IEC 61850 tabanlı akıllı şebekelerde zaman kısıtlı nondeterministik sonlu otomata (TC-NFA) ile anomali tespiti
Anomaly detection in IEC 61850-based smart grids using time-constrained nondeterministic finite automata (TC-NFA)
- Tez No: 1018178
- Danışmanlar: DR. ÖĞR. ÜYESİ MUSA BALTA
- Tez Türü: Yüksek Lisans
- Konular: Enerji, Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Energy, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: Belirtilmemiş.
- Yıl: 2026
- Dil: Türkçe
- Üniversite: Sakarya Üniversitesi
- Enstitü: Fen Bilimleri Enstitüsü
- Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Siber Güvenlik Bilim Dalı
- Sayfa Sayısı: Belirtilmemiş.
Özet
Enerji sistemleri, modern toplumların ekonomik, sosyal ve teknolojik faaliyetlerinin kesintisiz sürdürülebilmesi için kritik öneme sahip altyapılar arasında yer almaktadır. Elektrik üretimi, iletimi ve dağıtımı süreçlerinin güvenilir şekilde yürütülmesi; sanayi, sağlık, ulaşım ve iletişim gibi birçok sektörün doğrudan enerjiye bağımlı olması nedeniyle büyük önem taşımaktadır. Son yıllarda enerji sistemlerinde dijitalleşmenin hız kazanması, akıllı şebeke teknolojilerinin yaygınlaşması ve endüstriyel haberleşme ağlarının daha fazla kullanılmaya başlanmasıyla birlikte bu sistemler siber tehditlere karşı daha açık hâle gelmiştir. Özellikle IEC 61850 standardına dayalı olarak çalışan akıllı trafo merkezlerinde kullanılan GOOSE (Generic Object-Oriented Substation Event) ve MMS (Manufacturing Message Specification) protokolleri, gerçek zamanlı veri iletişimi ve koruma sistemlerinin koordinasyonu açısından kritik rol üstlenmektedir. Ancak bu protokollerin zamanlama ve olay sıralaması açısından hassas yapısı, çeşitli siber saldırılar sonucunda sistem güvenliğinin ve sürekliliğinin tehlikeye girmesine neden olabilmektedir. Bu nedenle enerji sistemlerinde meydana gelebilecek anormal davranışların erken aşamada ve güvenilir şekilde tespit edilmesi, sistem güvenliği açısından önemli bir gereklilik olarak ortaya çıkmaktadır. Bu tez çalışmasında, enerji sistemlerine ait ağ trafiğinde davranış tabanlı anomali tespiti gerçekleştirmek amacıyla Zamansal Kısıtlamaya Dayalı Belirsiz Sonlu Otomat (Temporal Constraint-Based Non-deterministic Finite Automaton – TC-NFA) tabanlı yeni bir yöntem önerilmiştir. Önerilen yaklaşım, mevcut birçok anomali tespit yönteminden farklı olarak yalnızca paket içeriklerini veya istatistiksel ağ özelliklerini incelemekle sınırlı kalmamakta; sistemde gerçekleşen olayların sıralı yapısını ve olaylar arasındaki zaman ilişkilerini de dikkate almaktadır. Böylece saldırganların geçerli protokol mesajları kullanarak gerçekleştirdiği ancak olay sırasını veya zamanlamasını bozduğu saldırı senaryolarının tespit edilmesi amaçlanmaktadır. Geliştirilen TC-NFA modeli, yalnızca normal çalışma koşullarında elde edilen ağ trafiği verileri kullanılarak eğitilmektedir. Bu sayede modele saldırı verilerinin etiketlenerek sunulmasına ihtiyaç duyulmamakta ve daha önce görülmemiş saldırı türlerine karşı da uyum sağlanabilmektedir. Model içerisinde her olay bir sembol olarak tanımlanmakta ve olaylar arasındaki geçişler NFA yapısı kullanılarak temsil edilmektedir. Ayrıca her geçiş için zamansal davranışı ifade eden istatistiksel profiller oluşturulmaktadır. Olaylar arasındaki zaman farkları analiz edilirken medyan ve Medyan Mutlak Sapma (Median Absolute Deviation – MAD) gibi aykırı değerlere karşı dayanıklı istatistiksel yöntemlerden yararlanılmaktadır. Elde edilen zamansal sapmalar, olayların normal davranıştan ne ölçüde uzaklaştığını gösteren anomali skorlarına dönüştürülmektedir. Nihai anomali kararı ise olay bazlı skorların belirli bir zaman penceresi içerisinde biriktirilmesi ve önceden belirlenen eşik değerleriyle karşılaştırılması sonucunda verilmektedir. Önerilen yaklaşım, IEC 61850 tabanlı gerçekçi enerji sistemi senaryolarından elde edilen ağ trafiği verileri üzerinde test edilmiştir. Deneysel değerlendirmelerde doğruluk, kesinlik, duyarlılık ve F1-skoru gibi yaygın performans metrikleri kullanılmıştır. Elde edilen sonuçlar, TC-NFA modelinin hem normal işletim koşullarında hem de farklı saldırı senaryolarında yüksek