How to Find out What's Going on in Encrypted Smart Meter Networks - without Decrypting Anything


연구 분야: Infrastructure



학회: ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security


초록

Smart meter networks are part of the critical infrastructure and therefore central to IT security consideration. Besides various forms of access control a permanent monitoring of the network traffic is of utmost importance to the detection of malicious activities taking place. Such monitoring must happen in real time and should possibly be implementable everywhere in the network. These requirements do not allow for the decryption of the network traffic. The paper describes a method by which network packets can be assigned to use cases common in smart meter infrastructures without the need for decryption. It is based solely on metadata and reliably can establish the relationship between a network packet and a use case. The information calculated with this method can be used to detect packets that are not pertaining to any of the allowed use cases and hence are highly suspicious. Moreover, the execution of use cases not initiated by the central server become evident, too, and should raise corresponding alerts. The method was implemented as a proof-of-concept and tested in the real-world environment of a medium-sized city.


Author Profile
Oliver Eigner

Department of Computer Science and Security St. Pölten University of Applied Sciences Austria

Andorra
Author Profile
Hubert Schölnast

Department of Computer Science and Security St. Pölten University of Applied Sciences Austria

Andorra
Author Profile
Paul Tavolato

Faculty of Computer Science University of Vienna Austria

Austria

📄 논문 정보

발행 연도 2024년
인용수 1
출판 국가 Andorra, Austria
사이트 ACM
좋아요 수 0

연관 논문 목록 (275건)