Research Article

Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases

Volume: 8 Number: 3 September 30, 2025
EN

Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases

Abstract

In recent years, with the acceleration of digitalization, Intelligent Electronic Devices (IEDs) used particularly in energy transmission and distribution infrastructures have become one of the primary targets of cyber-attacks. This has made the detection and management of vulnerabilities in IEDs more challenging. Most energy system operators rely on security advisories published by vendors to identify security vulnerabilities. This study presents an approach aimed at automating this process. Manufacturer, model, hardware, and software version information of the devices is passively obtained from SCL files compliant with the IEC 61850 standard, and this data is correlated with the NVD, CWE, and vendor security bulletins to generate a comprehensive vulnerability report. In the implementations carried out in the CENTER-SAÜ test environment, the developed system was observed to produce accurate and complete results. The reports include the identified vulnerabilities and the risk level, attack vector, affected versions, patches and recommended mitigation measures for each vulnerability.

Keywords

References

  1. AFAD, 2014-2023 Kritik Altyapıların Korunması: Yol Haritası Belgesi. 2014.
  2. A. Pinto, L.-C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on Intrusion Detection Systems Based on Machine Learning Techniques for the Protection of Critical Infrastructure,” Sensors, vol. 23, no. 5, p. 2415, Feb. 2023, doi: 10.3390/s23052415.
  3. P. E. Weerathunga and A. Cioraca, “Securing IEDs against cyber threats in critical substation automation and industrial control systems,” in 2017 70th Annual Conference for Protective Relay Engineers (CPRE), Apr. 2017, pp. 1–20, doi: 10.1109/CPRE.2017.8090048.
  4. K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, and A. Hahn, “Guide to Industrial Control Systems (ICS) Security,” Gaithersburg, MD, Jun. 2015. doi: 10.6028/NIST.SP.800-82r2.
  5. TEİAŞ, “GRAFİK VI.I- TÜRKİYE İLETİM HAT UZUNLUKLARININ GELİŞİMİ (2013-2023),” 2024. [Online]. Available: https://www.teias.gov.tr/turkiye-elektrik-uretim-iletim-istatistikleri.
  6. TEİAŞ, “GRAFİK VI.III- TÜRKİYE TRAFO ADETLERİNİN GELİŞİMİ (2013-2023),” 2024. [Online]. Available: https://www.teias.gov.tr/turkiye-elektrik-uretim-iletim-istatistikleri.
  7. TEDAŞ, “2023 Yılı Türki̇ye Elektri̇k Dağıtımı Sektör Raporu,” 2024. [Online]. Available: https://www.tedas.gov.tr/FileUpload/MediaFolder/25819eac-d024-4308-891a-d248db8c1e0a.pdf.
  8. A. Abedi, L. Gaudard, and F. Romerio, “Review of major approaches to analyze vulnerability in power systems,” Reliab. Eng. Syst. Saf., vol. 183, no. November, pp. 153–172, Mar. 2019, doi: 10.1016/j.ress.2018.11.019.

Details

Primary Language

English

Subjects

Computer Software

Journal Section

Research Article

Early Pub Date

September 30, 2025

Publication Date

September 30, 2025

Submission Date

July 31, 2025

Acceptance Date

September 8, 2025

Published in Issue

Year 2025 Volume: 8 Number: 3

APA
Gargouri, K., & İskefiyeli, M. (2025). Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases. Sakarya University Journal of Computer and Information Sciences, 8(3), 553-569. https://doi.org/10.35377/saucis...1754929
AMA
1.Gargouri K, İskefiyeli M. Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases. SAUCIS. 2025;8(3):553-569. doi:10.35377/saucis.1754929
Chicago
Gargouri, Khouloud, and Murat İskefiyeli. 2025. “Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases”. Sakarya University Journal of Computer and Information Sciences 8 (3): 553-69. https://doi.org/10.35377/saucis. 1754929.
EndNote
Gargouri K, İskefiyeli M (September 1, 2025) Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases. Sakarya University Journal of Computer and Information Sciences 8 3 553–569.
IEEE
[1]K. Gargouri and M. İskefiyeli, “Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases”, SAUCIS, vol. 8, no. 3, pp. 553–569, Sept. 2025, doi: 10.35377/saucis...1754929.
ISNAD
Gargouri, Khouloud - İskefiyeli, Murat. “Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases”. Sakarya University Journal of Computer and Information Sciences 8/3 (September 1, 2025): 553-569. https://doi.org/10.35377/saucis. 1754929.
JAMA
1.Gargouri K, İskefiyeli M. Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases. SAUCIS. 2025;8:553–569.
MLA
Gargouri, Khouloud, and Murat İskefiyeli. “Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases”. Sakarya University Journal of Computer and Information Sciences, vol. 8, no. 3, Sept. 2025, pp. 553-69, doi:10.35377/saucis. 1754929.
Vancouver
1.Khouloud Gargouri, Murat İskefiyeli. Firmware Analyzer of Intelligent Electronic Devices in Substations Based on Vulnerability Databases. SAUCIS. 2025 Sep. 1;8(3):553-69. doi:10.35377/saucis. 1754929

 

INDEXING & ABSTRACTING & ARCHIVING

 

31045 31044   ResimLink - Resim Yükle  31047 

31043 28939 28938 34240
 

 

29070    The papers in this journal are licensed under a Creative Commons Attribution-NonCommercial 4.0 International License