Research on Power Terminal Attack Detection Technology Based on ATT&CK Multi-modal Perception


연구 분야: Safety



학회: CNSCT '24: Proceedings of the 2024 3rd International Conference on Cryptography, Network Security and Communication Technology


초록

There are a large number of power terminals and complex environments, facing prominent attack risks, which are related to the safe operation of the entire power grid. This paper proposes a power terminal attack detection technology based on the ATT&CK framework, which analyzes and detects attack behaviors through multi-modal perception. Collect attack-related data from various power terminals, combine it with the Bayesian framework to determine the attack technology, map the attack stages and realize the reconstruction of the attack path and the prediction of the attack target. Finally, the technology is applied through the data lake and microservice fusion architecture. This paper proposes a fusion method of attack data in electric power information network, solves the problem of correlation between the ATT&CK framework and the attack process, and expands the attack behavior detection capability of multi-source data fusion.


Author Profile
Rui Wang

Operation and Maintenance Management Dept. Information Communication Branch of State Grid Corporation of China China

Andorra
Author Profile
Xiaoying Zou

Operation and Maintenance Management Dept. Information Communication Branch of State Grid Corporation of China China

Andorra
Author Profile
Yaxi Li

Operation and Maintenance Management Dept. Information Communication Branch of State Grid Corporation of China China

Andorra

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Andorra
사이트 ACM
좋아요 수 0

연관 논문 목록 (108건)