<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    cn
   </journal-id>
   <journal-title-group>
    <journal-title>
     Communications and Network
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    1949-2421
   </issn>
   <issn publication-format="print">
    1947-3826
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/cn.2024.163006
   </article-id>
   <article-id pub-id-type="publisher-id">
    cn-135683
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Computer Science 
     </subject>
     <subject>
       Communications
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    Optimization of Stealthwatch Network Security System for the Detection and Mitigation of Distributed Denial of Service (DDoS) Attack: Application to Smart Grid System
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Emmanuel S.
      </surname>
      <given-names>
       Kolawole
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Penrose S.
      </surname>
      <given-names>
       Cofie
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       John H.
      </surname>
      <given-names>
       Fuller
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Cajetan M.
      </surname>
      <given-names>
       Akujuobi
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Emmanuel A.
      </surname>
      <given-names>
       Dada
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Justin F.
      </surname>
      <given-names>
       Foreman
      </given-names>
     </name>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Pamela H.
      </surname>
      <given-names>
       Obiomon
      </given-names>
     </name>
    </contrib>
   </contrib-group> 
   <aff id="affnull">
    <addr-line>
     aElectrical and Computer Engineering Department, Prairie View A&amp;M University, Prairie View, TX, USA
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     31
    </day> 
    <month>
     07
    </month>
    <year>
     2024
    </year>
   </pub-date> 
   <volume>
    16
   </volume> 
   <issue>
    03
   </issue>
   <fpage>
    108
   </fpage>
   <lpage>
    134
   </lpage>
   <history>
    <date date-type="received">
     <day>
      14,
     </day>
     <month>
      June
     </month>
     <year>
      2024
     </year>
    </date>
    <date date-type="published">
     <day>
      27,
     </day>
     <month>
      June
     </month>
     <year>
      2024
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      27,
     </day>
     <month>
      August
     </month>
     <year>
      2024
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    The Smart Grid is an enhancement of the traditional grid system and employs new technologies and sophisticated communication techniques for electrical power transmission and distribution. The Smart Grid’s communication network shares information about status of its several integrated IEDs (Intelligent Electronic Devices). However, the IEDs connected throughout the Smart Grid, open opportunities for attackers to interfere with the communications and utilities resources or take clients’ private data. This development has introduced new cyber-security challenges for the Smart Grid and is a very concerning issue because of emerging cyber-threats and security incidents that have occurred recently all over the world. The purpose of this research is to detect and mitigate Distributed Denial of Service [DDoS] with application to the Electrical Smart Grid System by deploying an optimized Stealthwatch Secure Network analytics tool. In this paper, the DDoS attack in the Smart Grid communication networks was modeled using Stealthwatch tool. The simulated network consisted of Secure Network Analytic tools virtual machines (VMs), electrical Grid network communication topology, attackers and Target VMs. Finally, the experiments and simulations were performed, and the research results showed that Stealthwatch analytic tool is very effective in detecting and mitigating DDoS attacks in the Smart Grid System without causing any blackout or shutdown of any internal systems as compared to other tools such as GNS3, NeSSi2, NISST Framework, OMNeT++, INET Framework, ReaSE, NS2, NS3, M5 Simulator, OPNET, PLC&amp;TIA Portal management Software which do not have the capability to do so. Also, using Stealthwatch tool to create a security baseline for Smart Grid environment, contributes to risk mitigation and sound security hygiene.
   </abstract>
   <kwd-group> 
    <kwd>
     Smart Grid System
    </kwd> 
    <kwd>
      Distributed Denial of Service (DDoS) Attack
    </kwd> 
    <kwd>
      Intrusion Detection and Prevention Systems
    </kwd> 
    <kwd>
      Detection
    </kwd> 
    <kwd>
      Mitigation and Stealthwatch
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>
    <xref ref-type="bibr" rid="scirp.135683-"></xref>1. Introduction</title>
   <sec id="s1_1">
    <title>Smart Grid Background</title>
    <p>The advancement in the Smart Grid technology has culminated in the integration of communication and computer network for Grid system-wide collection of power usage information, local energy consumption, and other measured data <xref ref-type="bibr" rid="scirp.135683-1">
      [1]
     </xref>. This development of the Smart Grid has introduced new cyber-security challenges and is a very concerning issue because of cyber-threats and security incidents that have targeted critical infrastructures all over the world. Securing the Smart Grid has become necessary due to constant cyber-attacks leading to blackout and loss of intellectual properties. Research shows that one of the crucial part of the Smart Grid infrastructure is its integral communication system <xref ref-type="bibr" rid="scirp.135683-2">
      [2]
     </xref>. A high amount of crucial data flows through the communication and computer network of the Smart Grid. Therefore, it is very important to provide a secure and reliable Smart Grid system <xref ref-type="bibr" rid="scirp.135683-3">
      [3]
     </xref>. To increase grid resilience and reliability, networked microgrids are being investigated as a promising solution. Networked microgrids are clusters of geographically close, islanded microgrids that can function as a single, aggregate island. This flexibility enables customer-level resilience and reliability improvements during extreme event outages and reduces utility costs during normal grid operations <xref ref-type="bibr" rid="scirp.135683-4">
