arXiv · 2508.20051
SCAMPER -- Synchrophasor Covert chAnnel for Malicious and Protective ERrands
Abstract
We note that constituent fields (notably the fraction-of-seconds timestamp field) in the data payload structure of the synchrophasor communication protocol (IEEE C37.118 standard) are overprovisioned relative to real-world usage and needs, lending themselves to abuse for embedding of covert channels. We develop the SCAMPER (Synchrophasor Covert Channel for Malicious and Protective ERrands) framework to exploit these overprovisioned fields for covert communication and show that SCAMPER can be applied for both malicious (attack) and protective (defense) purposes. Through modifications of the timestamp field, we demonstrate that SCAMPER enables an attacker to accomplish surreptitious communications between devices in the power system to trigger a variety of malicious actions. These timestamp modifications can be performed without having any impact on the operation of the power system. However, having recognized the potential for this covert channel, we show that SCAMPER can instead be applied for defensive security purposes as an integrated cryptographic data integrity mechanism that can facilitate detection of false data injection (FDI) attacks. We perform experimental studies of the proposed methods on two Hardware-in-the-Loop (HIL) testbeds to demonstrate the effectiveness of the proposed SCAMPER framework for both malicious and protective purposes.
Explore related subjects
Keep this discovery
Prashanth Krishnamurthy, Ramesh Karri, Farshad Khorrami. 2025-08-27. SCAMPER -- Synchrophasor Covert chAnnel for Malicious and Protective ERrands. https://arxiv.org/abs/2508.20051
Cite the original work for its findings. Save a collection to share your selection of sources.