Skip to Main Content
In this paper, we propose a distributed, light-weight and fast intrusion detection approach suitable for implementation across multiple resource constrained SCADA field devices in the smart grid. The predictable and regular nature of the SCADA communication patterns is exploited to detect intrusions in the field devices. The novel approach is anomaly-based, uses the Bloom filter data structure for memory efficiency and incorporates the physical state of the power system for greater robustness. The proposed method is tested using MODBUS protocol used for communication between a SCADA server and field devices in a SCADA system.