      [4]
     </xref>.</p>
    <p>To achieve this cohesive operation, microgrid controllers and external connections (including advanced communication protocols, protocol translators, and/or internet connection) are needed. However, these advancements also increase the vulnerability landscape of networked microgrids, and significant consequences could arise during networked operation, increasing cascading impact.</p>
    <p>1) Problem Statement</p>
    <p>The Smart Grid system is an intelligent grid designed to handle surge loading and distributed generation using information and communication technology employing smart meters and control system. Because Smart Grid is embedded into open communication infrastructures to support vast amounts of data exchange, Smart Grids are vulnerable to cyber-attacks. Cyberattacks on Smart Grid include the breaching of sensitive customer data by adversaries, malware propagation, malfunctions in cyber systems, and vulnerabilities in distributed control devices. The threats could target the generation, transmission, distribution, and consumers.</p>
    <p>Recently, the issue of Distributed Denial of Service (DDoS) attacks on the Electric grid system has been very rampant across the world. Lots of tangible assets and intellectual properties and many hours have been lost in this regard. Additionally, attackers can make power system unstable by designing DDoS attack sequences through jamming the communication channels, attacking networking protocols, and flooding the network traffics.</p>
    <p>Below are some of the situations of the former researchers and the problems that existed in them.</p>
    <p>Limitations: The research was conducted using NeSSi 2 Tool and the results showed that the entire grid could be compromised with a large-enough DDoS attack but Only after the server had been taken offline was an impact observed.</p>
    <p>Limitations: The proposed framework NIST is very general and vague and needs to be focused on particular domains of Smart Grid. In fact, the authors did not provide a specific solution and technique.</p>
    <p>Limitations: The research was conducted using OMNeT++ Tool and the results showed that DDoS attack on the server reportedly diminished connections with almost 90% of the smart meters.</p>
    <p>Limitations: The research was conducted using PLC and TIA Portal Management Software Tools and the results showed that the network was quickly disrupted even with a small number of attackers.</p>
    <p>Limitations: The research was conducted using GNS3 Tool and the simulation results from the tool clearly show the vulnerability of DDoS attack in a Smart Grid power System. The destination server became overwhelmed, unavailable and shut down after consistent flooding. This was because there was no proper and reliable tool or control in place to detect, monitor and mitigate DDoS attack in place.</p>
    <p>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>2) Purpose of this Research</p>
    <p>The purpose and objective of this research is to detect and mitigate the Distributed Denial of Service [DDoS] attack with application to the Electrical Smart Grid System by deploying an optimized Stealthwatch Secure Network analytics tool. Stealthwatch analytic tool also has the capability to detect malware/attack in encrypted traffic without any decryption using “Encrypted Traffic Analytics [ETA]” capability on the tool. It focuses on the study of the practical ways to detect and mitigate DDoS attacks when data are transferred over Smart Grid Communication Networks without any adverse effect on the internal systems or any shutdown of the systems due to attack.</p>
    <p>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>Unfortunately, no technology today can completely keep hackers out of enterprise networks. However, if an organization is regularly monitoring its own environment with the right mix of people, processes and technology, the security team will be better equipped to identify and stop an attack while it’s still happening, avoiding the disastrous results and costs associated with a data breach.</p>
    <sec id="s1">
     <title>
      <xref ref-type="bibr" rid="scirp.135683-"></xref>2. Literature Review</title>
    </sec>
    <sec id="s2_2">
     <title>Introduction</title>
     <p>The Smart Grid is the modern system of wires, meters, and transformers that work together to power our homes and businesses. We connect ourselves to the Smart Grid when we plug in our devices and click on the light switch. The electricity grid is older than you might have thought—it was developed in the 1890s and evolved along with our ever-changing technology <xref ref-type="bibr" rid="scirp.135683-5">
       [5]
      </xref>. Today, the modern Smart Grid contains over nine thousand electricity generating units, has over one million megawatts of generating capacity, and is connected to more than three hundred thousand transmission lines. Smart Grid is divided into three main networks: the operation network, the business network, and the customer network. Each of these three networks has individual set of communication subnetworks serving different functions. The first, operation network is used for maintaining the Grid functionality by the power companies. The second one, the business network is used by the participants in the electricity market to effectively regulate the market and to provide electricity services to the customers at large. The last part which is the customer network is used by individual customer for management of their home energy and to enhance the electricity usage <xref ref-type="bibr" rid="scirp.135683-6">
       [6]
      </xref>. Due to the division of the Smart Grid networks in terms of communication, Smart Grid is divided into three areas as shown in <xref ref-type="fig" rid="fig1">
       Figure 1
      </xref>. such as WAN, HAN, and NAN. WAN (Wide Area Network) provides communication links or interface between the NANs and the utility systems in order to transfer information. NAN (Neighborhood Area Network) in its case connects multiple HANs to the local access points. HAN (Home Area Network), this communication is for end user home or business communications <xref ref-type="bibr" rid="scirp.135683-7">
       [7]
      </xref>.</p>
