Skip to content

Distributed SDN control for securing DNP3 protocol-based communications in smart grids

TL;DR

Results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.

Abstract

Legacy Distributed Network Protocol 3 (DNP3) communications remain widely used in modem smart grids, but they expose geographically distributed power infrastructure to coordinated cyberattacks that combine protocol-level command abuse with network-layer disruption. These threats require a defense framework that can detect multi-class attacks with low latency while also reasoning over source authorization, command semantics, and topology context to produce safe, auditable mitigation actions. This thesis presents GridCAD-LLM, a distributed software-defined networking framework for resilient DNP3 defense that integrates cloud-assisted multiclass traffic detection, source-aware event interpretation, and topology-grounded policy synthesis through a large language model. The framework combines distributed ONOS controllers, an Atomix-backed consensus layer, and a cloud-hosted multilayer perceptron to detect ten DNP3 attack classes and coordinate mitigation across grid regions. For administrative command-abuse events involving masteronly function codes, GridCAD-LLM uses DNP3 command semantics, victim-response evidence, and live ONOS topology context to generate validated SDN enforcement blueprints under explicit safety constraints. Evaluation in a geo-distributed AWS-based testbed shows 99.5 percent classification accuracy for routine attack classes, cloud-offloaded inference latency under 100 ms, and coordinated policy-update latency below 15 ms. Across 100 balanced command-abuse simulations, the policy-synthesis pipeline achieves 99 percent correctness with average inference latency below 2 s, while live retrieval-augmented updates improve heldout correctness from 94 percent to 100 percent. These results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.

View source

Similar papers

V5GIDS: An ETSI NFV MANO-Aligned Federated Intrusion Detection Framework for 5G Networks

Experimental results show that V5GIDS achieves strong detection performance in the evaluated settings while improving deployment relevance through orchestration alignment, reduced telemetry exchange, and resource-aware distributed operation.

Sofian Ben Khalifa, Rahim Taheri, Ivan Jordanov · 0 citations
Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is pr...

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations
Open access 2026

DDoS Defense Model on 5G Network Slices

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al. · 0 citations
Jul 2026

DISCO: Distributed Spectrum Compliance and Orchestration for Scalable IoT Coexistence

Distributed Spectrum Compliance and Orchestration (DISCO) is introduced, a hierarchical architecture that separates local spectrum learning from edge-level compliance regulation and slower cloud or non-terrestrial-network context adaptation.

L. S. Saoud, Moussa Ayyash · 0 citations
Open access Aug 2026

APATCP: programmable multi-controller framework for real-time detection and mitigation of complex TCP flooding attacks in SD-IoT networks

Results establish APATCP as a scalable, adaptive, and resource-efficient framework that delivers high detection accuracy, low overhead, and robust mitigation, ensuring reliable defense for next-generation SD-IoT infrastructures against increasingly sophisticated TCP flooding threats.

Ashraf Alyanbaawi, A. Hassan, Marwa M. Khashaba et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.