太阳能光伏智能电网的网络安全漏洞:威胁建模和风险评估方法

IF 0.6 Q4 CONSTRUCTION & BUILDING TECHNOLOGY
Fiza Abdul Rahim, Nur Azfahani Ahmad, Pritheega Magalingam, Norziana Jamil, Zaihisma Che Cob, Lizawati Salahudin
{"title":"太阳能光伏智能电网的网络安全漏洞:威胁建模和风险评估方法","authors":"Fiza Abdul Rahim, Nur Azfahani Ahmad, Pritheega Magalingam, Norziana Jamil, Zaihisma Che Cob, Lizawati Salahudin","doi":"10.30880/ijscet.2023.14.03.018","DOIUrl":null,"url":null,"abstract":"Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, these tools must be properly secured to prevent the grid from becoming more vulnerable to cyber-attacks. This study proposes a threat modeling and risk assessment approach tailored to smart grids incorporating solar PV systems. The approach involves identifying, assessing, and mitigating risks through threat modeling and risk assessment. A threat model is designed by adapting and applying general threat modeling steps to the context of smart grids with solar PV. The process involves the identification of device assets and access points within the smart grid infrastructure. Subsequently, the threats to these devices were classified utilizing the STRIDE model. To further prioritize the identified threat, the DREAD threat-risk ranking model is employed. The threat modeling stage reveals several high-risk threats to the smart grid infrastructure, including Information Disclosure, Elevation of Privilege, and Tampering. Targeted recommendations in the form of mitigation controls are formulated to secure the smart grid’s posture against these identified threats. The risk ratings provided in this study offer valuable insights into the cybersecurity risks associated with smart grids incorporating solar PV systems, while also providing practical guidance for risk mitigation. Tailored mitigation strategies are proposed to address these vulnerabilities. By taking proactive measures, energy sector stakeholders may strengthen the security of their smart grid infrastructure and protect critical operations from potential cyber threats.","PeriodicalId":14418,"journal":{"name":"International Journal of Sustainable Construction Engineering and Technology","volume":"72 1","pages":"0"},"PeriodicalIF":0.6000,"publicationDate":"2023-09-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach\",\"authors\":\"Fiza Abdul Rahim, Nur Azfahani Ahmad, Pritheega Magalingam, Norziana Jamil, Zaihisma Che Cob, Lizawati Salahudin\",\"doi\":\"10.30880/ijscet.2023.14.03.018\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, these tools must be properly secured to prevent the grid from becoming more vulnerable to cyber-attacks. This study proposes a threat modeling and risk assessment approach tailored to smart grids incorporating solar PV systems. The approach involves identifying, assessing, and mitigating risks through threat modeling and risk assessment. A threat model is designed by adapting and applying general threat modeling steps to the context of smart grids with solar PV. The process involves the identification of device assets and access points within the smart grid infrastructure. Subsequently, the threats to these devices were classified utilizing the STRIDE model. To further prioritize the identified threat, the DREAD threat-risk ranking model is employed. The threat modeling stage reveals several high-risk threats to the smart grid infrastructure, including Information Disclosure, Elevation of Privilege, and Tampering. Targeted recommendations in the form of mitigation controls are formulated to secure the smart grid’s posture against these identified threats. The risk ratings provided in this study offer valuable insights into the cybersecurity risks associated with smart grids incorporating solar PV systems, while also providing practical guidance for risk mitigation. Tailored mitigation strategies are proposed to address these vulnerabilities. By taking proactive measures, energy sector stakeholders may strengthen the security of their smart grid infrastructure and protect critical operations from potential cyber threats.\",\"PeriodicalId\":14418,\"journal\":{\"name\":\"International Journal of Sustainable Construction Engineering and Technology\",\"volume\":\"72 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.6000,\"publicationDate\":\"2023-09-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Sustainable Construction Engineering and Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.30880/ijscet.2023.14.03.018\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"CONSTRUCTION & BUILDING TECHNOLOGY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Sustainable Construction Engineering and Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.30880/ijscet.2023.14.03.018","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"CONSTRUCTION & BUILDING TECHNOLOGY","Score":null,"Total":0}
引用次数: 0

摘要

网络安全是智能电网日益关注的问题,尤其是太阳能光伏(pv)的集成。随着太阳能的安装和逆变器的进步,公用事业可以通过各种工具实时提供太阳能发电和其他信息。然而,这些工具必须得到适当的保护,以防止电网变得更容易受到网络攻击。本研究提出了一种针对集成太阳能光伏系统的智能电网的威胁建模和风险评估方法。该方法包括通过威胁建模和风险评估来识别、评估和减轻风险。通过对太阳能光伏智能电网的威胁建模步骤进行调整和应用,设计了一个威胁模型。该过程涉及识别智能电网基础设施中的设备资产和接入点。随后,利用STRIDE模型对这些设备的威胁进行了分类。为了进一步确定已识别的威胁的优先级,采用了DREAD威胁-风险排序模型。威胁建模阶段揭示了智能电网基础设施面临的几种高风险威胁,包括信息泄露、特权提升和篡改。制定了缓解控制形式的有针对性的建议,以确保智能电网能够应对这些已确定的威胁。本研究提供的风险评级为与太阳能光伏系统相关的智能电网的网络安全风险提供了有价值的见解,同时也为风险缓解提供了实用指导。针对这些脆弱性,提出了量身定制的缓解战略。通过采取积极措施,能源部门的利益相关者可以加强其智能电网基础设施的安全性,并保护关键运营免受潜在的网络威胁。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, these tools must be properly secured to prevent the grid from becoming more vulnerable to cyber-attacks. This study proposes a threat modeling and risk assessment approach tailored to smart grids incorporating solar PV systems. The approach involves identifying, assessing, and mitigating risks through threat modeling and risk assessment. A threat model is designed by adapting and applying general threat modeling steps to the context of smart grids with solar PV. The process involves the identification of device assets and access points within the smart grid infrastructure. Subsequently, the threats to these devices were classified utilizing the STRIDE model. To further prioritize the identified threat, the DREAD threat-risk ranking model is employed. The threat modeling stage reveals several high-risk threats to the smart grid infrastructure, including Information Disclosure, Elevation of Privilege, and Tampering. Targeted recommendations in the form of mitigation controls are formulated to secure the smart grid’s posture against these identified threats. The risk ratings provided in this study offer valuable insights into the cybersecurity risks associated with smart grids incorporating solar PV systems, while also providing practical guidance for risk mitigation. Tailored mitigation strategies are proposed to address these vulnerabilities. By taking proactive measures, energy sector stakeholders may strengthen the security of their smart grid infrastructure and protect critical operations from potential cyber threats.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
0.90
自引率
20.00%
发文量
25
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信