IEC 61850
Что такое IEC 61850?
IEC 61850An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic.
IEC 61850 is the international standard family for communications in electrical substation automation, first published in 2003 and now the dominant protocol stack in modern substations. It specifies an object-oriented data model — Intelligent Electronic Devices (IEDs) expose Logical Nodes (LNs) such as PIOC (overcurrent protection), XCBR (circuit breaker), MMXU (measurements) — independent of the underlying transport. On the wire it defines three communication services: MMS-based client/server traffic (e.g. SCADA reads), GOOSE multicast peer-to-peer messages used for time-critical protection signaling (trip commands within milliseconds), and Sampled Values (SV) for digital instrument transformer measurements. IEC 61850 typically runs on dedicated process and station Ethernet networks inside a substation, with the corresponding IEC 62351 standard adding authentication, integrity, and (more rarely) encryption. Security concerns include unauthenticated GOOSE/SV by default, denial of service against the protection bus, malicious IED firmware, and inadequate segmentation between the substation LAN and corporate IT. Compromise of IEC 61850 traffic is the engineering primitive behind the 2016 Industroyer attack and remains a primary OT threat model for utilities.
● Примеры
- 01
A substation deploys IEC 62351-secured GOOSE so that an injected GOOSE trip message from a malicious host on the process bus is rejected by IEDs.
- 02
An OT NDR baselines normal MMS traffic from a substation gateway and alerts when a non-engineering host begins issuing IEC 61850 control writes.
● Частые вопросы
Что такое IEC 61850?
An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic. Относится к категории OT / ICS / IoT в кибербезопасности.
Что означает IEC 61850?
An international standard for communications inside electrical substations, covering object-oriented data models (LNs), high-speed messaging (GOOSE), sampled-values measurements (SV), and MMS-based client/server traffic.
Как работает IEC 61850?
IEC 61850 is the international standard family for communications in electrical substation automation, first published in 2003 and now the dominant protocol stack in modern substations. It specifies an object-oriented data model — Intelligent Electronic Devices (IEDs) expose Logical Nodes (LNs) such as PIOC (overcurrent protection), XCBR (circuit breaker), MMXU (measurements) — independent of the underlying transport. On the wire it defines three communication services: MMS-based client/server traffic (e.g. SCADA reads), GOOSE multicast peer-to-peer messages used for time-critical protection signaling (trip commands within milliseconds), and Sampled Values (SV) for digital instrument transformer measurements. IEC 61850 typically runs on dedicated process and station Ethernet networks inside a substation, with the corresponding IEC 62351 standard adding authentication, integrity, and (more rarely) encryption. Security concerns include unauthenticated GOOSE/SV by default, denial of service against the protection bus, malicious IED firmware, and inadequate segmentation between the substation LAN and corporate IT. Compromise of IEC 61850 traffic is the engineering primitive behind the 2016 Industroyer attack and remains a primary OT threat model for utilities.
Как защититься от IEC 61850?
Защита от IEC 61850 обычно сочетает технические меры и операционные практики, как описано в определении выше.
Какие есть другие названия IEC 61850?
Распространённые альтернативные названия: IEC 61850 substation, GOOSE / MMS / SV.
● Связанные термины
- ot-iot№ 587
Промышленная система управления (ICS)
Обобщённый термин для систем автоматизации и надзора за промышленными процессами, включая SCADA, DCS, ПЛК, RTU и системы противоаварийной защиты.
- ot-iot№ 1083
SCADA
Системы диспетчерского управления и сбора данных, которые собирают телеметрию с удалённых полевых устройств и позволяют операторам контролировать масштабные процессы.
- ot-iot№ 854
Операционные технологии (OT)
Аппаратные и программные средства, которые контролируют физические процессы и инфраструктуру — заводы, электростанции и коммунальные сети.
- ot-iot№ 588
Industroyer / CrashOverride
Модульное ICS-ВПО, применённое в атаке на украинскую энергосистему в 2016 году и обновлённое до Industroyer2 в 2022 году; «говорит» на нативных протоколах энергосетей.
- ot-iot№ 589
Industroyer2 (CrashOverride 2)
A 2022 evolution of the Industroyer/CrashOverride electric-grid malware, attributed by ESET to Sandworm and used in an unsuccessful April 2022 attempt to cut power in a Ukrainian regional utility.
- ot-iot№ 984
Эталонная архитектура предприятия Purdue (PERA)
Уровневая референсная модель промышленных сетей, отделяющая бизнес-IT от управления процессом и широко используемая при проектировании сегментации ICS.