A Protection Method Based on Message Identification and Flow Monitoring for Managing the Congestion Arising From Network Attacks on Smart Substation

The information security of smart substations has become a major issue, as substations become increasingly dependent on communication networks. This letter analyzes the data flows in the communication networks of smart substations and proposes a protection method based on message identification and flow monitoring for managing the congestion arising from network attacks. This method implements the rapid identification and filtering of messages by condensing key information into a message information tag and then examines the tag along with the traffic rates at switches to identify and discard counterfeit messages. OPNET simulation results show that the method successfully identifies and discards counterfeit messages and avoids timeouts and packet drops in the transmission process of authentic messages during periods of congestion.