Moving target defense for securing smart grid communications: Architectural design, implementation and evaluation

dc.contributor.advisor Manimaran Govindarasu
dc.contributor.author Chidambaram Pappa, Aswin
dc.contributor.department Department of Electrical and Computer Engineering
dc.date 2018-08-11T12:58:09.000
dc.date.accessioned 2020-06-30T03:05:40Z
dc.date.available 2020-06-30T03:05:40Z
dc.date.copyright Fri Jan 01 00:00:00 UTC 2016
dc.date.embargo 2001-01-01
dc.date.issued 2016-01-01
dc.description.abstract <p>Supervisory Control And Data Acquisition (SCADA) communications are often subjected to various kinds of sophisticated cyber-attacks which can have a serious impact on the Critical Infrastructure such as the power grid. Most of the time, the success of the attack is based on the static characteristics of the system, thereby enabling an easier profiling of the target system(s) by the adversary and consequently exploiting their limited resources. In this thesis, a novel approach to mitigate such static vulnerabilities is proposed by implementing a Moving Target Defense (MTD) strategy in a power grid SCADA environment, which leverages the existing communication network with an end-to-end IP Hopping technique among the trusted peer devices. This offers a proactive L3 layer network defense, minimizing IP-specific threats and thwarting worm propagation, APTs, etc., which utilize the cyber kill chain for attacking the system through the SCADA network. The main contribution of this thesis is to show how MTD concepts provide proactive defense against targeted cyber-attacks, and a dynamic attack surface to adversaries without compromising the availability of a SCADA system.</p> <p>Specifically, the thesis presents a brief overview of the different type of MTD designs, the proposed MTD architecture and its implementation with IP hopping technique over a Control Center–Substation network link along with a 3-way handshake protocol for synchronization on the Iowa State’s Power Cyber testbed. The thesis further investigates the delay and throughput characteristics of the entire system with and without the MTD to choose the best hopping rate for the given link. It also includes additional contributions for making the testbed scenarios more realistic to real world scenarios with multi-hop, multi-path WAN. Using that and studying a specific attack model, the thesis analyses the best ranges of IP address for different hopping rate and different number of interfaces. Finally, the thesis describes two case studies to explore and identify potential weaknesses of the proposed mechanism, and also experimentally validate the proposed mitigation alterations to resolve the discovered vulnerabilities. As part of future work, we plan to extend this work by optimizing the MTD algorithm to be more resilient by incorporating other techniques like network port mutation to further increase the attack complexity and cost.</p>
dc.format.mimetype application/pdf
dc.identifier archive/lib.dr.iastate.edu/etd/15681/
dc.identifier.articleid 6688
dc.identifier.contextkey 11164964
dc.identifier.doi https://doi.org/10.31274/etd-180810-5309
dc.identifier.s3bucket isulib-bepress-aws-west
dc.identifier.submissionpath etd/15681
dc.identifier.uri https://dr.lib.iastate.edu/handle/20.500.12876/29864
dc.language.iso en
dc.source.bitstream archive/lib.dr.iastate.edu/etd/15681/chidambarampappa_iastate_0097M_16001.pdf|||Fri Jan 14 20:44:47 UTC 2022
dc.subject.disciplines Computer Engineering
dc.subject.keywords Critical Infrastructure
dc.subject.keywords IP address hopping
dc.subject.keywords Moving Target Defense
dc.subject.keywords Power Grid
dc.subject.keywords proactive L3 layer network defense
dc.subject.keywords SCADA
dc.title Moving target defense for securing smart grid communications: Architectural design, implementation and evaluation
dc.type thesis en_US
dc.type.genre thesis en_US
dspace.entity.type Publication
relation.isOrgUnitOfPublication a75a044c-d11e-44cd-af4f-dab1d83339ff
thesis.degree.discipline Computer Engineering
thesis.degree.level thesis
thesis.degree.name Master of Science
File
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
chidambarampappa_iastate_0097M_16001.pdf
Size:
2.66 MB
Format:
Adobe Portable Document Format
Description: