A Review of Protocol Analysis-Based Secure Traffic Monitoring and Anomalous Behavior Detection Technologies for Power Monitoring Systems
Abstract
Focusing on the typical characteristics of power monitoring systems—including dedicated protocols, stable communication relationships, stringent real-time requirements, and security incidents with severe operational consequences—this paper presents a systematic review of protocol analysis-based secure traffic monitoring and anomalous behavior detection. The review begins with the network architecture, representative protocols such as International Electrotechnical Commission (IEC) 104, IEC 61850, and Distributed Network Protocol 3 (DNP3), and their associated security risks, thereby clarifying the foundational role of protocol-level visibility in power monitoring scenarios. It then surveys protocol analysis methods, including deep packet inspection, flow-level feature analysis, machine learning, and hybrid identification approaches, as well as anomaly detection strategies targeting connection behavior, operational status, and physical consistency. On this basis, it further summarizes common issues in publicly available datasets, evaluation metrics, and experimental design. Existing studies indicate that related technologies are moving from single rule matching toward the coordinated use of protocol semantic understanding, behavioral modeling, and multi-layer fusion analysis. Nevertheless, substantial gaps remain in power-specific data resources, cross-scenario generalization, stealthy anomaly recognition, and engineering interpretability. Finally, the paper discusses future research directions in light of the practical requirements of power monitoring systems.