     <p>
      <xref ref-type="fig" rid="fig2">
       Figure 2
      </xref> below depicts generic Smart Grid Network Architecture components or modules with different reference points.</p>
     <p>As shown, typical Smart Grid network consists of following components.</p>
     <fig id="fig1" position="float">
      <label>Figure 1</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 1. Illustration of Smart Grid network architecture <xref ref-type="bibr" rid="scirp.135683-7">
         [7]
        </xref>.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId13.jpeg?20240830112201" />
     </fig>
     <fig id="fig2" position="float">
      <label>Figure 2</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 2. Generic Smart Grid Network Architecture components <xref ref-type="bibr" rid="scirp.135683-8">
         [8]
        </xref>.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId14.jpeg?20240830112201" />
     </fig>
     <p>Grid domain: Operations include bulk generation, distribution, and transmission Smart meters Consumer domain: HAN (Home Area Network) consists of smart appliances and more. Communication network: This connects smart meters with consumers and electricity company for energy monitoring and control operations, include various wireless technologies such as Zigbee, wifi, HomePlug, cellular, GSM, GPRS, 3G, 4G-LTE, etc. Third-party service providers: system vendors, operators, web companies etc.</p>
     <p>Smart Grid security has attracted a lot of attentions from both academic and industry communities. Some of the reviews and comments are thereby highlighted as part of this research paper. Asri, S., Pranggono, B. Impact of Distributed Denial of Service Attack on Advanced Metering Infrastructure. Wireless Personal Communications 83(3), 2211-2223 (2015) <xref ref-type="bibr" rid="scirp.135683-3">
       [3]
      </xref>. The results showed that the entire grid could be compromised with a large-enough DDoS attack but Only after the server had been taken offline was an impact observed. Fang et al. The contributions of cloud technologies to Smart Grid. Renewable and Sustainable Energy Reviews, Vol. 59, pp. 1326-1331, June (2016) <xref ref-type="bibr" rid="scirp.135683-9">
       [9]
      </xref>. The results showed the review of application of different areas of cloud computing technology in Smart Grid and finally, cloud security is briefly investigated. No precise framework has been proposed to enhance the security of the Smart Grid and issues were surveyed generally. Abdul Rahman et al. Smart Grid security challenges: Classification by sources of threat. Journal of Electrical Systems and Information Technology, Vol. 5, No. 3, pp. 468-483, Dec. (2018) <xref ref-type="bibr" rid="scirp.135683-10">
       [10]
      </xref>. The authors examined security challenges of Smart Grid and they classified and analyzed identified challenges based on threat sources carefully. Meanwhile, their proposed framework is very general and vague and needs to be focused on domains of Smart Grid. In fact, the authors did not provide a specific solution and technique. Shrestha. M et al. A Methodology for Security Classification applied to Smart Grid Infrastructures. International Journal of Critical Infrastructure Protection, 28 (2020) <xref ref-type="bibr" rid="scirp.135683-11">
       [11]
      </xref>. The authors proposed a methodology called Smart Grid Security Classification (SGSC) developed for complex systems such as the Smart Grid. They indeed covered risk analysis methods, security criteria and protection mechanism in their methodology. Their methodology does not support automatic computation of scores and multi-metrics approach. K. Demir et al. Securing the cloud-assisted Smart Grid. International Journal of Critical Infrastructure Protection, pp. 100-111, Dec. (2018) <xref ref-type="bibr" rid="scirp.135683-12">
       [12]
      </xref>. The authors proposed cloud computing technology to improve the security of the Smart Grid. They specifically concentrated on distributed denial of service attack and counteracting it. There is no comprehensive approach to enhance Smart Grid security using cloud computing technology in this paper and it focuses only on countering a specific attack. Souris, K.I et al. Cyber Attack Impact on Critical Smart Grid Infrastructures. ISGT pp. 1-5. IEEE (2014) <xref ref-type="bibr" rid="scirp.135683-5">
       [5]
      </xref>. The authors considered four different types of AMI DoS setups. The results showed that DoS attack against the server caused a drop in the number of TCP packets delivered to smart meters, leading to some service degradation. Also, the DDoS attack on the server reportedly diminished connections with almost 90% of the smart meters. Yilmaz, E.N et al. Cyber Security in Industrial Control Systems: Analysis of DoS Attacks Against PLCs and the Insider Effect. In: 2018 6th International Istanbul Smart Grids and Cities Congress and Fair (ICSG). pp. 81-85. IEEE (2018) <xref ref-type="bibr" rid="scirp.135683-13">
       [13]
      </xref>. The authors explored the possibility of DoS attacks against PLCs, suggesting that a PLC can be targeted both from within and outside of its own IP network, as long as its IP address is known. The results showed that the network was quickly disrupted even with a small number of attackers.</p>
     <p>In reality, Smart Grid is divided into three main networks: operation, business, and customer networks. Each of these three networks has an individual set of communication subnetworks serving different functions. First, the operation network is used for maintaining the Grid functionality by the power companies. The second one, the business network, is used by the participants in the electricity market to regulate the market effectively and provide electricity services to the customers at large. The last part, the customer network, is used by the individual customers to manage their home energy to enhance electricity usage <xref ref-type="bibr" rid="scirp.135683-3">
       [3]
      </xref>. Due to the division of the Smart Grid networks in terms of communication, Smart Grid is divided into three areas: WAN, HAN, and NAN. WAN (Wide Area Network) provides communication links or interfaces between the NANs and the utility systems to transfer information. In its case, NAN (Neighborhood Area Network) connects multiple Hans to the local access points. In the case of HAN (Home Area Network), this communication is for end-user home or business communications <xref ref-type="bibr" rid="scirp.135683-4">
