Skip to main content
QUICK REVIEW

[論文レビュー] Co-Simulation Framework For Network Attack Generation and Monitoring

Oceane Bel, Joonseok Kim|arXiv (Cornell University)|Jun 30, 2023
Distributed and Parallel Computing SystemsComputer Science被引用数 3
ひとこと要約

本稿では、GridLAB-D、HELICS、NS-3 を統合したコンテナ化された共同シミュレーションフレームワークであるNATI[P]Gを提示する。これにより、ハードウェアを要せず、リアルなサイバー物理的電力系統のシミュレーションが可能となる。アプリケーション層でのDNP3プロトコルを用いたミドルマンインザミドル(Man-in-the-Middle)攻撃を実証し、グリッドフォーミングインバーターが攻撃下でもより安定した制御を示し、最適化されたコンデンサおよび発電機設定により、系統分離後2分以内に周波数を回復させられることを示した。

ABSTRACT

Resilience assessment is a critical requirement of a power grid to maintain high availability, security, and quality of service. Most grid research work that is currently pursued does not have the capability to have hardware testbeds. Additionally, with the integration of distributed energy resources, the attack surface of the grid is increasing. This increases the need for reliable and realistic modeling techniques that are usable by the wider research community. Therefore, simulation testbeds have been used to model a real-world power grid topology and measure the impact of various perturbations. Existing co-simulation platforms for powergrid focus on a limited components of the overall system, such as focusing only on the dynamics of the physical layer. Additionally a significant number of existing platforms need specialized hardware that may be too expensive for most researchers. Finally, not many platforms support realistic modeling of the communication layer, which requires use of Supervisory Control and Data Acquisition communication protocol such as DNP3 while modeling cybersecurity scenarios. We present Network Attack Testbed in [Power] Grid (NATI[P]G), (pronounced natig), a standalone, containerized, and reusable environment to enable cyber analysts and researchers to run different cybersecurity and performance scenarios on powergrid. Our tool combines GridLAB-D, a grid simulator, HELICS, a co-simulation framework, and NS-3, a network simulator, to create an end-to-end simulation environment for the power grid. We demonstrate use cases by generating a library of datasets for several scenarios. These datasets can be used to detect cyberattacks at the cyber layer, and develop counter measures to these adverse scenarios.

研究の動機と目的

  • 通信層のリアルなモデリングを支援する、アクセス可能なエンドツーエンドの共同シミュレーションプラットフォームの不足に対処すること。
  • 高価または専用のハードウェアを必要とせず、分布系統における高度なサイバー攻撃(特にアプリケーション層)をシミュレート・分析できる環境を提供すること。
  • マイクログリッドおよび分布系統向けに、多様なサイバーセキュリティおよびレジリエンス評価シナリオをサポートする再利用可能なコンテナ化テストベッドを開発すること。
  • サイバーインシデント検出、リスク評価、緩和戦略開発の下流研究を支援するため、シミュレートされた攻撃シナリオからのベンチマークデータセットを提供すること。
  • 周波数安定性やインバーター応答を含む、現実の系統挙動を、敵対的条件下でもモデリング可能な可能性を実証すること。

提案手法

  • 電力系統のダイナミクスをモデリングするためのGridLAB-D、ネットワークレベルの通信および攻撃シミュレーションのためのNS-3、およびシミュレータ間の時刻とデータ同期のためのHELICSを統合する。
  • NS-3でDNP3プロトコルコマンド(例:PrefおよびQrefの値を変更)を用いて、インバーター制御へのサイバー侵入を模擬するアプリケーション層でのミドルマンインザミドル攻撃を実装する。
  • 星型およびリング型のトポロジーを含む、グリッド構造を定義するトポロジー設定ファイルを用いて、異なるネットワーク構成における攻撃影響を評価する。
  • Dockerを用いたコンテナ化により、研究者が単体で再利用可能かつポータブルな環境としてNATI[P]Gをデプロイできるようにする。
  • 系統分離イベントをシミュレートし、さまざまな制御パrameter設定下での周波数偏差および電圧安定性を測定する。
  • シミュレータから得た時系列データセットを収集・分析し、攻撃誘発の異常を検出するとともに、緩和戦略の評価を実施する。
Figure 1 : Overview of the co-simulation environment with interactions between HELICS, GridLAB-D and NS3. Each node uses the DNP3 protocol to communicate. The control center, where the Open Platform Communications (OPC) server is located, is responsible for control a region of the grid network. The
Figure 1 : Overview of the co-simulation environment with interactions between HELICS, GridLAB-D and NS3. Each node uses the DNP3 protocol to communicate. The control center, where the Open Platform Communications (OPC) server is located, is responsible for control a region of the grid network. The

実験結果

リサーチクエスチョン

  • RQ1ミドルマンインザミドル攻撃中、制御パrameter(PrefおよびQref)が操作された場合、グリッドフォロwingインバーターとグリッドフォーミングインバーターの応答にどのような差が生じるか?
  • RQ2マイクログリッドがサイバー攻撃によって分離された場合、周波数偏差を最小限に抑えるために、発電機およびコンデンサのパrameter設定をどのように最適化できるか?
  • RQ3専用ハードウェアを要せず、共同シミュレーションフレームワーク内でリアルなDNP3ベースのアプリケーション層攻撃を効果的にモデリングおよびシミュレートできるか?
  • RQ4ネットワークトポロジー(例:星型対リング型)は、分布系統におけるサイバー誘発擾乱の伝播および検出にどのように影響するか?
  • RQ5NATI[P]Gフレームワークは、再現可能でデータ豊富なデータセットをどれほど生成できるか?そのデータセットは、サイバー・レジリエンスモデルのトレーニングおよび検証に適しているか?

主な発見

  • グリッドフォーミングインバーターは、操作されたPrefおよびQref値に対して優れたレジリエンスを示し、攻撃前のレベルまで出力電圧を正常に回復させた。一方、グリッドフォロwingインバーターは不安定化にさらされやすかった。
  • 発電機出力を300 kWに低下させ、コンデンサ容量を相あたり600 kVArに増加させた場合、系統分離後約2分で周波数が正常値に回復した。これは、効果的な緩和策であることを示している。
  • 星型およびリング型トポロジーの両方で、同じ最適化された発電機およびコンデンサ設定が類似した周波数回復を達成した。これは、緩和戦略のスケーラビリティを示している。
  • インバーター42に接続された負荷での電流測定値は、攻撃下でより大きなピークと低い谷を示し、星型トポロジーで観察されたパターンと一致した。これは、一貫した攻撃シグネチャを示している。
  • 系統分離時の周波数応答は、初期に上昇し、その後ゆっくり上昇し、約140秒で安定化した。これは、攻撃下での動的システム回復を示している。
  • フレームワークは、リアルタイムのデータストリームにおけるサイバー攻撃誘発の異常を効果的に検出でき、データ駆動型インシデント検出システムの開発を支援した。
Figure 2 : Microgrid setup for experimentation, using the IEEE feeder model as described by Ashok et al. [ 8 ] . We use this setup to run the cyber attacks and collect data on how the attacks impact the performance of the power grid. The attack conducts a man-in-the-middle attack on two inverters in
Figure 2 : Microgrid setup for experimentation, using the IEEE feeder model as described by Ashok et al. [ 8 ] . We use this setup to run the cyber attacks and collect data on how the attacks impact the performance of the power grid. The attack conducts a man-in-the-middle attack on two inverters in

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。