Skip to main content
QUICK REVIEW

[論文レビュー] Power Grid Defense Against Malicious Cascading Failure

Paulo Shakarian, Hansheng Lei|arXiv (Cornell University)|Jan 6, 2014
Smart Grid Security and ResilienceEngineering参考文献 24被引用数 16
ひとこと要約

本稿は、攻撃者が変電所を標的とし、停電の影響を最大化するのに対し、防御者が重要なノードを強化して損傷を最小化する、悪意ある連鎖的障害に対するゲーム理論的モデルを提案する。研究では、決定論的および混合戦略を形式化し、ほとんどの場合でNP困難であることを証明した。また、実験的に、攻撃者が追加リソースを獲得する利点が防御者よりも大きいことが示され、最適な攻撃条件下ではミニマックス防御が単純な負荷ベース戦略を上回ることを示した。

ABSTRACT

An adversary looking to disrupt a power grid may look to target certain substations and sources of power generation to initiate a cascading failure that maximizes the number of customers without electricity. This is particularly an important concern when the enemy has the capability to launch cyber-attacks as practical concerns (i.e. avoiding disruption of service, presence of legacy systems, etc.) may hinder security. Hence, a defender can harden the security posture at certain power stations but may lack the time and resources to do this for the entire power grid. We model a power grid as a graph and introduce the cascading failure game in which both the defender and attacker choose a subset of power stations such as to minimize (maximize) the number of consumers having access to producers of power. We formalize problems for identifying both mixed and deterministic strategies for both players, prove complexity results under a variety of different scenarios, identify tractable cases, and develop algorithms for these problems. We also perform an experimental evaluation of the model and game on a real-world power grid network. Empirically, we noted that the game favors the attacker as he benefits more from increased resources than the defender. Further, the minimax defense produces roughly the same expected payoff as an easy-to-compute deterministic load based (DLB) defense when played against a minimax attack strategy. However, DLB performs more poorly than minimax defense when faced with the attacker's best response to DLB. This is likely due to the presence of low-load yet high-payoff nodes, which we also found in our empirical analysis.

研究の動機と目的

  • 攻撃者と防御者の2人ゲームとして、連鎖的障害に対する電力グリッド防御をモデル化すること。
  • リソース制約下での両者に対する決定論的および混合戦略を形式化すること。
  • さまざまな状況下で最適戦略を求める際の計算複雑性を分析すること。
  • 混合戦略のための二重オラクル手法を含む、スケーラブルなアルゴリズムを開発すること。
  • 実世界の米国電力グリッドネットワーク上でモデルを実証的に評価し、防御戦略を比較すること。

提案手法

  • 発電(供給)ノードと負荷(消費)ノードを含む無向グラフとして電力グリッドをモデル化する。
  • 最短経路中央性を用いてエッジ負荷を定義し、[8]に基づき線路の応力の推定を行うが、供給-負荷ダイナミクスを含めるように拡張する。
  • 過負荷エッジを繰り返し削除する故障オペレータを導入し、連鎖的障害をシミュレートする。
  • 攻撃者が分断された負荷を最大化し、防御者がそれを最小化する連鎖的障害ゲームを定式化する。
  • 線路容量を (1+α) × 初期負荷 として容量マージン α を設定し、余剰容量を模擬する。
  • 防御者のミニマックス混合戦略を計算するために、グリーディヒューリスティクスを組み合わせた二重オラクルアルゴリズムを実装する。

実験結果

リサーチクエスチョン

  • RQ1異なるリソース制約下で、攻撃者および防御者の最適決定論的戦略を求める計算複雑性はいかほどか?
  • RQ2報酬と頑健性の観点から、混合戦略は決定論的戦略と比べてどのように異なるか?
  • RQ3大規模な電力グリッドネットワーク向けに、実行可能なアルゴリズムを開発できるか?
  • RQ4攻撃者のリソース増加に比して、防御者の報酬はどのように変化するか?
  • RQ5低負荷だが高報酬のノードは、さまざまな防御戦略の有効性にどのような役割を果たすか?

主な発見

  • 攻撃者が追加リソースを得る利点が防御者よりも大きい。リソースを1から6に増加させた際、攻撃者の報酬は3倍に増加したが、防御者の報酬は僅か70%の向上にとどまった。
  • ミニマックス防御は、ミニマックス攻撃者に対しては単純な負荷ベース(DLB)防御と同等の性能を示したが、DLBに対する攻撃者の最適反応に直面した際には、DLBを著しく上回った。
  • 低負荷だが高報酬のノードの存在が、最適攻撃戦略に対してDLBがうまく機能しない理由を説明している。
  • 二重オラクルアルゴリズムの実行時間は、線形計画問題および戦略集合の増大に伴い反復ごとに増加し、大規模ネットワークではスケーラビリティに制限が生じる。
  • 実行時間は戦略サイズに比例して増加する(R² = 0.90 ± 0.2)が、最も長い実験でも12日を要しており、最適化の必要性を示している。
  • モデルは攻撃者に有利に働く。攻撃者が追加リソースを得る利点は、防御者が同等の投資で補填できるものよりも大きい。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。