• DocumentCode
    1830030
  • Title

    Possibilistic decision trees for Intrusion Detection in IEC61850 automated substations

  • Author

    Premaratne, Upeka ; Ling, Charles ; Samarabandu, Jagath ; Sidhu, Tarlochan

  • Author_Institution
    Univ. of Moratuwa, Moratuwa, Sri Lanka
  • fYear
    2009
  • fDate
    28-31 Dec. 2009
  • Firstpage
    204
  • Lastpage
    209
  • Abstract
    This paper details the use of possibilistic decision trees for a lightweight Intrusion Detection System (IDS) to be used in Intelligent Electronic Devices (IEDs) of IEC61850 automated electric substations. Traffic data is captured by performing simulated attacks on IEDs. Data is obtained for two types of genuine user activity and two types of common malicious attacks on IEDs. The genuine user activity includes, casual browsing of IED data and downloading of IED data while a Ping flood Denial of Service (DoS) and password crack attack are performed for malicious attacks. Classification is done using possibilistic decision trees for the logarithmic histogram of the time difference between the arrival of two consecutive packets. The main contribution of this paper is the use of non-specificity for obtaining a continuous valued possibilistic decision tree and its cut points. It also includes the use of mean distance metrics to obtain the possibility distribution for the real attack data.
  • Keywords
    decision trees; power engineering computing; security of data; substation automation; IEC61850 automated electric substations; Ping flood denial of service; continuous valued possibilistic decision tree; in intelligent electronic devices; lightweight intrusion detection system; logarithmic histogram; malicious attacks; mean distance metrics; password crack attack; Computer crime; Decision trees; Floods; Intrusion detection; Protocols; Security; Substation automation; Switches; Telecommunication traffic; Traffic control; IEC61850; Information security; decision trees; intrusion detection; possibilistic decision trees; scale invariance; self similarity;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Industrial and Information Systems (ICIIS), 2009 International Conference on
  • Conference_Location
    Sri Lanka
  • Print_ISBN
    978-1-4244-4836-4
  • Electronic_ISBN
    978-1-4244-4837-1
  • Type

    conf

  • DOI
    10.1109/ICIINFS.2009.5429863
  • Filename
    5429863