{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,28]],"date-time":"2025-08-28T12:36:57Z","timestamp":1756384617601,"version":"3.40.3"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031641701"},{"type":"electronic","value":"9783031641718"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-64171-8_25","type":"book-chapter","created":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T11:02:33Z","timestamp":1720609353000},"page":"483-502","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["SecMonS: A Security Monitoring Framework for\u00a0IEC 61850 Substations Based on\u00a0Configuration Files and\u00a0Logs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2489-8981","authenticated-orcid":false,"given":"Onur","family":"Duman","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7457-5198","authenticated-orcid":false,"given":"Mengyuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7441-7541","authenticated-orcid":false,"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3015-3043","authenticated-orcid":false,"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,9]]},"reference":[{"key":"25_CR1","unstructured":"Analysis of the cyber attack on the Ukrainian power grid. https:\/\/www.sans.org\/webcasts\/analyzing-ukrainian-power-grid-cyber-attacks-102007, Accessed 29 May 2023"},{"key":"25_CR2","unstructured":"Current CVSS score distribution for all vulnerabilities. https:\/\/www.cvedetails.com\/cvss-score-distribution.php, Accessed 29 May 2023"},{"key":"25_CR3","unstructured":"Power system test cases. https:\/\/pandapower.readthedocs.io\/en\/v2.4.0\/networks\/power_system_test_cases.html, Accessed 2 July 2023"},{"key":"25_CR4","unstructured":"Survey: 27 percent of IT professionals receive more than 1 million security alerts daily. https:\/\/www.imperva.com\/blog\/27-percent-of-it-professionals-receive-more-than-1-million-security-alerts-daily, Accessed 3 July 2023"},{"issue":"3","key":"25_CR5","doi-asserted-by":"publisher","first-page":"2676","DOI":"10.1109\/TSG.2019.2959937","volume":"11","author":"P Akaber","year":"2019","unstructured":"Akaber, P., et al.: Cases: concurrent contingency analysis-based security metric deployment for the smart grid. IEEE Trans. Smart Grid 11(3), 2676\u20132687 (2019)","journal-title":"IEEE Trans. Smart Grid"},{"key":"25_CR6","doi-asserted-by":"crossref","unstructured":"Ammann, P., Wijesekera, D., Kaushik, S.: Scalable, graph-based network vulnerability analysis. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 217\u2013224 (2002)","DOI":"10.1145\/586110.586140"},{"key":"25_CR7","doi-asserted-by":"crossref","unstructured":"Bhattarai, B., Huang, H.: Steinerlog: prize collecting the audit logs for threat hunting on enterprise network. In: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, pp. 97\u2013108 (2022)","DOI":"10.1145\/3488932.3523261"},{"key":"25_CR8","doi-asserted-by":"crossref","unstructured":"Biswas, P.P., Li, Y., Tan, H.C., Mashima, D., Chen, B.: An attack-trace generating toolchain for cybersecurity study of iec61850 based substations. In: 2020 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pp.\u00a01\u20137. IEEE (2020)","DOI":"10.1109\/SmartGridComm47815.2020.9302989"},{"key":"25_CR9","doi-asserted-by":"crossref","unstructured":"Biswas, P.P., Tan, H.C., Zhu, Q., Li, Y., Mashima, D., Chen, B.: A synthesized dataset for cybersecurity study of IEC 61850 based substation. In: 2019 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pp.\u00a01\u20137. IEEE (2019)","DOI":"10.1109\/SmartGridComm.2019.8909783"},{"key":"25_CR10","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1016\/j.comcom.2019.06.004","volume":"145","author":"D Borbor","year":"2019","unstructured":"Borbor, D., Wang, L., Jajodia, S., Singhal, A.: Optimizing the network diversity to improve the resilience of networks against unknown attacks. Comput. Commun. 145, 96\u2013112 (2019)","journal-title":"Comput. Commun."},{"key":"25_CR11","unstructured":"Code, P.: Communication networks and systems for power utility automation\u2013part 6: Configuration description language for communication in electrical substations related to IEDS (2010)"},{"issue":"2","key":"25_CR12","first-page":"1018","volume":"19","author":"O Duman","year":"2020","unstructured":"Duman, O., Zhang, M., Wang, L., Debbabi, M., Atallah, R.F., Lebel, B.: Factor of security (FOS): quantifying the security effectiveness of redundant smart grid subsystems. IEEE Trans. Dependable Secure Comput. 