Group Purchasing
Group Purchasing

Defensible IEC 61850 Substation Network Security Monitoring with Zeek

Defensible IEC 61850 Substation Network Security Monitoring with Zeek (PDF, 0.73MB)Published: 26 Jan, 2026
Created by:
Elliot Lee

This study introduces a Zeek-based monitoring framework that leverages transport layer and layer two invariants, such as MAC and VLAN integrity, multicast group membership, traffic rates, and MMS connection behavior, to detect the most consequential precursors to substation misoperation. Using reproducible lab PCAPs, the framework validates lightweight detectors for baseline discovery, false data injection precursors, denial-of-service, spoofing, and eavesdropping/exposure.