Power Utility Automation System Monitoring via IED Configuration Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems in electric power systems rely heavily on signature-based blacklists, which are ineffective in detecting new or unknown critical events, limiting their usefulness in identifying security intrusions and other anomalies in power utility automation systems.

Innovation Solution

A monitoring system that uses configuration information to verify the behavior of intelligent electronic devices (IEDs) against a system model, allowing it to detect deviations from expected behavior without relying on pre-defined signatures, and generating alerts for non-conformant data or system status, thereby identifying both known and unknown critical events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based blacklist approach is used for intrusion detection, then known attacks can be detected, but new or unknown attacks cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of using a blacklist approach that only detects known attacks by matching signatures, the patent inverts the approach by using a whitelist model that defines expected legitimate behavior. The system generates a system model specifying valid data messages and their properties, then detects deviations from this model. This inversion allows the system to detect both known and unknown attacks by identifying any behavior that does not conform to the established system model, thereby resolving the contradiction between detection accuracy for known attacks and adaptability to new attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If extensive signature lists are maintained for intrusion detection, then coverage of known threats is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvethreat coverageVSAvoidsignature list management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the core essence of intrusion detection from maintaining extensive signature lists to instead generating a system model that represents the legitimate behavior of the power utility automation system. By taking out the need for comprehensive signature databases and replacing them with a dynamically generated model based on system configuration information, the system achieves threat coverage without the complexity and maintenance burden of managing extensive signature lists.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs self-service by automatically generating the system model using configuration information from the monitored devices themselves. Rather than requiring external maintenance of signature databases, the system creates its own baseline for legitimate behavior by analyzing the configuration data, communication protocols, and operational parameters of the IEDs and other automation devices. This self-generated model reduces dependency on external signature updates and simplifies maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10338111B2Method of monitoring operation of an electric power system and monitoring system
Publication Date: 2019.07.02 OMICRON ELECTRONICS GMBH
  • US10338111B2 patent drawing
  • US10338111B2 patent drawing
  • US10338111B2 patent drawing

AI summary

In a method, operation of an electric power system which has a power utility automation system (1981-1984, 1991-1994) is monitored. The power utility automation system (1981-1984, 1991-1994) comprises a plurality of intelligent electronic devices (IEDs) (1981-1984, 1991-1994) communicating via a communication network. During operation of the electric power system, properties of the electric power system are monitored, the monitored properties comprising monitored data messages which are transmitted by the plurality of IEDs (1981-1984, 1991-1994) over the communication network. The monitored data messages are evaluated based on configuration information for the power utility automation system (1981-1984, 1991-1994) to detect a critical event. An alert signal is generated in response to detection of the critical event.