       [4]
      </xref>.</p>
    </sec>
   </sec>
   <sec id="s3">
    <title>3. Cyber Security Threat in Smart Grid System</title>
    <sec id="s3_1">
     <title>Cyber Threats to the Smart Grid</title>
     <p>Attacks against the Smart Grid will likely differ from many traditional attacks against cyber environments. First, an attacker must be able to compromise the grid’s cyber elements. However, for the attack to cause negative system impact, the attacker must also know how to control the cyber elements in order to manipulate the physical system. <xref ref-type="fig" rid="fig3">
       Figure 3
      </xref> demonstrates this relationship.</p>
     <p>In the Smart Grid, the most severe threats related to the privacy deterioration of Smart Grid consumers include <xref ref-type="bibr" rid="scirp.135683-15">
       [15]
      </xref> <xref ref-type="bibr" rid="scirp.135683-16">
       [16]
      </xref>.</p>
     <fig id="fig3" position="float">
      <label>Figure 3</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 3. Attacks to the Smart Grid <xref ref-type="bibr" rid="scirp.135683-14">
         [14]
        </xref>.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId15.jpeg?20240830112202" />
     </fig>
     <p>the risks, costs, and advantages of the SG systems, because of the demand for a higher level of security.</p>
     <p>How Does Attack Happen in the Environments: The Seven Kill Chains</p>
     <p>The cyber kill chain (CKC) is a classic cybersecurity model that is developed to better understand the stages an attack must go through to conduct an attack and help security teams stop an attack at each stage <xref ref-type="bibr" rid="scirp.135683-17">
       [17]
      </xref>. <xref ref-type="fig" rid="fig4">
       Figure 4
      </xref> below shows the seven steps in the kill chain.</p>
     <fig id="fig4" position="float">
      <label>Figure 4</label>
      <caption>
       <title>Figure 4. The seven kill chains <xref ref-type="bibr" rid="scirp.135683-17">
         [17]
        </xref>.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId16.jpeg?20240830112201" />
     </fig>
    </sec>
   </sec>
   <sec id="s4">
    <title>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>4. Methodology</title>
    <sec id="s4_1">
     <title>
      <xref ref-type="bibr" rid="scirp.135683-"></xref>Materials and Methodology</title>
     <p>
      <xref ref-type="bibr" rid="scirp.135683-"></xref>In this section, the tools/devices/materials, codes, algorithms, and Lab apparatus simulation techniques used for the Detection and Mitigation of Distributed Denial of Service (DDoS) attack in application to Smart Grid System have been discussed in detail.</p>
     <p>1) The Materials, Devices and Tools</p>
     <p>In this research, the strategy started by building the Flow Collector virtual machine (VM), Flow Sensor virtual machine (VM) and Stealthwatch management console virtual machine (VM) and then assigned IP addresses in accordance with the simulated communication Network designed model as shown in <xref ref-type="fig" rid="fig5">
       Figure 5
      </xref>. The flow rate licenses is also one of the required components when deploying Stealthwatch analytics tool. Also, the attackers/source virtual machine (VM) and Target/destination virtual machine (VM) have also been built and assigned IP addresses per the simulated communication Network as well, and both can send and receive icmp/ping packets with no issues. The traffic between the attacker’s system and the target server has also been captured on the Stealthwatch management console under normal or baseline operation. The model setup already validated that traffic can go from attacker’s system to the target server and is captured on our Stealthwatch management console and thin client with no issues. We later then Installed or ingested DDoS payload/malicious codes on the attacker’s machine to carry out the DDoS operations on the target server/machine so that our model Stealthwatch tools can capture, detect, and mitigate the DDoS attack without any impact on the target system. In the simulation, once the flow level rises above the defined baseline on the target system based on our coding/algorithm, this will generate an alert to the administrator to take proper action before it affects the target server.</p>
     <p>2) The Secure Network Analytics Components</p>
     <p>
      <xref ref-type="fig" rid="fig5">
       Figure 5
      </xref> below shows the materials samples of Secure Stealthwatch Analytics components used in this research to detect and mitigate DDoS attack in Smart Grid system.</p>
     <fig id="fig5" position="float">
      <label>Figure 5</label>
      <caption>
       <title>Figure 5. Secure Stealthwatch network analytics components <xref ref-type="bibr" rid="scirp.135683-18">
         [18]
        </xref>.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId17.jpeg?20240830112203" />
     </fig>
     <p>3) Stealthwatch Analytics Tools Build</p>
     <p>Flow Collector Build</p>
     <p>
      <xref ref-type="fig" rid="fig6">
       Figure 6
      </xref> below shows the process or steps used to build the flow collector used in this research.</p>
     <p>After the VM has been assigned.</p>
     <p>Step 1: Entering the configuration mode in the network option.</p>
     <p>Step 2: <xref ref-type="fig" rid="fig7">
       Figure 7
      </xref> below shows the steps to configure FC the IP address/hostname details as shown below:</p>
     <p>IP address====192.168.232.206</p>
     <p>Subnet Mask==255.255.255.192/6</p>
     <p>Gateway=====192.168.232.193</p>
     <p>Broadcast Address==192.168.232.225</p>
     <p>Hostname========fm2lab-sw-fc01</p>
     <p>Flow Senosr Build</p>
     <p>
      <xref ref-type="fig" rid="fig8">
       Figure 8
      </xref> below the process or steps used to build the flow sensor used in this research.</p>
     <p>After the VM has been assigned:</p>
     <fig id="fig6" position="float">
      <label>Figure 6</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 6. Flow collector build interface.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId18.jpeg?20240830112203" />
     </fig>
