As power systems modernize toward smart grid architectures, the integration of distributed generation and communication networks has expanded operational flexibility while simultaneously introducing new attack surfaces. Overcurrent protection relays—fundamental to system stability—increasingly depend on digital communication and automated controls, making them vulnerable to sophisticated cyber intrusions that traditional security measures may fail to detect.
Researchers have developed an integrated cyber-physical evaluation framework to assess these risks systematically. The approach models how attackers can manipulate current and voltage measurements transmitted to protection relays, potentially triggering false trips or blocking legitimate protective actions while evading detection algorithms. Using an attack-tree methodology, the framework identifies multiple pathways through which cyber interference propagates from communication networks into the protection layer.
The evaluation employs co-simulation technology pairing OMNeT—a communication network simulator—with ETAP power system software. This dual-domain approach allows analysts to observe real-time interactions between cyber events and electrical responses. Testing on the IEEE 9-bus standard network demonstrated how three attack categories affect relay performance: command blocking (preventing relay actuation), configuration manipulation (altering settings), and false data injection (corrupting measurement inputs).
Results revealed critical vulnerabilities in fault detection sensitivity and relay selectivity under coordinated attacks. Specifically, blocking relay commands delayed protective response during faults, while configuration changes compromised coordination margins between cascaded relays. False data injection attacks proved particularly dangerous, capable of triggering misoperations indistinguishable from genuine faults.
These findings highlight essential gaps in current protection system resilience. The framework provides utilities with a systematic methodology to evaluate their own protection architectures against realistic cyber-physical threat scenarios, enabling targeted hardening of vulnerable points. As smart grid adoption accelerates, integrating such assessment protocols into relay design and cyber defense strategies becomes imperative to maintain reliable grid operation.



