DocumentCode
1283792
Title
Optimization of Trust System Placement for Power Grid Security and Compartmentalization
Author
Gonzalez, Juan M Carlos ; Hopkinson, Kenneth M. ; Greve, Gabriel H. ; Compton, Matthew D. ; Wilhelm, Joseph ; Kurkowski, Stuart H. ; Thomas, Ryan W.
Author_Institution
Dept. of Electr. & Comput. Eng., Air Force Inst. of Technol., Wright-Patterson AFB, OH, USA
Volume
26
Issue
2
fYear
2011
fDate
5/1/2011 12:00:00 AM
Firstpage
550
Lastpage
563
Abstract
This article proposes a robust mathematical method to strategically place trust nodes to compartmentalize a time-critical SCADA network. The trust nodes combine firewall and intrusion detection technology to provide communication network security for protection, control, and SCADA systems. The mathematical technique optimizes the placement of the trust nodes based on the timing requirements of existing systems and the number of trust nodes that are available in the system given constraints, which may arise due to budgetary limitations or the restrictions of existing utility hardware. The intent is to create a planning tool to allow utility system operators to determine the best locations to place trust nodes to increase system security given limited resources and/or hardware constraints. The operational requirements of the environment are translated into a mathematical model. Mixed integer linear programming is used to process this model in search of an optimal solution. Because the problem is provably NP-Hard, a heuristic is also given to quickly find good, but not optimal, solutions. Experiments show promise for the proposed techniques.
Keywords
SCADA systems; integer programming; linear programming; mathematical analysis; power grids; power system control; power system security; SCADA systems; communication network security; control; firewall; intrusion detection technology; mathematical model; mathematical technique; mixed integer linear programming; power grid compartmentalization; power grid security; protection; time-critical SCADA network; trust system placement; Communication networks; Communication system security; Communications technology; Hardware; Intrusion detection; Power grids; Power system protection; Power system security; Robustness; Time factors; Computer network security; linear programming; power grid; supervisory control and data acquisition (SCADA) system; trust node;
fLanguage
English
Journal_Title
Power Systems, IEEE Transactions on
Publisher
ieee
ISSN
0885-8950
Type
jour
DOI
10.1109/TPWRS.2010.2053725
Filename
5535236
Link To Document