SCADA MITM Detection via Power Flow Discrepancy Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional IT security tools are inadequate for securing OT networks as they do not consider the integrity of the payload data in SCADA communication, making them vulnerable to man-in-the-middle attacks that can inject false data, compromising the security of power grid operations.
Innovation Solution
A system and method that includes secure substation-substation communication links, substation intelligent boxes for sampling voltage and phase angle measurements, send and capture servers for creating packets with power flow data, and an intrusion detection system server to analyze packets and trigger alarms when power flow discrepancies are detected, ensuring the integrity of OT data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IT security tools (firewall, encryption, IDS, IPS) are used to secure SCADA networks, then network security is improved, but these tools cannot detect man-in-the-middle attacks that inject false data into OT data streams
Solution Approach 1:
The patent introduces an intermediary component (intrusion detection system) that mediates between the OT data stream and the analysis system. This intermediary captures OT data packets, extracts payload information, and enables detection of man-in-the-middle attacks without disrupting the original data flow or requiring changes to existing SCADA infrastructure
Solution Approach 2:
The patent replaces traditional mechanical/network-layer security mechanisms (firewalls, encryption) with an information-based detection approach. Instead of relying on network protocol security, the system substitutes a method that extracts and analyzes payload information to detect anomalies and false data injection attacks
2Measurement precision
If secure substation-substation communication links are implemented with intrusion detection, then detection precision for MITM attacks is improved, but device complexity increases
Solution Approach 1:
The patent extracts only the essential payload information from OT data packets for analysis, rather than processing entire packets or implementing complex security protocols. This extraction approach maintains high detection precision while minimizing the added system complexity by focusing only on critical data elements
Solution Approach 2:
The patent changes the detection parameter from network-layer characteristics to payload-information characteristics. By shifting the detection focus to payload content analysis rather than protocol compliance, the system achieves high detection precision with relatively simple implementation
3Reliability
If comprehensive security measures are deployed across all substations, then power system security is improved, but implementation cost increases
Solution Approach 1:
The patent creates a universal detection mechanism that can be implemented at any substation using existing infrastructure. The intrusion detection system serves multiple functions: detecting MITM attacks, monitoring OT data integrity, and providing security alerts, thereby reducing the need for additional specialized hardware across the power system
Data Source
AI summary
A system for detecting MITM for SCADA communication networks includes secure substation-substation communication links for providing secure and reliable paths to exchange OT data between substations for OT data consistency check; a SIB in each substation for sampling CT and PT measurements to calculate voltage magnitude and phase angle thereof; a S&C server in each substation coupled to the SIB for receiving the voltage magnitude and phase angle from the SIB and obtaining a packet carrying active power flow in transmission lines between two substations and a time stamp; an IDS server placed in a SCADA center for collecting the packet of each substation sent by the S&C server; analyzing the received packet from every adjacent substation; inspecting the payload of the received packet; and triggering an intrusion alarm to a SCADA operator when the power flow is not the same as the payload of the packets.


