RT Conference Proceedings T1 Substation-Aware. An intrusion detection system for the IEC 61850 protocol. A1 Lopez, Jose Antonio A1 Angulo, Iñaki A1 Martinez, Saturnino AB The number of cyberattacks against the Smart Grid has increased in the last years. Considered as a critical infrastructure, power system operators must improve the cybersecurity countermeasures of their installations. Intrusion Detection Systems (IDS) appears as a promising solution to detect hidden activity of the hackers before launching the attack. Most detection tools are generalist, designed to find predefined patterns such as frequency of messages, well-known malware packets, source and destination of the messages or the content of each packet itself. These tools also allow plugging modules for different protocols, offering a better understanding of the analysed data, such as the protocol action (read, write, reset...) or data model/schema understanding. However, the semantics of the data transmitted cannot be inferred. The Substation-Aware (SBT-Aware) tool adds the latest feature for primary and secondary substations, taking into account not only the protocols defined in the IEC 61850 standard, but the substation topology as well. In this paper we present the SBT-Aware, an IDS that has been developed and tested in the course of the H2020 SDN-microSENSE project. PB Association for Computing Machinery SN 978-145039670-7 SN 9781450396707 YR 2022 FD 2022-08-23 LA eng NO Lopez , J A , Angulo , I & Martinez , S 2022 , Substation-Aware. An intrusion detection system for the IEC 61850 protocol. in unknown . ACM International Conference Proceeding Series , Association for Computing Machinery , pp. 1-7 , 17th International Conference on Availability, Reliability and Security, ARES 2022 , Vienna , Austria , 23/08/22 . https://doi.org/10.1145/3538969.3543818 NO conference NO Publisher Copyright: © 2022 Owner/Author. DS TECNALIA Publications RD 29 sept 2024