başarı oranı sergilediğini göstermiştir. Ayrıca modelin yalnızca bilinen saldırıları değil, daha önce eğitim verilerinde yer almayan yeni saldırı türlerini de tespit edebildiği gözlemlenmiştir. Açıklanabilir yapısı sayesinde anomaliye neden olan olayların ve zaman sapmalarının izlenebilmesi mümkün olmakta, düşük hesaplama maliyeti ise gerçek zamanlı uygulamalarda kullanılabilirliğini artırmaktadır. Sonuç olarak bu çalışma, enerji sistemlerinde davranışsal analiz ile zaman farkındalığını bir araya getiren TC-NFA tabanlı yenilikçi bir anomali tespit yaklaşımı sunarak literatüre katkı sağlamayı ve kritik enerji altyapılarının siber güvenliğinin artırılmasına destek olmayı amaçlamaktadır.
Özet (Çeviri)
Energy systems constitute one of the most critical infrastructures of modern society, providing the foundation for economic activities, industrial production, transportation, healthcare services, and communication networks. The continuous and reliable operation of these systems is essential for maintaining social and economic stability. In recent years, the rapid digital transformation of power systems and the widespread adoption of smart grid technologies have significantly increased the dependence of energy infrastructures on information and communication technologies. While this transformation has improved operational efficiency, automation capabilities, and monitoring accuracy, it has also expanded the cyberattack surface of critical energy infrastructures. Consequently, cybersecurity has become a major concern for operators, researchers, and policymakers responsible for protecting modern power systems. Within modern substations, the IEC 61850 standard has emerged as the dominant communication framework for enabling interoperability among Intelligent Electronic Devices (IEDs). IEC 61850 provides standardized communication mechanisms that facilitate real-time information exchange and support advanced automation functions. Among the communication services defined by the standard, Generic Object-Oriented Substation Event (GOOSE) messages and Manufacturing Message Specification (MMS) communications play particularly important roles. GOOSE messages are designed for high-speed, time-critical communication between protection and control devices, while MMS is primarily used for monitoring, configuration, and supervisory control operations. Because these protocols are essential for maintaining reliable and deterministic system behavior, any disruption, manipulation, or unauthorized modification of their communication patterns may lead to severe operational consequences, including equipment damage, service interruption, and large-scale power outages. Traditional intrusion detection systems often rely on signature-based methods or feature-oriented machine learning techniques. While these approaches can successfully detect previously known attack patterns, they frequently struggle to identify novel or sophisticated attacks that exploit legitimate communication protocols. Furthermore, many existing solutions focus primarily on packet contents, statistical network features, or traffic volume characteristics, while neglecting the sequential and temporal relationships that naturally exist between communication events. In industrial control systems and smart substations, however, system behavior is often defined not only by the occurrence of individual messages but also by the order in which events occur and the timing constraints governing their interactions. Consequently, attacks that preserve protocol validity while altering event sequences or timing characteristics may evade conventional detection mechanisms. To address these challenges, this thesis proposes a novel behavioral anomaly detection framework based on Temporal Constraint-Based Non-deterministic Finite Automata (TC-NFA). The proposed approach models normal system behavior by simultaneously considering event sequences and temporal dependencies between consecutive events. Rather than treating network packets as isolated observations, the method represents system activities as sequences of symbolic events whose transitions