{"title":"Cost modeling of response actions for automated response and recovery in AMI","authors":"Ahmed M. Fawaz, R. Berthier, W. Sanders","doi":"10.1109/SmartGridComm.2012.6486008","DOIUrl":null,"url":null,"abstract":"The smart grid is creating new security vulnerabilities due to the deployment of networked devices into the traditional grid. A core component of the smart grid is the advanced metering infrastructures (AMIs), which increase the attack surface due to smart devices deployed at households. Manual management of security incidents in such a large and complex system is impractical, and the need for automated response and recovery to attacks is critical. This paper addresses that challenge through two main contributions. First, we introduce and classify an extended set of AMI-specific cyber incident response actions. Second, we define a cost model and an approach to translate security properties into monetary costs. The cost model is a key element in enabling an automated response engine to make optimal decisions and mitigate cyber incidents.","PeriodicalId":143915,"journal":{"name":"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2012-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 IEEE Third International Conference on Smart Grid Communications (SmartGridComm)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartGridComm.2012.6486008","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
Abstract
The smart grid is creating new security vulnerabilities due to the deployment of networked devices into the traditional grid. A core component of the smart grid is the advanced metering infrastructures (AMIs), which increase the attack surface due to smart devices deployed at households. Manual management of security incidents in such a large and complex system is impractical, and the need for automated response and recovery to attacks is critical. This paper addresses that challenge through two main contributions. First, we introduce and classify an extended set of AMI-specific cyber incident response actions. Second, we define a cost model and an approach to translate security properties into monetary costs. The cost model is a key element in enabling an automated response engine to make optimal decisions and mitigate cyber incidents.