Substation Security Policy Configuration via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart grid substations are vulnerable to cyber-attacks due to their interconnected nature with public and non-public communications networks, making it difficult to determine authorized access and enforce security measures effectively.

Innovation Solution

Implementing behavioral security methods that examine substation configuration files to determine device characteristics and communication patterns, configuring security policies to enforce allowed communications, and using bait stations to detect silent malware, thereby enhancing security and resilience against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If substations are connected to external public and nonpublic networks to facilitate easy access, then network connectivity and accessibility are improved, but security vulnerability to malicious attacks increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security appliances (firewalls, intrusion detection systems, and other security devices) as intermediary components between the substation networks and external public/nonpublic networks. These security appliances act as mediators that filter and monitor traffic, allowing legitimate access while blocking malicious attacks. The security appliances create a buffer zone that maintains network connectivity while protecting against security threats, thus resolving the contradiction between accessibility and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are configured to control device characteristics and communication patterns, then security control capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidsecurity policy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables security appliances to automatically discover substation devices, extract their characteristics from configuration files, and autonomously generate appropriate security policies. The system self-configures security rules based on device types, allowed roles, and communication modes without requiring manual intervention. This automation reduces the complexity of security policy configuration while maintaining strong security control capabilities, as the system performs the complex configuration tasks itself.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If behavioral security methods are implemented to detect anomalies in real-time, then security detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a two-phase security approach: first, during normal operation, the system establishes baseline communication patterns and device behaviors by examining configuration files and learning normal traffic flows. Second, during anomaly detection, the system compares real-time traffic against these pre-established baselines. This preliminary action of creating reference profiles enables faster real-time detection, as the system only needs to check for deviations from known patterns rather than analyzing every packet from scratch, thus reducing processing time while maintaining detection precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2721801B1Security measures for the smart grid
Publication Date: 2019.10.09 CISCO TECHNOLOGY INC
  • EP2721801B1 patent drawingFigure 1
  • EP2721801B1 patent drawingFigure 2
  • EP2721801B1 patent drawingFigure 3

AI summary

Security is enabled in an electrical system by examining a configuration file for a substation present in the electrical system, where the substation includes one or more electrical devices and one or more network devices. Based on the examination of the configuration file, information is determined on a characteristic of an electrical device that is selected from a group including a type, allowed role of the electrical device and allowed communication modes for the electrical device. Based on the determined information, a basis for controlling the role and communication modes for the electrical device is identified. A security policy is configured in a network device in the substation to incorporate the identified basis. Based on the configured security policy in the network device, communication patterns for the electrical device are allowed that are associated with the allowed role and allowed communication modes for the electrical device.