Digital Substation Decoy Network for Bogus MAC ID Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IEC 61850 standard does not specify security features to address cyber threats on substation communication networks, making them vulnerable to attacks that can manipulate protection systems and cause grid failures.
Innovation Solution
Implementing a decoy network that mimics the substation communication network, using bogus MAC IDs to detect and divert malicious attacks, and replicating the behavior of critical communication layers to deceive attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If the substation communication network uses standard IEC 61850 protocols for digital communication, then the automation and digitalization of power grid operations is improved, but the network becomes vulnerable to cyber attacks that can manipulate protection systems
Solution Approach 1:
The patent creates a decoy network that is a copy of the real substation communication network. The decoy network includes fake IEDs, fake switching devices, and fake communication protocols that mirror the actual network structure. When attackers probe the network, they interact with the decoy instead of the real critical infrastructure, thereby protecting the actual network from cyber attacks while maintaining the digitalization benefits.
Solution Approach 2:
The decoy network acts as an intermediary layer between attackers and the real substation communication network. It absorbs attack traffic and provides false information to attackers, preventing direct access to critical systems. This intermediary structure allows the automated digital network to operate securely by shielding the real infrastructure from harmful cyber activities.
2Ease of operation
If remote access is enabled for control and maintenance operations, then the ease of operation and maintenance is improved, but the risk of unauthorized control attacks increases
Solution Approach 1:
The decoy network provides a fake remote access interface that mirrors the real network's accessibility. Attackers can connect to the decoy through remote access channels, but they only interact with counterfeit systems. This protects the real remotely accessible systems while maintaining the ease of remote operation for authorized users.
Solution Approach 2:
The patent converts the vulnerability of remote access into a benefit by using the decoy network to attract and neutralize attack traffic. The decoy's fake remote access interface lures attackers away from real systems, transforming the risk of remote access into a protective mechanism that shields critical infrastructure while preserving legitimate remote maintenance capabilities.
3Ease of operation
If the network uses unencrypted communication channels as recommended by IEC 62351, then the ease of data transmission is improved, but the network becomes vulnerable to packet manipulation and data theft
Solution Approach 1:
The decoy network replicates the unencrypted communication structure of the real network, providing attackers with a target that uses the same vulnerable protocols. However, since the decoy contains fake data and fake IEDs, any packet manipulation or data theft attempts result in interacting with counterfeit systems rather than real critical infrastructure, thereby maintaining transmission efficiency while neutralizing the vulnerability risk.
Data Source
AI summary
The present disclosure relates to securing digital substation. A switching node is configured to connect a decoy network and a substation communication network. Further, a plurality of bogus medium access control (MAC) IDs are created that resembles similar to a plurality of critical media access control (MAC) IDs exchanged between a plurality of intelligent electronic devices (IEDs) present in the substation communication network. Furthermore, the plurality of bogus MAC IDs are provided to the decoy network for communicating with the alien device. In this way, one or more malicious attack requests received from the alien device are detected. Further, the switching node may switch the substation network to the decoy network for displaying a set of bogus MAC IDs to the alien device depending on type of the one or more malicious attack requests.


