Advanced cyber-attacks on smart grids expose limitations of conventional defenses, particularly for detecting protocol-compliant masquerading and supporting timely response. This paper presents GOOSEIDRS, a reproducible intrusion detection and response framework for the IEC 61850 GOOSE protocol. To support reproducible training and evaluation, we use a protocol-aware augmentation pipeline that extends limited Generic Object Oriented Substation Event (GOOSE) captures into long-duration masquerading traces, while Explainable Artificial Intelligence (XAI) supports decision auditing. We engineer a compact feature set centered on State Number (stNum)/Sequence Number (sqNum) semantics with timing context (inter-arrival time, rolling statistics, and violation indicators). Our LightGBM-based IDS operates online with a two-threshold warning/attack logic, achieves over 99% on accuracy, precision, recall, and F1-score, and triggers protocol-compliant corrective GOOSE responses in live HIL experiments. We evaluate the framework against state-dominant masquerading attacks and release the dataset and artifacts for reproducibility1.
Alberto et al. (Fri,) studied this question.