Uppsats

Architectural Gaps in Energy Substation Remote Access : A Threat Modeling Case Study

Kandidat-uppsats

Mälardalens universitet/Institutionen för datavetenskap och datateknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

Energy substations depend on remote access for maintenance, but deployed architectures diverge from the reference models that define how remote sessions should be secured. NIST SP 800-82r3 provides reference architectures for operational technology environments but does not differentiate the remote-access modalities present at the control boundary. We examined a distributed IEC 61850 substation through a single-site case study. One semi-structured interview and an expert workshop with five domain specialists produced the empirical topology. Per-element STRIDE threat modeling, focused on Elevation of Privilege (EoP), compared the topologyagainst the NIST SP 800-82r3 IoT-integrated reference. The deployed topology diverges from the reference in remote-access session termination, shared accounts, and plane separation. Remote-access sessions reach Station Level assets without terminating at a controlled intermediary. Shared accounts persist at the device level. Management and control planes lack network-level separation. Applying STRIDE per element, we traced the three gaps to a centralized authentication loop with three injection points. In the studied deployment, the gaps are structural, sustained by legacy protocol limitations and digitalservices that have expanded beyond what the reference model covers. The dual-lens framing treats physical position and data-flow path as independent dimensions, extending per-element STRIDE forenvironments where physical and digital zone boundaries diverge.

Information

Författare
Falk, Henrik
Lärosäte / institution
Mälardalens universitet/Institutionen för datavetenskap och datateknik
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.