are governed by a finite-state behavioral model. By integrating temporal constraints into the state transition mechanism, the proposed framework captures both logical and timing-related characteristics of normal operational processes. One of the primary advantages of the proposed TC-NFA model is its unsupervised learning capability. The framework is trained exclusively using normal operational traffic and therefore does not require labeled attack datasets. This characteristic is particularly important in critical infrastructure environments, where obtaining representative and comprehensive attack data is often difficult, expensive, or impractical. Furthermore, because the model learns the normal behavior of the system rather than specific attack signatures, it possesses the potential to detect previously unseen attack scenarios and zero-day threats. During the model construction phase, each network event is transformed into a symbolic representation based on selected protocol attributes and communication characteristics. These symbols serve as the alphabet of the finite automaton. The observed event sequences are then used to construct the non-deterministic finite automaton, where states represent behavioral contexts and transitions represent observed event relationships. For every transition, temporal profiles are generated to characterize the expected timing behavior between consecutive events. To establish robust temporal constraints, the proposed framework employs statistical techniques that are resistant to outliers and noise. Specifically, the Median and Median Absolute Deviation (MAD) are utilized to model the distribution of inter-event time differences. Unlike conventional statistical measures such as the mean and standard deviation, these robust estimators are less sensitive to abnormal observations and provide more reliable representations of typical system behavior. For each transition, the median inter-arrival time is calculated and used as a central reference point, while the MAD is employed to estimate the acceptable variability range. This temporal profile enables the system to quantify deviations from expected timing patterns. During online monitoring, incoming network events are processed sequentially and matched against the learned TC-NFA model. For each observed transition, both structural conformity and temporal consistency are evaluated. Structural anomalies occur when unexpected transitions, states, or event sequences are encountered. Temporal anomalies arise when the observed timing behavior deviates significantly from the learned temporal constraints. These deviations are converted into anomaly scores that reflect the degree of behavioral inconsistency. Instead of making decisions solely on individual events, the framework accumulates anomaly evidence over time, allowing it to identify persistent abnormal behavior while reducing sensitivity to isolated fluctuations and measurement noise. The final anomaly detection decision is produced through a threshold-based evaluation mechanism. Cumulative anomaly scores are compared against predefined thresholds to determine whether the observed behavior corresponds to normal operation or potential malicious activity. This approach provides flexibility in balancing detection sensitivity and false positive rates according to operational requirements. To evaluate the effectiveness of the proposed method, extensive experiments were conducted using network traffic datasets generated from realistic IEC 61850-based substation environments. The evaluation scenarios included both normal operational conditions and various cyberattack situations designed to manipulate communication behavior. Experimental performance was assessed using commonly accepted metrics, including accuracy, precision, recall, and F1-score. The results demonstrate that the TC-NFA framework achieves high detection performance while maintaining balanced behavior across different attack categories. The experimental findings further indicate that incorporating temporal constraints significantly improves the ability to detect attacks that would