Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach

Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, t...

全面介紹

書目詳細資料
發表在:International Journal of Sustainable Construction Engineering and Technology
主要作者: 2-s2.0-85184894473
格式: Article
語言:English
出版: Penerbit UTHM 2023
在線閱讀:https://www.scopus.com/inward/record.uri?eid=2-s2.0-85184894473&doi=10.30880%2fIJSCET.2023.14.03.018&partnerID=40&md5=b7b5b6e36ce71d4ddd1c72e221863198
id Rahim F.A.; Ahmad N.A.; Magalingam P.; Jamil N.; Cob Z.C.; Salahudin L.
spelling Rahim F.A.; Ahmad N.A.; Magalingam P.; Jamil N.; Cob Z.C.; Salahudin L.
2-s2.0-85184894473
Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
2023
International Journal of Sustainable Construction Engineering and Technology
14
3
10.30880/IJSCET.2023.14.03.018
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85184894473&doi=10.30880%2fIJSCET.2023.14.03.018&partnerID=40&md5=b7b5b6e36ce71d4ddd1c72e221863198
Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, these tools must be properly secured to prevent the grid from becoming more vulnerable to cyber-attacks. This study proposes a threat modeling and risk assessment approach tailored to smart grids incorporating solar PV systems. The approach involves identifying, assessing, and mitigating risks through threat modeling and risk assessment. A threat model is designed by adapting and applying general threat modeling steps to the context of smart grids with solar PV. The process involves the identification of device assets and access points within the smart grid infrastructure. Subsequently, the threats to these devices were classified utilizing the STRIDE model. To further prioritize the identified threat, the DREAD threat-risk ranking model is employed. The threat modeling stage reveals several high-risk threats to the smart grid infrastructure, including Information Disclosure, Elevation of Privilege, and Tampering. Targeted recommendations in the form of mitigation controls are formulated to secure the smart grid’s posture against these identified threats. The risk ratings provided in this study offer valuable insights into the cybersecurity risks associated with smart grids incorporating solar PV systems, while also providing practical guidance for risk mitigation. Tailored mitigation strategies are proposed to address these vulnerabilities. By taking proactive measures, energy sector stakeholders may strengthen the security of their smart grid infrastructure and protect critical operations from potential cyber threats. © 2023, Penerbit UTHM. All rights reserved.
Penerbit UTHM
21803242
English
Article
All Open Access; Gold Open Access; Green Open Access
author 2-s2.0-85184894473
spellingShingle 2-s2.0-85184894473
Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
author_facet 2-s2.0-85184894473
author_sort 2-s2.0-85184894473
title Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
title_short Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
title_full Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
title_fullStr Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
title_full_unstemmed Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
title_sort Cybersecurity Vulnerabilities in Smart Grids with Solar Photovoltaic: A Threat Modelling and Risk Assessment Approach
publishDate 2023
container_title International Journal of Sustainable Construction Engineering and Technology
container_volume 14
container_issue 3
doi_str_mv 10.30880/IJSCET.2023.14.03.018
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-85184894473&doi=10.30880%2fIJSCET.2023.14.03.018&partnerID=40&md5=b7b5b6e36ce71d4ddd1c72e221863198
description Cybersecurity is a growing concern for smart grids, especially with the integration of solar photovoltaics (PVs). With the installation of more solar and the advancement of inverters, utilities are provided with real-time solar power generation and other information through various tools. However, these tools must be properly secured to prevent the grid from becoming more vulnerable to cyber-attacks. This study proposes a threat modeling and risk assessment approach tailored to smart grids incorporating solar PV systems. The approach involves identifying, assessing, and mitigating risks through threat modeling and risk assessment. A threat model is designed by adapting and applying general threat modeling steps to the context of smart grids with solar PV. The process involves the identification of device assets and access points within the smart grid infrastructure. Subsequently, the threats to these devices were classified utilizing the STRIDE model. To further prioritize the identified threat, the DREAD threat-risk ranking model is employed. The threat modeling stage reveals several high-risk threats to the smart grid infrastructure, including Information Disclosure, Elevation of Privilege, and Tampering. Targeted recommendations in the form of mitigation controls are formulated to secure the smart grid’s posture against these identified threats. The risk ratings provided in this study offer valuable insights into the cybersecurity risks associated with smart grids incorporating solar PV systems, while also providing practical guidance for risk mitigation. Tailored mitigation strategies are proposed to address these vulnerabilities. By taking proactive measures, energy sector stakeholders may strengthen the security of their smart grid infrastructure and protect critical operations from potential cyber threats. © 2023, Penerbit UTHM. All rights reserved.
publisher Penerbit UTHM
issn 21803242
language English
format Article
accesstype All Open Access; Gold Open Access; Green Open Access
record_format scopus
collection Scopus
_version_ 1828987866452066304