compatible with dynamic programming, as they require the assumption that rewards do not depend on the next state. In this case, our results imply that one can always construct a rectangular uncertainty set that is equivalent, for both policy evaluation and optimization, to the dynamic programming-compatible non-rectangular model. This highlights a key limitation: dynamic-programming-compatible non-rectangular uncertainty sets, although practically relevant for uncertainty quantification, do not provide a genuinely distinct assessment of policy performance. Interestingly, our proof techniques rely on identifying a novel simultaneous solvability property, which we show is central to several important properties of RMDPs, including the existence of stationary optimal policies and dynamic programming-based formulations. The simultaneous solvability property enables a unified approach to studying all existing models of uncertainty, rectangular and non-rectangular alike.

math.OC

A simple and practical adaptive trust-region method

We present an adaptive trust-region method for unconstrained optimization that allows inexact solutions to the trust-region subproblems. Our method is a simple variant of the classical trust-region method of Ssorensen. The method achieves the best possible convergence bound up to an additive logarithmic term for finding an $ε$-approximate stationary point, i.e., $O( Δ_f L^{1/2} ε^{-3/2}) + \tilde{O}(1)$ iterations, where $L$ is the Lipschitz constant of the Hessian, $Δ_f$ is the optimality gap, and $ε$ is the termination tolerance for the gradient norm. This improves over existing trust-region methods whose worst-case bound is at least a factor of $L$ worse. We compare our performance with state-of-the-art trust-region (TRU) and cubic regularization (ARC) methods from the GALAHAD library on the CUTEst benchmark problems with at least 100 variables. We also compare with the recently developed Universal trust-region (UTR) method, using the same subproblem solver. In terms of shifted geometric mean of wall-clock times our method's is between $1.2\times$ and $2\times$ faster. We report similar improvements for number of function evaluations, factorizations, gradient evaluations and Hessian evaluations. Compared to the conference version of this paper, our revised method includes several practical enhancements. These modifications dramatically improved performance, including almost an order of magnitude reduction in the shifted geometric mean of wall-clock times. We also show that it suffices for the function to be continuously twice-differentiable to guarantee that either the minimum gradient norm converges to zero or the objective value tends towards negative infinity, even when the iterates diverge.

math.OC

Rough Stochastic Pontryagin Maximum Principle and an Indirect Shooting Method

We derive first-order Pontryagin optimality conditions for stochastic optimal control with deterministic controls for systems modeled by rough differential equations (RDE) driven by Gaussian rough paths. This Pontryagin Maximum Principle (PMP) applies to systems following stochastic differential equations (SDE) driven by Brownian motion, yet it does not rely on forward-backward SDEs and involves the same Hamiltonian as the deterministic PMP. The proof consists of first deriving various integrable error bounds for solutions to nonlinear and linear RDEs by leveraging recent results on Gaussian rough paths. The PMP then follows using standard techniques based on needle-like variations. As an application, we propose the first indirect shooting method for nonlinear stochastic optimal control and show that it converges 10x faster than a direct method on a stabilization task.

math.OC