     <fig id="fig7" position="float">
      <label>Figure 7</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 7. Flow collector build network interface settings.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId19.jpeg?20240830112203" />
     </fig>
     <p>Step 1: Entering the configuration mode in the Network option.</p>
     <p>Step 2: <xref ref-type="fig" rid="fig9">
       Figure 9
      </xref> below show the steps to configure FS the IP address/hostname details as shown below:</p>
     <p>IP address====192.168.232.207</p>
     <p>Subnet Mask==255.255.255.192/6</p>
     <p>Gateway=====192.168.232.193</p>
     <p>Broadcast Address==192.168.232.225</p>
     <p>Hostname========fm2lab-sw-fs01</p>
     <p>Stealthwatch Management Console Build</p>
     <p>
      <xref ref-type="fig" rid="fig10">
       Figure 10
      </xref> below shows the process or steps used to build the Stealthwatch</p>
     <fig id="fig8" position="float">
      <label>Figure 8</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 8. Flow sensor build interface.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId20.jpeg?20240830112202" />
     </fig>
     <fig id="fig9" position="float">
      <label>Figure 9</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 9. Flow sensor build network interface settings.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId21.jpeg?20240830112202" />
     </fig>
     <p>Management Console used in this research.</p>
     <p>After the VM has been assigned:</p>
     <p>Step 1: Entering the configuration mode in the Network option.</p>
     <p>Step 2: <xref ref-type="fig" rid="fig11">
       Figure 11
      </xref> below show the steps to configure Stealthwatch Management Console IP address/hostname details as shown below:</p>
     <p>IP address====192.168.232.205</p>
     <p>Subnet Mask==255.255.255.192/6</p>
     <p>Gateway=====192.168.232.193</p>
     <p>Broadcast Address==192.168.232.225</p>
     <p>Hostname========fm2lab-sw-fs01</p>
     <fig id="fig10" position="float">
      <label>Figure 10</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 10. SMC build interface.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId22.jpeg?20240830112202" />
     </fig>
     <fig id="fig11" position="float">
      <label>Figure 11</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 11. SMC build network interface settings.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId23.jpeg?20240830112202" />
     </fig>
     <p>Attacker-Source Host1 Build</p>
     <p>
      <xref ref-type="fig" rid="fig12">
       Figure 12
      </xref> below is the set-up build for the attacker’s/Host1 VM used in this research. After the VM has been assigned:</p>
     <p>Step 1: The IP addresses configurations info:</p>
     <p>IP Address==192.168.232.209</p>
     <p>Subnet Mask==255.255.255.192</p>
     <p>Gateway=====192.168.232.193</p>
     <p>Broadcast Address===192.168.232.255</p>
     <p>Hostname========fm2lab-nsm</p>
     <p>Step 2: System build</p>
     <fig id="fig12" position="float">
      <label>Figure 12</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 12. Attacker [Host1] VM build.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId24.jpeg?20240830112202" />
     </fig>
     <p>Target-Destination Host2 Build</p>
     <p>
      <xref ref-type="fig" rid="fig13">
       Figure 13
      </xref> below is the set-up build for the attacker’s/Host1 VM used in this research. After the VM has been assigned:</p>
     <p>Step 1: The IP addresses configurations info:</p>
     <p>IP Address==192.168.233.214</p>
     <p>Subnet Mask==255.255.255.240</p>
     <p>Gateway=====192.168.233.209</p>
     <p>Broadcast Address===192.168.233.223</p>
     <p>Hostname========ubuntu214</p>
     <p>Step 2: System build</p>
     <p>4) Proposed Design Using Stealthwatch Tools</p>
     <p>Scenario Formation/Simulation Process</p>
     <p>
      <xref ref-type="fig" rid="fig14">
       Figure 14
      </xref> shows the Proposed Networked Smart Grid and its Communication Computer Network Design Using Stealthwatch which we considered in this research. In this network, we have chosen Host1 (192.168.232.209) as source and Host2 (192.168.233.214) as destination which is connected to Router R3 and R9. The routers R1 and R9 come under the Customer Edge networks.</p>
     <p>Here, both Host1 and Host2 are connected to virtual machine which is created by VMWare. All other routers are coming under ISP Router. After creating the network, addresses were assigned as shown in the figure below. Here we choose</p>
     <fig id="fig13" position="float">
      <label>Figure 13</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 13. Target server [Host2] VM build.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId25.jpeg?20240830112202" />
     </fig>
     <fig id="fig14" position="float">
      <label>Figure 14</label>
      <caption>
       <title>Figure 14. Proposed Smart Grid communication using Stealthwatch tool.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId26.jpeg?20240830112202" />
     </fig>
     <p>logical addressing scheme which is IP addressing and IPv4 addressing scheme is specifically used in this research which is subnetted by using VLSM to reduce the minimum wastage of IP’s. All the networks of the proposed architecture use IPv4 and are all connected to the network without any issues.</p>
     <p>Once all the VMs have been built and addressed with IP details, <xref ref-type="fig" rid="fig15(a)">
       Figure 15(a)
      </xref></p>
     <fig-group id="fig15" position="float">
      <fig id="fig15" position="float">
       <label>Figure 15</label>
       <caption>
        <title>(a)--(b)--Figure 15. (a) Ping status between attacker (Host1) and target server (Host2); (b) Ping status between target server (Host2) and attacker (Host1).</title>
       </caption>
       <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId27.jpeg?20240830112202" />
      </fig>
      <fig id="fig15" position="float">
       <label>Figure 15</label>
       <caption>
        <title>(a)--(b)--Figure 15. (a) Ping status between attacker (Host1) and target server (Host2); (b) Ping status between target server (Host2) and attacker (Host1).</title>
       </caption>
       <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId28.jpeg?20240830112202" />
      </fig>
     </fig-group>
