Otimização do Ataque Grayhole ao Protocolo GOOSE
Resumo
Subestações elétricas baseadas na norma IEC-61850 utilizam o protocolo GOOSE para comunicação crítica entre dispositivos de proteção. Ataques do tipo Grayhole — que descartam seletivamente pacotes de rede — ameaçam a confiabilidade dessas redes sem acionar alarmes imediatos. Embora modelos de Machine Learning detectem essas ameaças, sua natureza caixa-preta limita a transparência das decisões. Este artigo apresenta uma análise sistemática do ataque sob taxas de descarte de 3% a 90% e integra técnicas de Inteligência Artificial Explicável (XAI) para interpretar a lógica de detecção em redes IEC-61850. Os resultados reforçam a importância da explicabilidade na segurança de infraestruturas críticas.Referências
Anguita, D., Ghelardoni, L., Ghio, A., Oneto, L., Ridella, S., et al. (2012). The’k’in k-fold cross validation. In ESANN, volume 102, pages 441–446.
Ashraf, S. and et al. (2021). A comprehensive review of cybersecurity in iec 61850 based smart grids. IEEE Access, 9:88569–88588.
Ashraf, S., Shawon, M. H., Khalid, H. M., and Muyeen, S. (2021). Denial-of-service attack on iec 61850-based substation automation system: A crucial cyber threat towards smart substation pathways. Sensors, 21(19):6415.
Baigent, D., Adamiak, M., Mackiewicz, R., and Sisco, G. (2004). Iec 61850 communication networks and systems in substations: An overview for users. SISCO Systems.
Basumallik, S. (2020). A taxonomy of data attacks in power systems. arXiv preprint arXiv:2002.11011.
Elbez, G., Nahrstedt, K., and Hagenmeyer, V. (2022). Early detection of goose denial of service (dos) attacks in iec 61850 substations. In 2022 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pages 367–373.
Gonçalves, J. C. et al. (2023). Modelagem do ataque grayhole ao protocolo de comunicação goose usando o framework ereno.
Gunning, D., Stefik, M., Choi, J., Miller, T., Stumpf, S., and Yang, G.-Z. (2019). Xai—explainable artificial intelligence. Science robotics, 4(37):eaay7120.
Lázaro, J., Astarloa, A., Rodríguez, M., Bidarte, U., and Jiménez, J. (2021). A survey on vulnerabilities and countermeasures in the communications of the smart grid. Electronics, 10(16):1881.
McLennan, M., Group, S., and Group, Z. I. (2022). The global risks report 2022 17th edition. Disponível em: [link].
Min, E., Long, J., Liu, Q., Cui, J., and Chen, W. (2018). Tr-ids: Anomaly-based intrusion detection through text-convolutional neural network and random forest. Security and Communication Networks, 2018(1):4943509.
Pal, S., Sikdar, B., and Chow, J. H. (2016). An online mechanism for detection of gray-hole attacks on pmu data. IEEE Transactions on Smart Grid, 9(4):2498–2507.
Quincozes, S. (2022). ERENO: An Extensible Tool for Generating Realistic IEC–61850 Intrusion Detection Datasets. PhD thesis, Fluminense Federal University.
Quincozes, S. E., Kazienko, J. F., and Quincozes, V. E. (2023). An extended evaluation on machine learning techniques for denial-of-service detection in wireless sensor networks. Internet of Things, 22:100684.
Reda, H. T., Ray, B., Peidaee, P., Anwar, A., Mahmood, A., Kalam, A., and Islam, N. (2021). Vulnerability and impact analysis of the iec 61850 goose protocol in the smart grid. Sensors, 21(4):1554.
Sidhu, T. S. and Yin, Y. (2007). Modelling and simulation for performance evaluation of iec61850-based substation communication systems. IEEE Transactions on Power Delivery, 22(3):1482–1489.
Tefek, U., Esiner, E., Mashima, D., and Hu, Y.-C. (2022). Analysis of message authentication solutions for iec 61850 in substation automation systems. In 2022 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pages 224–230. IEEE.
