Defensible IEC 61850 Substation Network Security Monitoring with Zeek

This study introduces a Zeek-based monitoring framework that leverages transport layer and layer two invariants, such as MAC and VLAN integrity, multicast group membership, traffic rates, and MMS connection behavior, to detect the most consequential precursors to substation misoperation. Using...
By
Elliot Lee
January 26, 2026

All papers are copyrighted. No re-posting of papers is permitted

470x382_Research_Paper_gray.jpg