Cybersecurity breaches targeting electrical substations constitute a significant threat to the integrity of the power grid, necessitating comprehensive defense and mitigation strategies. Any anomaly in information and communication technology (ICT) should be detected for secure communications between devices in digital substations. This paper proposes large language models (LLM), e.g., ChatGPT, for the cybersecurity of IEC 61850-based digital substation communications. Multicast messages such as generic object oriented substation event (GOOSE) and sampled value (SV) are used for case studies. The proposed LLM-based cybersecurity framework includes for the first time data pre-processing of communication systems and human-in-the-loop (HITL) training (considering the cybersecurity guidelines recommended by humans). The results show a comparative analysis of detected anomaly data carried out based on the performance evaluation metrics for different LLMs. A hardware-in-the-loop (HIL) testbed is used to generate and extract a dataset of IEC 61850 communications.
翻译:针对变电站的网络攻击对电网完整性构成重大威胁,需要全面的防御与缓解策略。为确保数字变电站中设备间的安全通信,信息技术与通信系统(ICT)中的任何异常都应被检测。本文提出使用大型语言模型(LLM),例如ChatGPT,来保障基于IEC 61850的数字变电站通信安全。案例研究以通用面向对象变电站事件(GOOSE)和采样值(SV)等多播消息为例。所提出的基于LLM的网络安全框架首次集成了通信系统的数据预处理与人在环(HITL)训练(考虑人类推荐的网络安全准则)。结果基于不同LLM的性能评估指标,对所检测的异常数据进行了比较分析。采用硬件在环(HIL)测试平台生成并提取IEC 61850通信数据集。