otherwise appear legitimate from a protocol perspective. In particular, attacks involving message replay, timing manipulation, sequence alteration, and protocol misuse were effectively identified due to the model's awareness of both event ordering and temporal characteristics. Moreover, because the framework is based on behavioral modeling rather than attack signatures, it exhibited strong generalization capabilities when confronted with previously unseen attack patterns. Beyond detection performance, the proposed approach offers additional practical advantages. The finite automaton representation provides a transparent and interpretable model structure, enabling security analysts to understand the reasons behind anomaly decisions. This explainability is particularly valuable in critical infrastructure environments, where trust, accountability, and operational transparency are essential requirements. Furthermore, the computational simplicity of finite automata and robust statistical calculations results in low processing overhead, making the framework suitable for real-time deployment in resource-constrained industrial environments. In conclusion, this thesis introduces a novel anomaly detection methodology that combines behavioral modeling, temporal awareness, and automata-based representation for securing IEC 61850-based energy systems. By leveraging Temporal Constraint-Based Non-deterministic Finite Automata and robust temporal profiling techniques, the proposed framework effectively captures normal operational behavior and identifies deviations associated with cyberattacks. The experimental results demonstrate that the approach provides accurate, explainable, and computationally efficient anomaly detection capabilities while maintaining strong adaptability to previously unseen threats. The proposed method contributes to the growing body of research on cybersecurity for critical infrastructures and offers a practical solution for enhancing the resilience and security of modern smart grid environments. Beyond its immediate application in substation environments, the proposed framework can also be adapted to other industrial control systems that rely on time-sensitive communication protocols. Future work may focus on integrating deep learning-based feature extraction mechanisms with the TC-NFA model to further enhance detection capability in highly complex and heterogeneous network environments. Additionally, deploying the system in real-world operational substations would provide valuable insights into long-term stability, scalability, and real-time performance under production-level constraints.
Benzer Tezler
- Akıllı dağıtım şebekelerinde adaptif koruma koordinasyon sistemi
Adaptive protection coordination system in smart distribution networks
FURKAN AHMET TAMYİĞİT
Yüksek Lisans
Türkçe
2022
Elektrik ve Elektronik Mühendisliğiİstanbul Üniversitesi-CerrahpaşaElektrik ve Elektronik Mühendisliği Ana Bilim Dalı
DOÇ. DR. İBRAHİM GÜNEŞ
DR. ÖĞR. ÜYESİ ABDULFETAH ABDELA SHOBOLE
- Enerji sistemlerinde siber güvenlik
Cybersecurity in power systems
ABDULVEHHAB AĞIN
Doktora
Türkçe
2025
Elektrik ve Elektronik Mühendisliğiİstanbul Teknik ÜniversitesiElektrik Mühendisliği Ana Bilim Dalı
PROF. DR. AYŞEN DEMİRÖREN
- Predictive maintenance in substation automation system using deep learning
Derin öğrenme ile trafo merkezi otomasyon sisteminde kestirimci bakım
SARMAD NAJEEB HABEEB ALABBAD
Doktora
İngilizce
2026
Elektrik ve Elektronik MühendisliğiKarabük ÜniversitesiElektrik-Elektronik Mühendisliği Ana Bilim Dalı
DOÇ. DR. HÜSEYİN ALTINKAYA
- Elektrik şebekelerinde telekoruma olarak ıec 61850 uygulaması
Application of iec 61850 as teleprotection in electrical networks
İHSAN ALTUN
Yüksek Lisans
Türkçe
2018
Elektrik ve Elektronik MühendisliğiKocaeli ÜniversitesiElektrik Mühendisliği Ana Bilim Dalı
PROF. DR. AYŞEN BASA ARSOY
- Akıllı şebekeler ve orta gerilim uygulamaları
Smart grids and medium voltage applications
YASİN ÇOKSÜRER
Yüksek Lisans
Türkçe
2013
Elektrik ve Elektronik MühendisliğiGazi ÜniversitesiElektrik-Elektronik Mühendisliği Ana Bilim Dalı
PROF. DR. M.CENGİZ TAPLAMACIOĞLU