     <p>&amp; <xref ref-type="fig" rid="fig15(b)">
       Figure 15(b)
      </xref> then show the communication between the source node [attackers VM] to destination node [Target inside host] through our designed/proposed Stealthwatch network. To check the communication between the desired nodes in this research we use ping command, which works based on ICMP protocol. Based on echo request and echo reply between the source and destination we can find the communication status. Also, <xref ref-type="fig" rid="fig16">
       Figure 16
      </xref> displays the ping status throughput though our Stealthwatch tool to confirm the communication success between the two VMs. The figure also validates the Stealthwatch capability to see the traffic passing the grid system.</p>
     <p>5) Stealthwatch Smart Grid Firewall-IPS Rules, Security Event and Flowchart</p>
     <p>During this research, <xref ref-type="fig" rid="fig17">
       Figure 17
      </xref> below displays the firewall rule that was implemented in carrying out the research using Forcepoint next-generation Firewall.</p>
     <fig id="fig16" position="float">
      <label>Figure 16</label>
      <caption>
       <title>Figure 16. Flow level capture by Smart Grid computer Stealthwatch analytic tool between attacker (Host1) and target server (Host2).</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId29.jpeg?20240830112202" />
     </fig>
     <fig id="fig17" position="float">
      <label>Figure 17</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref><p class="imgGroupCss_v"><img class=" imgMarkCss lazy" data-original="https://html.scirp.org/file/6102002-rId31.jpeg?20240830112203" /></p>Figure 17. Proposed Stealthwatch Smart Grid firewall rules</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId30.jpeg?20240830112203" />
     </fig>
     <p>The firewall rules displayed the access that was allowed between the attack system or source client and the target server or destination server. The default denial rule was placed at the bottom of the firewall rule as the best practice.</p>
     <p>
      <xref ref-type="fig" rid="fig18">
       Figure 18
      </xref> below displays the Intrusion Detection System (IPS) rules that were implemented during the course of this research for the protection and security of the entire Smart Grid system use case.</p>
     <p>
      <xref ref-type="fig" rid="fig19">
       Figure 19
      </xref> shows the remodified flowchart of cyber-attack algorithm using Stealthwatch. It details how Stealthwatch detects anomaly on the network and generate alerts based on the threshold volume level.</p>
     <p>6) Optimization/Modification of Stealthwatch Codes &amp; Flow Data for Smart Grid System</p>
     <p>
      <xref ref-type="fig" rid="fig20">
       Figure 20
      </xref> below shows the optimized/modified codes used for the implementations. The codes are used during the deployment of our Stealthwatch tool to set parameters based on baseline per traffic volume. This is a significant part of the research to detect when there is an anomaly in the Smart Grid system for immediate detection and mitigation before it affects the Grid System. It shows the baseline volume of flowrate ratio set to 15 pfs as baseline without DDoS</p>
     <fig id="fig18" position="float">
      <label>Figure 18</label>
      <caption>
       <title>Figure 18. Proposed Stealthwatch Smart Grid IPS rules.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId32.jpeg?20240830112203" />
     </fig>
     <fig id="fig19" position="float">
      <label>Figure 19</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 19. Proposed block diagram of Smart Grid cyber-attack algorithm using Stealthwatch.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId33.jpeg?20240830112203" />
     </fig>
     <p>attack. When the flow rate ratio goes above 15 pfs, the alert/alarm sets in before the attack occurs.</p>
     <fig id="fig20" position="float">
      <label>Figure 20</label>
      <caption>
       <title>Figure 20. Optimized Stealtwatch coding and flow data for Smart Grid system.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId34.jpeg?20240830112203" />
     </fig>
    </sec>
   </sec>
   <sec id="s5">
    <title>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>5. Findings</title>
    <sec id="s5_1">
     <title>Simulations Analysis and Results</title>
     <p>In this section, our main concern and purpose of this simulation is to show the impact of DDoS attack in the proposed Smart Grid distribution network and how it is been detected, captured, and mitigated by our Secure Network Analytics (Stealthwatch) device/tools before it shuts down the grid completely. The data packets sent from Host1 to Host2 are captured using Stealthwatch central management console. <xref ref-type="fig" rid="fig21(a)">
       Figure 21(a)
      </xref> and <xref ref-type="fig" rid="fig21(b)">
       Figure 21(b)
      </xref> show the communication</p>
     <p>
      <xref ref-type="bibr" rid="scirp.135683-"></xref></p>
     <fig-group id="fig21" position="float">
      <fig id="fig21" position="float">
       <label>Figure 21</label>
       <caption>
        <title>(a)--(b)--(c)--Figure 21. (a) Ping status between Attacker (Host1) and Target Server (Host2); (b) Ping status between Attacker (Host1) and Target Server (Host2); (c) Ping status between Attacker (Host1) and Target Server (Host2) with Stealthwatch tool analytics before the attack</title>
       </caption>
       <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId35.jpeg?20240830112204" />
      </fig>
      <fig id="fig21" position="float">
       <label>Figure 21</label>
       <caption>
        <title>(a)--(b)--(c)--Figure 21. (a) Ping status between Attacker (Host1) and Target Server (Host2); (b) Ping status between Attacker (Host1) and Target Server (Host2); (c) Ping status between Attacker (Host1) and Target Server (Host2) with Stealthwatch tool analytics before the attack</title>
       </caption>
       <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId36.jpeg?20240830112204" />
      </fig>
      <fig id="fig21" position="float">
       <label>Figure 21</label>
       <caption>
        <title>(a)--(b)--(c)--Figure 21. (a) Ping status between Attacker (Host1) and Target Server (Host2); (b) Ping status between Attacker (Host1) and Target Server (Host2); (c) Ping status between Attacker (Host1) and Target Server (Host2) with Stealthwatch tool analytics before the attack</title>