19(2), 1018\u20131035 (2020)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"25_CR13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s42162-020-0103-1","volume":"3","author":"S Hacks","year":"2020","unstructured":"Hacks, S., Katsikeas, S., Ling, E., Lagerstr\u00f6m, R., Ekstedt, M.: powerlang: a probabilistic attack simulation language for the power domain. Energy Inf. 3, 1\u201317 (2020)","journal-title":"Energy Inf."},{"key":"25_CR14","doi-asserted-by":"crossref","unstructured":"Hawrylak, P.J., Haney, M., Papa, M., Hale, J.: Using hybrid attack graphs to model cyber-physical attacks in the smart grid. In: 2012 5th International Symposium on Resilient Control Systems, pp. 161\u2013164. IEEE (2012)","DOI":"10.1109\/ISRCS.2012.6309311"},{"key":"25_CR15","doi-asserted-by":"crossref","unstructured":"Hong, J., Liu, C.C., Govindarasu, M.: Detection of cyber intrusions using network-based multicast messages for substation automation. In: ISGT 2014, pp.\u00a01\u20135. IEEE (2014)","DOI":"10.1109\/ISGT.2014.6816375"},{"issue":"22","key":"25_CR16","doi-asserted-by":"publisher","first-page":"6471","DOI":"10.3390\/s20226471","volume":"20","author":"CL Hsu","year":"2020","unstructured":"Hsu, C.L., Chen, W.X., Le, T.V.: An autonomous log storage management protocol with blockchain mechanism and access control for the internet of things. Sensors 20(22), 6471 (2020)","journal-title":"Sensors"},{"issue":"3","key":"25_CR17","doi-asserted-by":"publisher","first-page":"1445","DOI":"10.1109\/TII.2012.2228874","volume":"9","author":"DM Ingram","year":"2012","unstructured":"Ingram, D.M., Schaub, P., Taylor, R.R., Campbell, D.A.: Performance analysis of IEC 61850 sampled value process bus networks. IEEE Trans. Ind. Inform. 9(3), 1445\u20131454 (2012)","journal-title":"IEEE Trans. Ind. Inform."},{"key":"25_CR18","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Noel, S., Kalapa, P., Albanese, M., Williams, J.: Cauldron mission-centric cyber situational awareness with defense in depth. In: 2011-MILCOM 2011 Military Communications Conference, pp. 1339\u20131344. IEEE (2011)","DOI":"10.1109\/MILCOM.2011.6127490"},{"key":"25_CR19","doi-asserted-by":"publisher","first-page":"8547","DOI":"10.1007\/s10462-022-10381-4","volume":"56","author":"D Levshun","year":"2023","unstructured":"Levshun, D., Kotenko, I.: A survey on artificial intelligence techniques for security event correlation: models, challenges, and opportunities. Artif. Intell. Rev. 56, 8547\u20138590 (2023)","journal-title":"Artif. Intell. Rev."},{"issue":"1","key":"25_CR20","doi-asserted-by":"publisher","first-page":"740","DOI":"10.1109\/TDSC.2022.3143551","volume":"20","author":"T Li","year":"2022","unstructured":"Li, T., Jiang, Y., Lin, C., Obaidat, M.S., Shen, Y., Ma, J.: Deepag: attack graph construction and threats prediction with bi-directional deep learning. IEEE Trans. Dependable Secure Comput. 20(1), 740\u2013757 (2022)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"25_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-030-58295-1_4","volume-title":"Critical Information Infrastructures Security","author":"E Ling","year":"2020","unstructured":"Ling, E., Lagerstr\u00f6m, R., Ekstedt, M.: A systematic literature review of information sources for threat modeling in the power systems domain. In: Rashid, A., Popov, P. (eds.) CRITIS 2020. LNCS, vol. 12332, pp. 47\u201358. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58295-1_4"},{"key":"25_CR22","doi-asserted-by":"publisher","first-page":"100601","DOI":"10.1016\/j.ijcip.2023.100601","volume":"41","author":"ER Ling","year":"2023","unstructured":"Ling, E.R., Ekstedt, M.: A threat modeling language for generating attack graphs of substation automation systems. Int. J. Crit. Infrastruct. Prot. 41, 100601 (2023)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"issue":"2","key":"25_CR23","first-page":"731","volume":"19","author":"A Nadeem","year":"2021","unstructured":"Nadeem, A., Verwer, S., Moskal, S., Yang, S.J.: Alert-driven attack graph generation using S-PDFA. IEEE Trans. Dependable Secure Comput. 19(2), 731\u2013746 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"25_CR24","doi-asserted-by":"crossref","unstructured":"Nadeem, A., Verwer, S., Moskal, S., Yang, S.J.: Enabling visual analytics via alert-driven attack graphs. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 2420\u20132422 (2021)","DOI":"10.1145\/3460120.3485361"},{"key":"25_CR25","doi-asserted-by":"crossref","unstructured":"Nadeem, A., Verwer, S., Yang, S.J.: Sage: intrusion alert-driven attack graph extractor. In: 2021 IEEE Symposium on Visualization for Cyber Security (VizSec), pp. 36\u201341. IEEE (2021)","DOI":"10.1109\/VizSec53666.2021.00009"},{"key":"25_CR26","unstructured":"Ou, X., Govindavajhala, S., Appel, A.W., et\u00a0al.: Mulval: a logic-based network security analyzer. In: USENIX Security Symposium, vol.