Distributed SDN control for securing DNP3 protocol-based communications in smart grids
Legacy Distributed Network Protocol 3 (DNP3) communications remain widely used in modem smart grids, but they expose geographically distributed power infrastructure to coordinated cyberattacks that combine protocol-level command abuse with network-layer disruption. These threats require a defense framework that can detect multi-class attacks with low latency while also reasoning over source authorization, command semantics, and topology context to produce safe, auditable mitigation actions. This thesis presents GridCAD-LLM, a distributed software-defined networking framework for resilient DNP3 defense that integrates cloud-assisted multiclass traffic detection, source-aware event interpretation, and topology-grounded policy synthesis through a large language model. The framework combines distributed ONOS controllers, an Atomix-backed consensus layer, and a cloud-hosted multilayer perceptron to detect ten DNP3 attack classes and coordinate mitigation across grid regions. For administrative command-abuse events involving masteronly function codes, GridCAD-LLM uses DNP3 command semantics, victim-response evidence, and live ONOS topology context to generate validated SDN enforcement blueprints under explicit safety constraints. Evaluation in a geo-distributed AWS-based testbed shows 99.5 percent classification accuracy for routine attack classes, cloud-offloaded inference latency under 100 ms, and coordinated policy-update latency below 15 ms. Across 100 balanced command-abuse simulations, the policy-synthesis pipeline achieves 99 percent correctness with average inference latency below 2 s, while live retrieval-augmented updates improve heldout correctness from 94 percent to 100 percent. These results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.