Skip to content
Preprint

Strategy Phasing of Cyber Attacks on Digital Substations

Jul 2026 · 0 citations · 8 references
Computer Science Engineering

TL;DR

This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path.

Abstract

Digital substations that comply with IEC 61850 have improved the operational efficiency of modern power systems. However, adversaries can abuse IEC 61850 communication to manipulate circuit breaker operations in substations, which can result in severe system impacts. These cyber attacks are crafted based on broader multi-phase strategies. The existing intrusion detection systems (IDSs) often flag only isolated symptoms. Thus, there is a lack of context in the attack phase to support the deployment of mitigation measures. This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path. The attack phases are derived from an ATT&CK-based threat modeling. The SubCASP model is trained and evaluated on a reproducible attack-graph dataset. Test results are presented to demonstrate the robustness of SubCASP for various IDS observability levels and missing IDS data logs scenarios.

View source

Similar papers

Open access Jul 2026

Living Off the Land Attacks on IEC 61850 Substations

Power from Shore (PfS) is becoming more widespread for offshore petroleum installations, which have introduced new dependencies and the potential for a single point of failure. In addition, the cyber threat landscape is increasing, with state-sponsored actors demonstrating the capabilities and willingness to target Operational Technology (OT) systems. Threat actors have been seen using living off the land techniques, such as with the Industroyer malware, which utilized legitimate but malicious IEC 104 commands to open circuit breakers. To evaluate these vulnerabilities, in this study, a Design Science Research approach was applied to map a generalized substation and develop a Software-in-the-Loop simulator, which was used to test a specific attack vector against substation automation systems. The results confirm that an adversary with local network access can successfully inject valid IEC 61850 Manufacturing Message Specification (MMS) commands to trigger unauthorized circuit breaker operations. Furthermore, it is also shown that a simulated substation can be used as a tool when developing OT malware.

Robin Eriksen Birkeland, S. Houmb · 0 citations
Open access Jul 2026

Integrated Safety–Security Modelling in Digital Substations

The integrated safety–security modelling in digital substations is key in today's smart grid context with the presence of cyber–physical threats. To deal with these problems, this paper adopts a unified framework for co-modelling based on mathematics, which integrates the four aspects of dependency analysis by graph, system methods based on state modelling, attacker-defender optimization and temporal logic verification. A cyber–physical interaction model incorporating the cascading failures and attack propagation is developed for the operational risk dynamics. Bounded disturbance analysis is used to derive stability conditions and the Nash equilibrium and the Hamilton–Jacobi–Isaacs formulations are used to optimize the defensive strategies. Linear Temporal Logic (LTL) and Computation Tree Logic (CTL) are logic formalisms used to provide formal verification to safety and recovery properties. The simulation results indicate that in digital substations a higher accuracy of fault detection (96.8 %), detection rate of cyberattacks (97.5 %), cascading failure containment (94.6 %) and lower response time (109ms) have been achieved.

Rohit Ravindra Nikam · 0 citations
Conference Aug 2026

A Review of Digital Oil Field Cybersecurity with a Perspective on Cyberphysical Attack Mitigation with the Integration of Physically Unclonable Functions

Due to the proliferation of immersive adoption of automation systems and infrastructure in the operation, monitoring and optimizing oil production fields, ICT systems have become a significant tool in the realization of this paradigm shift. This sensing and automation systems bring about situational awareness of the field using technologies in the form of SCADA (Supervisory Control and Data Acquisition), DCS (Distributed Control System) or WAMS (Wide Area Monitoring System) infrastructure. These technologies are closely integrated with vessels, equipment, wells and process variables. Due to the criticality of data for efficient operations, they are susceptible to cyber-attack for malicious reasons by intruders. Therefore, it is essential for these networks and data therein to be protected from cyber-attacks to ensure reliable and robust sensing, transmission and utilization of data in the oil production field. This paper discusses digitization of oil fields, cyber vulnerabilities, real cyber-attack events and mitigation strategies, cyber threats associated with digital oil fields. It also highlights and focuses on the System-on-Chip (SoC) strategies exemplifying the use of Physically Unclonable functions (PUF) in the generation of data provenance attributes to boost the cyber-physical security infrastructures in digital oil fields. A proposed framework for the deployment of PUFs to be integrated into digital systems infrastructure in the oil field is presented with benefits and limitations discussed.

Abdallah Abu-Saeed, E. Ayodele, Sani Salisu et al. · 0 citations
#machine learning Preprint Aug 2026

Digital Twin-Based Intrusion Detection for Vehicle Powertrain CAN Bus Systems

A DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.

Araf Rahman, M. Salek, Mashrur Chowdhury · 0 citations