       </caption>
       <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId37.jpeg?20240830112204" />
      </fig>
     </fig-group>
     <p>between the source node-Host1 (Attacker) to destination node-Host2 (Target Server) through Smart Grid Stealthwatch computer network. The figure also shows that the attacker server (Host1) with IP address 192.168.232.209 is able to reach Host2 with IP address 192.168.233.214 and vice-versa through icmp/ping protocol.</p>
     <p>1) Simulations Before the Attack Happened</p>
     <p>
      <xref ref-type="fig" rid="fig21(a)">
       Figure 21(a)
      </xref> and <xref ref-type="fig" rid="fig21(b)">
       Figure 21(b)
      </xref> show the ping status between the attacker and Target systems during the simulation phases.</p>
     <p>
      <xref ref-type="fig" rid="fig21(c)">
       Figure 21(c)
      </xref> below shows that Stealthwatch Analytic tool is able to capture the communication between the attacker and the Target devices with no issues. Based on the echo request and echo reply between the source and destination, we can find the communication status.</p>
     <p>2) Simulations During the Attack</p>
     <p>
      <xref ref-type="fig" rid="fig22">
       Figure 22
      </xref> below narrates the simulation results during and after the attack happpened. It displays the ingestion of malicious codes for DDoS attack in the attack system or source client in the form of excessive ping and port scan over 600 sockets as shown. This is to overwhelm and shut down the target or destination server. The figure also displays the Tcpdump simulation results that explain how the traffic is hitting the destination server per payload sent from the attack system. The TCPdump shows that the Attacker [Source Server-192.168.232.209] is constantly sending ping/port scans to Target [Destination Server-192.168.233.214] in order to overwhelm and shut it down.</p>
     <p>3) Simulations After the Attack Had Happened</p>
     <p>
      <xref ref-type="fig" rid="fig23(a)">
       Figure 23(a)
      </xref> and Figure 23(b) below show the effects of the attack launched</p>
     <fig id="fig22" position="float">
      <label>Figure 22</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.135683-"></xref>Figure 22. Stealthwatch simulations during and after the attack had happened.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId38.jpeg?20240830112204" />
     </fig>
     <fig id="fig23" position="float">
      <label>Figure 23</label>
      <caption>
       <title>(a)<xref ref-type="bibr" rid="scirp.135683-"></xref><p class="imgGroupCss_v"><img class=" imgMarkCss lazy" data-original="https://html.scirp.org/file/6102002-rId40.jpeg?20240830112204" /></p>(b)<xref ref-type="bibr" rid="scirp.135683-"></xref><p class="imgGroupCss_v"><img class=" imgMarkCss lazy" data-original="https://html.scirp.org/file/6102002-rId41.jpeg?20240830112203" /></p><xref ref-type="bibr" rid="scirp.135683-"></xref>(c)<p class="imgGroupCss_v"><img class=" imgMarkCss lazy" data-original="https://html.scirp.org/file/6102002-rId42.jpeg?20240830112203" /></p>(d)<p class="imgGroupCss_v"><img class=" imgMarkCss lazy" data-original="https://html.scirp.org/file/6102002-rId43.jpeg?20240830112203" /></p><xref ref-type="bibr" rid="scirp.135683-"></xref>(e)Figure 23. (a) Stealthwatch simulations after the attack had happened; (b) Stealthwatch Simulations after the attack had happened—cont; (c) Flow collector input and output flow comparison; (d) Stealthwatch Simulations after the attack had happened—cont; (e) Stealthwatch simulations after the attack had happened—cont.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/6102002-rId39.jpeg?20240830112204" />
     </fig>
     <p>on the attack system or destination server by the attack client or source system. The Stealthwath tool was able to detect the attack based on the volume of traffics, ports in use and how consistently the attacker was trying to break into the destination server or target.</p>
     <p>
      <xref ref-type="fig" rid="fig23(c)">
       Figure 23(c)
      </xref> shows the input and output flow logs comparison of the DDoS effect and how the tool is able to mitigate the attack before it shuts down the destination server. As soon as the flow rate ratio seems above 15 fps (flow per second) a bit, the system generates alerts to notify the administrator of any suspected attack to take any proper action if any slips as shown in <xref ref-type="fig" rid="fig23(d)">
       Figure 23(d)
      </xref>. Thou, it has already mitigated the flow increase based on the baseline code/algorithm setup, Firewall rules and IPS policy setup.</p>
     <p>
      <xref ref-type="fig" rid="fig23(e)">
       Figure 23(e)
      </xref> shows the simulation flow output on Stealthwatch tool after the attack which displayed little or no increase in flow level based on baseline set. Thou, there was a little increase in flow due to the excessive pings/Port scan, but the administrator was able to get the alert immediately based on the code/algorithm set to notify, if the flow goes above a 15 pfs. This then caused the administrator to investigate further without causing any shutting down of the server.</p>
    </sec>
   </sec>
   <sec id="s6">
    <title>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>6. Conclusions</title>
    <p>
     <xref ref-type="bibr" rid="scirp.135683-"></xref>The Smart Grid has been developed due to the constantly growing distribution from renewable sources and with further aim to increase the efficiency, reliability, and safety of the existing power grid. This development has introduced new cyber-security challenges for the Smart Grid and is a very concerning issue because of emerging cyber-threats and security incidents that have occurred recently all over the world.</p>
    <p>1) The Pros and Cons</p>
    <p>In this research, we studied and found out the impact of DDoS attack in a WAMS communication network in Smart Grid by the co-simulation of GNS3, PMU connection tester. We then proposed the simulation of Optimized Stealthwatch Network Security System Tools to detect, mitigate and prevent DDoS attack in application to Smart Grid by also applying mechanism such as Firewall, Intrusion detection and Prevention Systems.</p>
