Skip to content

Distributed SDN control for securing DNP3 protocol-based communications in smart grids

TL;DR

Results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.

Abstract

Legacy Distributed Network Protocol 3 (DNP3) communications remain widely used in modem smart grids, but they expose geographically distributed power infrastructure to coordinated cyberattacks that combine protocol-level command abuse with network-layer disruption. These threats require a defense framework that can detect multi-class attacks with low latency while also reasoning over source authorization, command semantics, and topology context to produce safe, auditable mitigation actions. This thesis presents GridCAD-LLM, a distributed software-defined networking framework for resilient DNP3 defense that integrates cloud-assisted multiclass traffic detection, source-aware event interpretation, and topology-grounded policy synthesis through a large language model. The framework combines distributed ONOS controllers, an Atomix-backed consensus layer, and a cloud-hosted multilayer perceptron to detect ten DNP3 attack classes and coordinate mitigation across grid regions. For administrative command-abuse events involving masteronly function codes, GridCAD-LLM uses DNP3 command semantics, victim-response evidence, and live ONOS topology context to generate validated SDN enforcement blueprints under explicit safety constraints. Evaluation in a geo-distributed AWS-based testbed shows 99.5 percent classification accuracy for routine attack classes, cloud-offloaded inference latency under 100 ms, and coordinated policy-update latency below 15 ms. Across 100 balanced command-abuse simulations, the policy-synthesis pipeline achieves 99 percent correctness with average inference latency below 2 s, while live retrieval-augmented updates improve heldout correctness from 94 percent to 100 percent. These results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.

View source

Similar papers

Conference Open access 2026

Mitigating Security Challenges in 5G Wireless Networks

An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is provided.

F. Philip-Kpae, A. Imoize, K. .. Okafor et al. · 0 citations
Open access 2026

DDoS Defense Model on 5G Network Slices

A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.

Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al. · 0 citations
Jul 2026

DISCO: Distributed Spectrum Compliance and Orchestration for Scalable IoT Coexistence

Distributed Spectrum Compliance and Orchestration (DISCO) is introduced, a hierarchical architecture that separates local spectrum learning from edge-level compliance regulation and slower cloud or non-terrestrial-network context adaptation.

L. S. Saoud, Moussa Ayyash · 0 citations
Open access Aug 2026

APATCP: programmable multi-controller framework for real-time detection and mitigation of complex TCP flooding attacks in SD-IoT networks

The exponential growth of the Internet of Things (IoT) has magnified vulnerability to Distributed Denial-of-Service (DDoS) threats, particularly advanced TCP flooding attacks that exploit protocol weaknesses to disrupt services and overwhelm constrained devices. Existing Software-Defined Networking (SDN) defenses often suffer from scalability bottlenecks, high controller overhead, and limited adaptability to evolving traffic dynamics. To overcome these challenges, this paper proposes APATCP, a P4-enabled, multi-controller SD-IoT framework for real-time adaptive detection and mitigation of TCP flooding. APATCP integrates four coordinated modules: Adaptive Collaborative Intrusion Defense (ACID) for decentralized intelligence sharing; Dynamic Traffic Anomaly Mitigation (DTAM) for adaptive thresholding and flow isolation; Dynamic Threat-Adaptive Classifier (DTAC), which leverages 24 P4-extracted features and an adaptive weighted ensemble classifier for complex multi-type attack classification; and FlowGuard-AP, a context-aware mitigation engine with dynamic response strategies. Evaluation across three IoT-centric datasets—CICIoT2024, Edge-IIoTset, and ToN_IoT—demonstrates superior performance, with APATCP achieving 99.3–99.98% accuracy, 98.2–99.5% recall, F1-scores up to 99.2%, and false positive rates as low as 0.4%. In binary classification, it consistently outperformed baselines such as LightGBM (97.5–97.8%) and XGBoost (96.7–97.1%). In multi-class evaluations spanning eight adversarial scenarios—including burst floods, hybrid multi-vector campaigns, and stealthy microbursts—the framework maintained > 98% accuracy while remaining operationally stable. Live emulations confirmed resilience under > 100k packets/s attack rates, keeping CPU load below 30%, packet loss under 2%, and end-to-end latency below 100 ms, while restoring throughput to over 95% of baseline within seconds. These results establish APATCP as a scalable, adaptive, and resource-efficient framework that delivers high detection accuracy, low overhead, and robust mitigation, ensuring reliable defense for next-generation SD-IoT infrastructures against increasingly sophisticated TCP flooding threats.

Ashraf Alyanbaawi, A. Hassan, Marwa M. Khashaba et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.