IEC 61850
IEC 61850 とは何ですか?
IEC 61850An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic.
IEC 61850 is the international standard family for communications in electrical substation automation, first published in 2003 and now the dominant protocol stack in modern substations. It specifies an object-oriented data model — Intelligent Electronic Devices (IEDs) expose Logical Nodes (LNs) such as PIOC (overcurrent protection), XCBR (circuit breaker), MMXU (measurements) — independent of the underlying transport. On the wire it defines three communication services: MMS-based client/server traffic (e.g. SCADA reads), GOOSE multicast peer-to-peer messages used for time-critical protection signaling (trip commands within milliseconds), and Sampled Values (SV) for digital instrument transformer measurements. IEC 61850 typically runs on dedicated process and station Ethernet networks inside a substation, with the corresponding IEC 62351 standard adding authentication, integrity, and (more rarely) encryption. Security concerns include unauthenticated GOOSE/SV by default, denial of service against the protection bus, malicious IED firmware, and inadequate segmentation between the substation LAN and corporate IT. Compromise of IEC 61850 traffic is the engineering primitive behind the 2016 Industroyer attack and remains a primary OT threat model for utilities.
● 例
- 01
A substation deploys IEC 62351-secured GOOSE so that an injected GOOSE trip message from a malicious host on the process bus is rejected by IEDs.
- 02
An OT NDR baselines normal MMS traffic from a substation gateway and alerts when a non-engineering host begins issuing IEC 61850 control writes.
● よくある質問
IEC 61850 とは何ですか?
An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic. サイバーセキュリティの OT / ICS / IoT カテゴリに属します。
IEC 61850 とはどういう意味ですか?
An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic.
IEC 61850 はどのように機能しますか?
IEC 61850 is the international standard family for communications in electrical substation automation, first published in 2003 and now the dominant protocol stack in modern substations. It specifies an object-oriented data model — Intelligent Electronic Devices (IEDs) expose Logical Nodes (LNs) such as PIOC (overcurrent protection), XCBR (circuit breaker), MMXU (measurements) — independent of the underlying transport. On the wire it defines three communication services: MMS-based client/server traffic (e.g. SCADA reads), GOOSE multicast peer-to-peer messages used for time-critical protection signaling (trip commands within milliseconds), and Sampled Values (SV) for digital instrument transformer measurements. IEC 61850 typically runs on dedicated process and station Ethernet networks inside a substation, with the corresponding IEC 62351 standard adding authentication, integrity, and (more rarely) encryption. Security concerns include unauthenticated GOOSE/SV by default, denial of service against the protection bus, malicious IED firmware, and inadequate segmentation between the substation LAN and corporate IT. Compromise of IEC 61850 traffic is the engineering primitive behind the 2016 Industroyer attack and remains a primary OT threat model for utilities.
IEC 61850 からどのように防御しますか?
IEC 61850 に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
IEC 61850 の別名は何ですか?
一般的な別名: IEC 61850 substation, GOOSE / MMS / SV。
● 関連用語
- ot-iot№ 587
産業用制御システム (ICS)
産業プロセスを自動化・監視するシステムの総称で、SCADA、DCS、PLC、RTU、安全制御システムなどを含む。
- ot-iot№ 1083
SCADA
遠隔のフィールド機器からテレメトリを収集し、運転員が広域な工業プロセスを監視・操作できるようにする監視制御・データ収集システム。
- ot-iot№ 854
制御技術 (OT)
工場、発電所、ユーティリティなどの物理プロセス・機器・インフラを監視・制御するハードウェアとソフトウェアの総称。
- ot-iot№ 588
Industroyer / CrashOverride
2016 年のウクライナ電力網攻撃で使用され、2022 年に Industroyer2 として更新されたモジュール型 ICS マルウェア。電力網のネイティブプロトコルを話し変電所を遮断できる。
- ot-iot№ 589
Industroyer2 (CrashOverride 2)
A 2022 evolution of the Industroyer/CrashOverride electric-grid malware, attributed by ESET to Sandworm and used in an unsuccessful April 2022 attempt to cut power in a Ukrainian regional utility.
- ot-iot№ 984
Purdue エンタープライズリファレンスアーキテクチャ
業務 IT とプロセス制御を分離する産業ネットワークの階層型参照モデルで、ICS のネットワークセグメンテーション設計に広く利用される。