Skip to content
Conference

Anomaly traffic detection and attack traceability for power communication networks

Sep 2026 · International Conference on Intelligent Transportation Systems and Automation Control · Vol 14368, pp. 143681N - 143681N-9 · 0 citations · 17 references
Engineering

Abstract

Power communication networks carry protection, metering, dispatching, and automated-control messages whose abnormal traffic may rapidly evolve into cyber-physical incidents. Existing intrusion detectors usually report an attack label but provide limited evidence about the source path, protocol cause, and affected electrical asset. This paper proposes a protocol-aware method that combines normalized flow features, a dynamic evidence graph, a spatio-temporal graph attention encoder, and a temporal autoencoder. The detector converts heterogeneous network observations into a calibrated anomaly score and then ranks traceback paths according to timing, protocol compatibility, attention contribution, and grid-impact evidence. To strengthen the empirical basis, a regional substation communication testbed with IEC 61850, MMS, DNP3, and Modbus traffic is used to compare random forest, LSTM, GraphSAGE, ST-GAT, and the proposed dual-channel model. The proposed method achieves 97.4% macro-F1 and a 92.6% top-1 traceback hit rate, while producing ranked evidence chains within 7.2 s after alarm triggering. The framework is also suitable for optical-fiber-supported automated-control networks and energy-facility communication scenarios where reliable traffic forensics is required.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.