Cloud-Based Malware Detection of Smart Meters in Advanced Metering Infrastructure

Authors

  • Zuo Jian Power Dispatch and Control Center of Guangdong Power Grid Corporation, Guangzhou 510600, China
  • Ziwen Cai Power Research Institute of China Southern Power Grid, Guangzhou 530600, China
  • Bin Qian Power Research Institute of China Southern Power Grid, Guangzhou 530600, China
  • Yong Xiao Power Research Institute of China Southern Power Grid, Guangzhou 530600, China

Abstract

In an Advanced Metering Infrastructure (AMI), smart meters implement encryption/decryption with Embedded Secure Access Module (ESAM) to secure communication. However, meters can be attacked by malicious adversaries once the ESAM is cracked. Since smart meters have limited communication and computing resources and cannot detect malicious code, a cloud-based cyber security protection approach is proposed to detect malware online. Firstly, the closed and fixed operating environment is utilized to establish and maintain a white list of legal processes in the cloud security server of the metering center. Thereafter, the operating process detection agent is installed in the smart meters, and all operating processes are recorded by it. The hash code of each operating process can be established as its identity and submitted to the cloud security server. The meter containing illegal processes can be identified by comparing it with the white list. The smart meter needs only to calculate and upload the hash code of processes, which is affordable for smart meters with limited computing and communication resources. The proposed approach can help strengthen the cyber security defense of an AMI.

Keywords: advanced metering infrastructure (AMI), cloud security, hash code, white list, smart meters

Cite As

Z. Jian, Z. Cai, B. Qian and Y. Xiao, "Cloud-Based Malware Detection of Smart Meters in Advanced Metering Infrastructure",
Engineering Intelligent Systems, vol. 30 no. 3, pp. 195-200, 2022.




Published

2022-05-01