1Naonworks, Seoul, South Korea
2IACF Kwangwoon University, Seoul, South Korea
*Corresponding author: June-Kyoung Lee Naonworks, South Korea E-mail: darkelan@naonworks.com
Online published on 21 September, 2018.
In this paper, we clarify the ambiguity of the payload transaction in the OpenADR 2.0b standard and propose a technique analyzing payload transaction. To eliminate vagueness in an element of payload transaction identifier described in the OpenADR 2.0b standard specification, we formalized the transaction process by defining a formal grammar. This grammar ensures that all payloads in the service participate in a unique transaction. The grammar that defines the transaction creation process in OpenADR 2.0b accommodates all scenarios published by the protocol specification document and is used for packet flow analysis without modification of XML schema interface. Using this, we analyze the payload transaction in real time applying the syntax pattern recognition technique and test VTN and VEN of EPRI’s well-known OpenADR 2.0b application has security vulnerability with a transaction identifier. An example is the transaction identifier of the request payload and the response payload is not the same or the response to a transaction identifier that is never used. The illogical transaction identifier has an adverse effect on the transaction analysis on the payload and ultimately can lead to serious security incidents.
OpenADR 2.0b, Formal Grammar, Syntactic Pattern Recognition, Protocol Verification, Smart Grid, Domain Specific Language