An Integrated Cyber-Physical Security Framework for Resilient Critical Power System Infrastructure: Vulnerability Analysis, Framework Design, and Simulation-Based Evaluation

Authors

  • Donatus Chima Nwose Department of Electrical Engineering, Nnamdi Azikiwe University, Awka, Nigeria
  • Emmanuel Aninye Anazia Department of Electrical Engineering, Nnamdi Azikiwe University, Awka, Nigeria
  • Ugochukwu Edebeani Anionovo Department of Electrical Engineering, Nnamdi Azikiwe University, Awka, Nigeria
  • Charles Austeen Ibeh Forensic Science Department, Nnamdi Azikiwe University, Awka, Nigeria

Keywords:

Cyber-Physical Systems; Critical Infrastructure Security; Resilience Framework; NS-3 Network Simulation; Denial-of-Service Attack; Co-Simulation; ICS/SCADA Vulnerability.

Abstract

Cyber-Physical Systems (CPS) now form the operational backbone of critical power system infrastructure, tightly coupling sensing, communication and control functions to physical processes. This coupling improves efficiency but also creates a blended attack surface in which cyber intrusions can propagate directly into physical operations, as demonstrated by incidents such as Stuxnet and the 2015/2016 Ukrainian power grid attacks. Existing security approaches remain fragmented, treating cyber and physical safeguards as separate concerns and rarely validating resilience claims through integrated, reproducible experimentation. This paper addresses three objectives drawn from a broader thesis: (i) a structured vulnerability analysis of Industrial Control System (ICS) and smart-grid architectures, identifying the interdependencies that expose them to coordinated cyber-physical threats; (ii) the design of an integrated resilience framework comprising physical, cyber, control and resilience-evaluation layers; and (iii) the development of a Python and NS-3 based co-simulation environment used to evaluate coordinated cyber-physical attack scenarios and quantify resilience performance. The physical process was represented using equation-based, OpenModelica-inspired models of a simplified power infrastructure, while NS-3 reproduced packet-level network behaviour; a Python-based control layer and a composite resilience-scoring layer completed the architecture. A denial-of-service (DoS) attack scenario was simulated over a 20 s window, comparing an unprotected baseline against a resilience-enabled configuration. Under attack, the mean functionality index fell to 0.5165 in the unprotected case; activating the resilience layer raised the minimum functionality index from 0.4058 to 0.5291 and the mean functionality index from 0.5165 to 0.7107, while recovery time fell from 57 s to 1 s, packet loss for legitimate traffic returned to 0%, and anomalies were detected within 1 s of attack onset with a zero false-positive rate. These results confirm that combining physical and cyber indicators in a single resilience metric enables earlier detection and more effective recovery than domain-isolated monitoring, supporting the case for integrated, simulation-validated resilience frameworks in critical power infrastructure.

Downloads

Published

2026-08-22