V, G. and Yadav, R. (2024). Enhancing the security of iec-61850 goose messages during transmission. In 2024 IEEE International Conference on Power and Energy (PECon), pages 82–85.
Xu, W. and Fan, Y. (2022). Intrusion detection systems based on logarithmic autoencoder and xgboost. Security and Communication Networks, 2022(1):9068724.
Ashraf, S. and et al. (2021). A comprehensive review of cybersecurity in iec 61850 based smart grids. IEEE Access, 9:88569–88588.
Ashraf, S., Shawon, M. H., Khalid, H. M., and Muyeen, S. (2021). Denial-of-service attack on iec 61850-based substation automation system: A crucial cyber threat towards smart substation pathways. Sensors, 21(19):6415.
Baigent, D., Adamiak, M., Mackiewicz, R., and Sisco, G. (2004). Iec 61850 communication networks and systems in substations: An overview for users. SISCO Systems.
Basumallik, S. (2020). A taxonomy of data attacks in power systems. arXiv preprint arXiv:2002.11011.
Elbez, G., Nahrstedt, K., and Hagenmeyer, V. (2022). Early detection of goose denial of service (dos) attacks in iec 61850 substations. In 2022 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pages 367–373.
Gonçalves, J. C. et al. (2023). Modelagem do ataque grayhole ao protocolo de comunicação goose usando o framework ereno.
Gunning, D., Stefik, M., Choi, J., Miller, T., Stumpf, S., and Yang, G.-Z. (2019). Xai—explainable artificial intelligence. Science robotics, 4(37):eaay7120.
Lázaro, J., Astarloa, A., Rodríguez, M., Bidarte, U., and Jiménez, J. (2021). A survey on vulnerabilities and countermeasures in the communications of the smart grid. Electronics, 10(16):1881.
McLennan, M., Group, S., and Group, Z. I. (2022). The global risks report 2022 17th edition. Disponível em: [link].
Min, E., Long, J., Liu, Q., Cui, J., and Chen, W. (2018). Tr-ids: Anomaly-based intrusion detection through text-convolutional neural network and random forest. Security and Communication Networks, 2018(1):4943509.
Pal, S., Sikdar, B., and Chow, J. H. (2016). An online mechanism for detection of gray-hole attacks on pmu data. IEEE Transactions on Smart Grid, 9(4):2498–2507.
Quincozes, S. (2022). ERENO: An Extensible Tool for Generating Realistic IEC–61850 Intrusion Detection Datasets. PhD thesis, Fluminense Federal University.
Quincozes, S. E., Kazienko, J. F., and Quincozes, V. E. (2023). An extended evaluation on machine learning techniques for denial-of-service detection in wireless sensor networks. Internet of Things, 22:100684.
Reda, H. T., Ray, B., Peidaee, P., Anwar, A., Mahmood, A., Kalam, A., and Islam, N. (2021). Vulnerability and impact analysis of the iec 61850 goose protocol in the smart grid. Sensors, 21(4):1554.
Sidhu, T. S. and Yin, Y. (2007). Modelling and simulation for performance evaluation of iec61850-based substation communication systems. IEEE Transactions on Power Delivery, 22(3):1482–1489.
Tefek, U., Esiner, E., Mashima, D., and Hu, Y.-C. (2022). Analysis of message authentication solutions for iec 61850 in substation automation systems. In 2022 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), pages 224–230. IEEE.
V, G. and Yadav, R. (2024). Enhancing the security of iec-61850 goose messages during transmission. In 2024 IEEE International Conference on Power and Energy (PECon), pages 82–85.
Xu, W. and Fan, Y. (2022). Intrusion detection systems based on logarithmic autoencoder and xgboost. Security and Communication Networks, 2022(1):9068724.
Publicado
01/09/2026
Como Citar
MUNDT, Guilherme C.; ZOMER, Carlos S. M.; QUINCONZES, Silvio E.; KAZIENKO, Juliano F.; MIANI, Rodrigo; QUINCONZES, Vagner E.; MOSSÉ, Daniel.
Otimização do Ataque Grayhole ao Protocolo GOOSE. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 626-637.
DOI: https://doi.org/10.5753/sbseg_estendido.2026.29806.
