Title :
Possibilistic decision trees for Intrusion Detection in IEC61850 automated substations
Author :
Premaratne, Upeka ; Ling, Charles ; Samarabandu, Jagath ; Sidhu, Tarlochan
Author_Institution :
Univ. of Moratuwa, Moratuwa, Sri Lanka
Abstract :
This paper details the use of possibilistic decision trees for a lightweight Intrusion Detection System (IDS) to be used in Intelligent Electronic Devices (IEDs) of IEC61850 automated electric substations. Traffic data is captured by performing simulated attacks on IEDs. Data is obtained for two types of genuine user activity and two types of common malicious attacks on IEDs. The genuine user activity includes, casual browsing of IED data and downloading of IED data while a Ping flood Denial of Service (DoS) and password crack attack are performed for malicious attacks. Classification is done using possibilistic decision trees for the logarithmic histogram of the time difference between the arrival of two consecutive packets. The main contribution of this paper is the use of non-specificity for obtaining a continuous valued possibilistic decision tree and its cut points. It also includes the use of mean distance metrics to obtain the possibility distribution for the real attack data.
Keywords :
decision trees; power engineering computing; security of data; substation automation; IEC61850 automated electric substations; Ping flood denial of service; continuous valued possibilistic decision tree; in intelligent electronic devices; lightweight intrusion detection system; logarithmic histogram; malicious attacks; mean distance metrics; password crack attack; Computer crime; Decision trees; Floods; Intrusion detection; Protocols; Security; Substation automation; Switches; Telecommunication traffic; Traffic control; IEC61850; Information security; decision trees; intrusion detection; possibilistic decision trees; scale invariance; self similarity;
Conference_Titel :
Industrial and Information Systems (ICIIS), 2009 International Conference on
Conference_Location :
Sri Lanka
Print_ISBN :
978-1-4244-4836-4
Electronic_ISBN :
978-1-4244-4837-1
DOI :
10.1109/ICIINFS.2009.5429863