 
 
    Please use this identifier to cite or link to this item:
    
    
    https://dspace.iiti.ac.in/handle/123456789/13510
Full metadata record
| DC Field | Value | Language | 
|---|---|---|
| dc.contributor.author | Barsha, Nisha Kumari | en_US | 
| dc.contributor.author | Hubballi, Neminath | en_US | 
| dc.date.accessioned | 2024-04-26T12:42:54Z | - | 
| dc.date.available | 2024-04-26T12:42:54Z | - | 
| dc.date.issued | 2024 | - | 
| dc.identifier.citation | Barsha, N. K., & Hubballi, N. (2024). Anomaly Detection in SCADA Systems: A State Transition Modeling. IEEE Transactions on Network and Service Management. Scopus. https://doi.org/10.1109/TNSM.2024.3373881 | en_US | 
| dc.identifier.issn | 1932-4537 | - | 
| dc.identifier.other | EID(2-s2.0-85187407129) | - | 
| dc.identifier.uri | https://doi.org/10.1109/TNSM.2024.3373881 | - | 
| dc.identifier.uri | https://dspace.iiti.ac.in/handle/123456789/13510 | - | 
| dc.description.abstract | Smart-Grid networks use Supervisory Control and Data Acquisition (SCADA) systems to bring measurement data from sensory nodes. These measurements drive the control decisions which are safety critical operations. SCADA communications now happen over TCP/IP networks and hence are susceptible to cyber attacks. As smart-grid is a critical infrastructure, it is essential to detect these cyber attacks. In this direction, our contributions in this paper are two-fold. First, we present three broad classes of network anomalies namely single message anomaly, message sequencing anomaly, and time based anomaly. We show that several cyber attacks in smart-grid networks can be detected by identifying these three types of anomalies. Second, we describe a novel state transition machine based model for identifying these three types of anomalies and hence different cyber attacks in smart-grid networks. Our state transition based model Deterministic Counting Timed Automata (DCTA) formalizes constraints on message attributes, timing of events, and counter values associated with states to detect these anomalies. We experiment with a publicly available dataset and show that DCTA is capable of detecting various cyber attacks with 100% detection rate in the best case for most of the attacks considered. We also benchmark its performance with recent methods found in the literature. IEEE | en_US | 
| dc.language.iso | en | en_US | 
| dc.publisher | Institute of Electrical and Electronics Engineers Inc. | en_US | 
| dc.source | IEEE Transactions on Network and Service Management | en_US | 
| dc.subject | Anomaly Detection | en_US | 
| dc.subject | Cyber Attacks | en_US | 
| dc.subject | SCADA | en_US | 
| dc.subject | Smart-Grid Networks | en_US | 
| dc.subject | State Transition Model | en_US | 
| dc.title | Anomaly Detection in SCADA Systems: A State Transition Modeling | en_US | 
| dc.type | Journal Article | en_US | 
| Appears in Collections: | Department of Computer Science and Engineering | |
Files in This Item:
There are no files associated with this item.
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.
Altmetric Badge:
            	
                
    
            