\u00a08, pp. 113\u2013128. Baltimore, MD (2005)"},{"key":"25_CR27","doi-asserted-by":"crossref","unstructured":"Pourmajidi, W., Miranskyy, A.: Logchain: Blockchain-assisted log storage. In: 2018 IEEE 11th International Conference on Cloud Computing (CLOUD), pp. 978\u2013982. IEEE (2018)","DOI":"10.1109\/CLOUD.2018.00150"},{"issue":"2","key":"25_CR28","first-page":"731","volume":"19","author":"A Presekal","year":"2023","unstructured":"Presekal, A., \u015etefanov, A., Rajkumar, V.S., Palensky, P.: Attack graph model for cyber-physical power systems using hybrid deep learning. IEEE Trans. Smart Grid 19(2), 731\u2013746 (2023)","journal-title":"IEEE Trans. Smart Grid"},{"key":"25_CR29","doi-asserted-by":"crossref","unstructured":"Rencelj\u00a0Ling, E., Ekstedt, M.: Generating threat models and attack graphs based on the IEC 61850 system configuration description language. In: Proceedings of the 2021 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, pp. 98\u2013103 (2021)","DOI":"10.1145\/3445969.3450421"},{"key":"25_CR30","doi-asserted-by":"crossref","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., Wing, J.M.: Automated generation and analysis of attack graphs. In: Proceedings 2002 IEEE Symposium on Security and Privacy, pp. 273\u2013284. IEEE (2002)","DOI":"10.1109\/SECPRI.2002.1004377"},{"key":"25_CR31","doi-asserted-by":"publisher","first-page":"100760","DOI":"10.1016\/j.iot.2023.100760","volume":"22","author":"P Silveira","year":"2023","unstructured":"Silveira, P., Silva, E.F., Galletta, A., Lopes, Y.: Security analysis of digitized substations: a systematic review of goose messages. Internet Things 22, 100760 (2023)","journal-title":"Internet Things"},{"key":"25_CR32","unstructured":"Sutton, R.S., Barto, A.G.: Reinforcement Learning: An Introduction. MIT Press, Cambridge (2018)"},{"key":"25_CR33","doi-asserted-by":"publisher","first-page":"156044","DOI":"10.1109\/ACCESS.2019.2948117","volume":"7","author":"TS Ustun","year":"2019","unstructured":"Ustun, T.S., Farooq, S.M., Hussain, S.S.: A novel approach for mitigation of replay and masquerade attacks in smartgrids using IEC 61850 standard. IEEE Access 7, 156044\u2013156053 (2019)","journal-title":"IEEE Access"},{"issue":"5","key":"25_CR34","doi-asserted-by":"publisher","first-page":"826","DOI":"10.3390\/sym13050826","volume":"13","author":"TS Ustun","year":"2021","unstructured":"Ustun, T.S., Hussain, S.S., Ulutas, A., Onen, A., Roomi, M.M., Mashima, D.: Machine learning-based intrusion detection for achieving cybersecurity in smart grids using IEC 61850 goose messages. Symmetry 13(5), 826 (2021)","journal-title":"Symmetry"},{"key":"25_CR35","doi-asserted-by":"crossref","unstructured":"Verwer, S., Hammerschmidt, C.A.: Flexfringe: a passive automaton learning package. In: 2017 IEEE International Conference on Software Maintenance and Evolution (ICSME), pp. 638\u2013642. IEEE (2017)","DOI":"10.1109\/ICSME.2017.58"},{"issue":"1","key":"25_CR36","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/TDSC.2013.24","volume":"11","author":"L Wang","year":"2013","unstructured":"Wang, L., Jajodia, S., Singhal, A., Cheng, P., Noel, S.: k-zero day safety: a network security metric for measuring the risk of unknown vulnerabilities. IEEE Trans. Dependable Secure Comput. 11(1), 30\u201344 (2013)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"1","key":"25_CR37","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1109\/TSG.2013.2280399","volume":"5","author":"S Zonouz","year":"2013","unstructured":"Zonouz, S., Davis, C.M., Davis, K.R., Berthier, R., Bobba, R.B., Sanders, W.H.: Socca: a security-oriented cyber-physical contingency analysis in power infrastructures. IEEE Trans. Smart Grid 5(1), 3\u201313 (2013)","journal-title":"IEEE Trans. Smart Grid"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-64171-8_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,23]],"date-time":"2024-11-23T21:41:59Z","timestamp":1732398119000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-64171-8_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031641701","9783031641718"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-64171-8_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"9 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lausanne","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Switzerland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva.org\/dimva2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}