Using Graph Theory to Contain Propagation of Malicious Code on a Smart Grid

No ratings

Presented at S4 2014 by

Smart Grid and Industrial Control System (ICS) mesh infrastructures have unique characteristics that separate them from traditional multipoint networks in terms of protection approaches. The dynamic nature of mesh establishment and reconfiguration in response to external stimuli means that a complete awareness of mesh configuration at any point in time is difficult, if not impossible. A response to any anomalous behavior that relies on a complete awareness of mesh topology, or on a presumption that the topology is static, will be insufficient to counter even the most rudimentary attempts of an adversary to traverse the network. Similarly, a response to anomalous behavior that assumes a rational adversary with a specific set of knowledge about mesh topology will be insufficient to assure a proper reaction. A containment approach that leverages graph theory and stochastic modeling may provide an effective means of delaying or halting the propagation of malicious code throughout a Smart Grid / ICS network. Similar approaches have been used in epidemiology and other health sciences. We propose to determine the extent to which these methods may be applied to Smart Grid and ICS networks to slow or halt propagating attacks that traverse the established communications mesh interlinking the network nodes, while simultaneously minimizing the cost to the protector of response and recovery.