Title :
SmartAnalyzer: A noninvasive security threat analyzer for AMI smart grid
Author :
Rahman, Mohammad Ashiqur ; Bera, Padmalochan ; Al-Shaer, Ehab
Author_Institution :
Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
Abstract :
The Advanced Metering Infrastructure (AMI) is the core component in smart grid that exhibits highly complex network configurations comprising of heterogeneous cyber-physical components. These components are interconnected through different communication media, protocols, and secure tunnels, and they are operated using different data delivery modes and security policies. The inherent complexity and heterogeneity in AMI significantly increase the potential of security threats due to misconfiguration or absence of defense, which may cause devastating damage to AMI. Therefore, there is a need of creating a formal model that can represent the global behavior of AMI configuration in order to verify the potential threats. In this paper, we present SmartAnalyzer, a formal security analysis tool, which offers manifold contributions: (i) formal modeling of AMI configuration including device configurations, topology, communication properties, interactions between the devices, data flows, and security properties; (ii) formal modeling of AMI invariant and user-driven constraints based on the interdependencies between AMI device configurations, security properties, and security control guidelines; (iii) verifying the AMI configuration´s compliances with security constraints using Satisfiability Modulo Theory (SMT) solver; (iv) generating a comprehensive security threat report with possible remediation plan based on the verification results. The accuracy, scalability, and usability of the tool are evaluated on real smart grid environment and synthetic test networks.
Keywords :
computer network security; power system analysis computing; power system measurement; smart power grids; telecommunication security; AMI device configurations; AMI smart grid; SmartAnalyzer; advanced metering infrastructure; data delivery modes; data flows; formal modeling; heterogeneous cyberphysical components; network configurations; noninvasive security threat analyzer; satisfiability modulo theory solver; secure tunnels; security control guidelines; security policies; synthetic test networks; user driven constraints; Analytical models; Authentication; Network topology; Protocols; Schedules; Smart grids;
Conference_Titel :
INFOCOM, 2012 Proceedings IEEE
Conference_Location :
Orlando, FL
Print_ISBN :
978-1-4673-0773-4
DOI :
10.1109/INFCOM.2012.6195611