王坤, 苏盛, 左剑, 李鸿鑫, 刘亮, 王冬青, 赵奕. 变电站自动化系统扰动同步协同攻击及防护分析[J]. 电网技术, 2021, 45(11): 4452-4460. DOI: 10.13335/j.1000-3673.pst.2021.0603
引用本文: 王坤, 苏盛, 左剑, 李鸿鑫, 刘亮, 王冬青, 赵奕. 变电站自动化系统扰动同步协同攻击及防护分析[J]. 电网技术, 2021, 45(11): 4452-4460. DOI: 10.13335/j.1000-3673.pst.2021.0603
WANG Kun, SU Sheng, ZUO Jian, LI Hongxin, LIU Liang, WANG Dongqing, ZHAO Yi. Synchronous Disturbance Coordinated Attack and Analysis of Defense for Substation Automation System[J]. Power System Technology, 2021, 45(11): 4452-4460. DOI: 10.13335/j.1000-3673.pst.2021.0603
Citation: WANG Kun, SU Sheng, ZUO Jian, LI Hongxin, LIU Liang, WANG Dongqing, ZHAO Yi. Synchronous Disturbance Coordinated Attack and Analysis of Defense for Substation Automation System[J]. Power System Technology, 2021, 45(11): 4452-4460. DOI: 10.13335/j.1000-3673.pst.2021.0603

变电站自动化系统扰动同步协同攻击及防护分析

Synchronous Disturbance Coordinated Attack and Analysis of Defense for Substation Automation System

  • 摘要: 国家支持型网络攻击可经供应链攻击等方式渗透侵入变电站自动化系统,进而以逻辑炸弹的形式,通过多个变电站的无站间通信扰动同步协同跳闸攻击,达成最大化破坏后果的目的。首先分析了变电站跳闸攻击实现方式;在此基础上,提出基于扰动同步的多变电站无站间通信协同机制,分析了采用节点低电压表征扰动时的攻击协同方式;采用IEEE 39节点系统进行以节点低电压为触发机制的扰动同步协同攻击仿真分析。仿真结果表明,采用适当的低电压阈值作为攻击协同判据,线路跳闸等初始故障可触发故障点邻近变电站中恶意软件的低电压逻辑,造成变电站跳闸失压、并可能以多个变电站主动连锁跳闸的方式导致大量变电站失压,触发大停电。最后结合电力监控系统入网检测流程,讨论变电站监控系统中扰动同步协同攻击恶意软件的检测方法。

     

    Abstract: State supported cyber-attack can intrude into substations automation systems via vendor of control and monitoring system by supply chain attack. It could initiate synchronous disturbance coordinated cyber-attack to trip all circuit breakers within multiple substations without communication among substation, and trigger blackout to maximize the consequence of cyber-attack. The way of switch attack of substation is analyzed. A disturbance based coordination mechanism is proposed to synchronize cyber- attack in various substations. Synchronous disturbance coordinated cyber-attack with under-voltage is simulated with IEEE 39 node system. Simulation result indicates that short circuit fault could trigger targeted malware in neighboring substations and result in proactive cascade outage of multiple substations or even catastrophic blackout. The way to detect undermined targeted malware coordinated by disturbance in substations automation system is proposed in the end.

     

/

返回文章
返回