Research on Power System Cyber Security Defense based on ATT\&CK Framework
Author
Abstract

Advanced persistent threat (APT) attack is one of the most serious threats to power system cyber security. ATT\&CK framework integrates the known historical and practical APT attack tactics and techniques to form a general language for describing hacker behavior and an abstract knowledge base framework for hacker attacks. Combined with the ATT\&CK for ICS framework, this paper combed the known attack techniques used by viruses or hacker groups aimed at cyberattacks on infrastructure, especially power systems. Then found the corresponding mitigations for each attack technique, and merged them. Next, we listed the high frequency and important mitigations for reference. At last, we proposed a cyber security defense model suitable for ICS to provide a reference for security teams on how to apply ATT\&ck; other similar cyberattack frameworks.

Year of Publication
2023
Date Published
jul
URL
https://ieeexplore.ieee.org/document/10256874
DOI
10.1109/EEPS58791.2023.10256874
Google Scholar | BibTeX | DOI