Two-stage advanced persistent threat (APT) attack on an IEC 61850 power grid substation


연구 분야: Networking



학회: International Journal of Information Security


초록

Advanced Persistent Threats (APTs) are stealthy, multi-step attacks tailored to a specific target. Often described as ’low and slow’, APTs remain undetected until the consequences of the cyber-attack become evident, usually in the form of damage to the physical world, as seen with the Stuxnet attack, or manipulation of an industrial process, as was the case in the Ukraine Power Grid attacks. Given the increasing sophistication and targeted nature of cyber-attacks, especially APTs, this paper delves into the substantial threats APTs pose to critical infrastructures, focusing on power grid substations. Through a detailed case study, we present and explore a 2-stage APT attack on an IEC 61850 power grid substation, employing a Hardware-in-the-Loop (HIL) testbed to simulate real-world conditions. More specifically, this paper discusses two significant experiments conducted to assess vulnerabilities in the control protocols used in IEC 61850 substations: IEC 60870-5-104 and IEC 61850. The integration of findings from these experiments revealed a number of previously undiscussed potential threats to power grid infrastructure that could arise from attacking one or more substations. To better address these potential threats, the paper proposes an extension to the Industrial Control System (ICS) kill chain that explicitly accounts for the consequences of attacks on the physical aspects of Cyber-Physical Systems (CPSs).


Author Profile
Aida Akbarzadeh

Dept. of Information Security and Communication Technology Norwegian University of Science and Technology Gjøvik Norway

Andorra
Author Profile
Laszlo Erdodi

Dept. of Information Security and Communication Technology Norwegian University of Science and Technology Trondheim Norway

Andorra
Author Profile
Siv Hilde Houmb

Dept. of Information Security and Communication Technology Norwegian University of Science and Technology Gjøvik Norway

Andorra

📄 논문 정보

발행 연도 2024년
인용수 15
출판 국가 Andorra, Norway
사이트 Springer
좋아요 수 0

연관 논문 목록 (82건)