SCADA MITM Detection via Power Flow Discrepancy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IT security tools are inadequate for securing OT networks as they do not consider the integrity of the payload data in SCADA communication, making them vulnerable to man-in-the-middle attacks that can inject false data, compromising the security of power grid operations.

Innovation Solution

A system and method that includes secure substation-substation communication links, substation intelligent boxes for sampling voltage and phase angle measurements, send and capture servers for creating packets with power flow data, and an intrusion detection system server to analyze packets and trigger alarms when power flow discrepancies are detected, ensuring the integrity of OT data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IT security tools (firewall, encryption, IDS, IPS) are used to secure SCADA networks, then network security is improved, but these tools cannot detect man-in-the-middle attacks that inject false data into OT data streams

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection capability against MITM attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component (intrusion detection system) that mediates between the OT data stream and the analysis system. This intermediary captures OT data packets, extracts payload information, and enables detection of man-in-the-middle attacks without disrupting the original data flow or requiring changes to existing SCADA infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/network-layer security mechanisms (firewalls, encryption) with an information-based detection approach. Instead of relying on network protocol security, the system substitutes a method that extracts and analyzes payload information to detect anomalies and false data injection attacks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If secure substation-substation communication links are implemented with intrusion detection, then detection precision for MITM attacks is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential payload information from OT data packets for analysis, rather than processing entire packets or implementing complex security protocols. This extraction approach maintains high detection precision while minimizing the added system complexity by focusing only on critical data elements

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the detection parameter from network-layer characteristics to payload-information characteristics. By shifting the detection focus to payload content analysis rather than protocol compliance, the system achieves high detection precision with relatively simple implementation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security measures are deployed across all substations, then power system security is improved, but implementation cost increases

Engineering Contradiction:
Improvepower system securityVSAvoidhardware quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent creates a universal detection mechanism that can be implemented at any substation using existing infrastructure. The intrusion detection system serves multiple functions: detecting MITM attacks, monitoring OT data integrity, and providing security alerts, thereby reducing the need for additional specialized hardware across the power system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11178176B2Methods and systems for detection of man-in-the-middle attacks for SCADA communication networks and applications of same
Publication Date: 2021.11.16 THE BOARD OF TRUSTEES OF THE UNIV OF ARKANSAS
  • US11178176B2 patent drawing
  • US11178176B2 patent drawing
  • US11178176B2 patent drawing

AI summary

A system for detecting MITM for SCADA communication networks includes secure substation-substation communication links for providing secure and reliable paths to exchange OT data between substations for OT data consistency check; a SIB in each substation for sampling CT and PT measurements to calculate voltage magnitude and phase angle thereof; a S&C server in each substation coupled to the SIB for receiving the voltage magnitude and phase angle from the SIB and obtaining a packet carrying active power flow in transmission lines between two substations and a time stamp; an IDS server placed in a SCADA center for collecting the packet of each substation sent by the S&C server; analyzing the received packet from every adjacent substation; inspecting the payload of the received packet; and triggering an intrusion alarm to a SCADA operator when the power flow is not the same as the payload of the packets.