    <p>2) Concluding Thoughts/Summary</p>
    <p>In this work, we proposed the system architecture of Stealthwatch Network Security System in Smart Grid. The impact of DDoS attack in a WAMS communication network has been studied and the efficient monitoring, detection and its mitigation was proposed through the optimization and modification of Stealthwatch simulation tool algorithms/codes. Also, we deployed Firewall &amp; IPS systems to add to the detection and mitigation of DDoS attack in Smart Grid System. From the simulation results, we could see that the target system did not shut down nor degraded because of the source attack due to the mitigation strategies and alert system in place through Stealthwatch System Tools, IPS and Firewall in this research.</p>
   </sec>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.135683-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Wang, K., Du, M., Maharjan, S. and Sun, Y. (2017) Strategic Honeypot Game Model for Distributed Denial of Service Attacks in the Smart Grid. IEEE Transactions on Smart Grid, 8, 2474-2482. &gt;https://doi.org/10.1109/tsg.2017.2670144 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Guo, Y., Ten, C., Hu, S. and Weaver, W.W. (2015) Modeling Distributed Denial of Service Attack in Advanced Metering Infrastructure. 2015 IEEE Power&amp;Energy Society Innovative Smart Grid Technologies Conference, Washington, 18-20 February 2015, 1-5. &gt;https://doi.org/10.1109/isgt.2015.7131828 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Asri, S. and Pranggono, B. (2015) Impact of Distributed Denial-of-Service Attack on Advanced Metering Infrastructure. Wireless Personal Communications, 83, 2211-2223. &gt;https://doi.org/10.1007/s11277-015-2510-3 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Eddy, J., Miner, N.E. and Stamp, J. (2017) Sandia’s Microgrid Design Toolkit. The Electricity Journal, 30, 62-67. &gt;https://doi.org/10.1016/j.tej.2017.04.002 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Sgouras, K.I., Birda, A.D. and Labridis, D.P. (2014) Cyber Attack Impact on Critical Smart Grid Infrastructures. Innovative Smart Grid Technologies 2014, Washington, 19-22 February 2014, 1-5. &gt;https://doi.org/10.1109/isgt.2014.6816504 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Yi, P., Zhu, T., Zhang, Q., Wu, Y. and Pan, L. (2016) Puppet Attack: A Denial of Service Attack in Advanced Metering Infrastructure Network. Journal of Network and Computer Applications, 59, 325-332. &gt;https://doi.org/10.1016/j.jnca.2015.04.015 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Wei, J. and Kundur, D. (2012) A Flocking-Based Model for DoS-Resilient Communication Routing in Smart Grid. 2012 IEEE Global Communications Conference, Anaheim, 3-7 December 2012, 3519-3524. &gt;https://doi.org/10.1109/glocom.2012.6503660 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     RF Wireless World (2012) Wireless Vendors and Resources.&gt;https://www.rfwireless-world.com/Articles/Smart-Grid-Architecture-basics-and-working.html
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Fang, B., Yin, X., Tan, Y., Li, C., Gao, Y., Cao, Y., et al. (2016) The Contributions of Cloud Technologies to Smart Grid. Renewable and Sustainable Energy Reviews, 59, 1326-1331. &gt;https://doi.org/10.1016/j.rser.2016.01.032 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Otuoze, A.O., Mustafa, M.W. and Larik, R.M. (2018) Smart Grids Security Challenges: Classification by Sources of Threats. Journal of Electrical Systems and Information Technology, 5, 468-483. &gt;https://doi.org/10.1016/j.jesit.2018.01.001 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Shrestha, M., Johansen, C., Noll, J. and Roverso, D. (2020) A Methodology for Security Classification Applied to Smart Grid Infrastructures. International Journal of Critical Infrastructure Protection, 28, Article 100342. &gt;https://doi.org/10.1016/j.ijcip.2020.100342 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Demir, K., Ismail, H., Vateva-Gurova, T. and Suri, N. (2018) Securing the Cloud-Assisted Smart Grid. International Journal of Critical Infrastructure Protection, 23, 100-111. &gt;https://doi.org/10.1016/j.ijcip.2018.08.004 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ylmaz, E.N., Ciylan, B., Gonen, S., Sindiren, E. and Karacayilmaz, G. (2018) Cyber Security in Industrial Control Systems: Analysis of DoS Attacks against PLCs and the Insider Effect. 2018 6th International Istanbul Smart Grids and Cities Congress and Fair, Istanbul, 25-26 April 2018, 81-85. &gt;https://doi.org/10.1109/sgcf.2018.8408947 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref14">
    <label>14</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Liu, R., Vellaithurai, C., Biswas, S.S., Gamage, T.T. and Srivastava, A.K. (2015) Analyzing the Cyber-Physical Impact of Cyber Events on the Power Grid. IEEE Transactions on Smart Grid, 6, 2444-2453. &gt;https://doi.org/10.1109/tsg.2015.2432013 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref15">
    <label>15</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Efthymiou, C. and Kalogridis, G. (2010) Smart Grid Privacy via Anonymization of Smart Metering Data. 2010 First IEEE International Conference on Smart Grid Communications, Gaithersburg, 4-6 October 2010, 238-243. &gt;https://doi.org/10.1109/smartgrid.2010.5622050 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref16">
    <label>16</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Pour, M.M., Anzalchi, A. and Sarwat, A. (2017) A Review on Cyber Security Issues and Mitigation Methods in Smart Grid Systems. SoutheastCon 2017, Concord, 30 March-2 April 2017, 1-4. &gt;https://doi.org/10.1109/secon.2017.7925278 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref17">
    <label>17</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Yadav, T. and Rao, A.M. (2015) Technical Aspects of Cyber Kill Chain. In: Abawajy, J.H., Mukherjea, S., Thampi, S.M. and Ruiz-Martínez, A., Eds., Security in Computing and Communications, Springer International Publishing, 438-452. &gt;https://doi.org/10.1007/978-3-319-22915-7_40 
    </mixed-citation>
   </ref>
   <ref id="scirp.135683-ref18">
    <label>18</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Cisco (n.d.) Cisco Models Specifications. &gt;https://cisco.com
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>