PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 25, 2026Journal of Cybersecurity and Privacy3 citationsOpen Access

Tracking Real-Time Anomalies in Cyber–Physical Systems Through Dynamic Behavioral Analysis

View Full Paper
PKP. KrishnamurthyARAli RastehRKRamesh Karri

Key Points

  • This research aims to develop a framework for real-time anomaly detection in cyber-physical systems, particularly in smart grid substations and SCADA systems.
  • Proposed framework processes raw network packets for real-time monitoring.
  • Utilized hierarchical semantic extraction and tag processing pipeline.
  • Anomalies detected by evaluating events against expected temporal properties.
  • Tested methodology on hardware in the loop testbed under various cyber-attack scenarios.
  • Successfully detected and localized anomalies in real time.
  • Demonstrated efficacy of framework under multiple attack scenarios on physical devices.
  • Implemented on a dynamic power system simulator integrated with real-time automation controllers and relays.

Abstract

Embedded devices in modern power systems offer increased connectivity and remote reprogrammability/reconfigurability. These features along with interconnections between Information Technology (IT) and Operational Technology (OT) networks enable greater agility, reduced operator workload, and enhanced power system performance and capabilities, as well as expanding the cyber-attack surface. This increased cyber-attack surface, as well as increasingly complex, diverse, and potentially untrustworthy software/hardware supply chains, increases the need for robust real-time monitoring in power systems, and more generally in cyber–physical systems (CPS). We propose a novel framework for real-time monitoring and anomaly detection in CPS, specifically smart grid substations and SCADA systems. The proposed framework enables real-time signal temporal logic condition-based anomaly monitoring by processing raw captured packets from the communication network through a hierarchical semantic extraction and tag processing pipeline into a time series of semantic events and observations, that are then evaluated against expected temporal properties to detect and localize anomalies. We demonstrate the efficacy of our methodology on a hardware in the loop (HITL) testbed under several attack scenarios. The HITL testbed includes multiple physical power system devices (real-time automation controllers and relays) and simulated devices (Phasor Measurement Units—PMUs, relays, Phasor Data Concentrators—PDCs), all interfaced to a dynamic power system simulator.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Krishnamurthy et al. (2026) studied this question.

synapsesocial.com/papers/69c37b11b34aaaeb1a67d2e5https://doi.org/10.3390/jcp6020055
Ask AI
Helpful
Bookmark
Share
View Full Paper