Datasets of Man-in-the-middle Attacks Targeting Modbus TCP/IP and MMS protocols in the Smart Grid

Open data API in a single place

Provided by Zenodo

Get early access to Datasets of Man-in-the-middle Attacks Targeting Modbus TCP/IP and MMS protocols in the Smart Grid API!

Let us know and we will figure it out for you.

Dataset information

Country of origin
Updated
2023.10.04 00:00
Created
2023.01.01
Available languages
English
Keywords
Cyber-security, IEC 61850 protocol, man-in-the-middle attack, Modbus protocol, network intrusion detection system, private area network, smart grid.
Quality scoring

Dataset description

The sustainable development of smart grids requires the massive deployment of renewable energy, in a highly distributed manner, introducing new challenges for the system operation. Therefore, the integration of information and communication technologies in sites with Distributed Energy Resources (DERs) is needed to monitor and control the DERs operation. In this scheme, a local controller is installed at each DER site to interact with the centralized applications at the grid level and the power equipment at the site level. This local controller uses client–server protocols (e.g., Modbus TCP/IP and IEC 61850 Manufacturing Message Specification (MMS)) to communicate with different power equipment in the Private Area Network (PAN) of the site. Such protocols often lack information confidentiality and integrity mechanisms. As a result, the smart grids become vulnerable to cyber-attacks.  This repository contains datasets created to evaluate the detection and classification of man-in-the-middle attacks, operating in eavesdropping mode, targeting MMS and Modbus TCP/IP protocols in the PAN of the smart grid. Five Flow-based features were used to create these datasets, as shown in Table 1, in addition to the ARP poisoning indicator feature: Table 1 Feature Description IRTT Time for establishing one connection TTOC Time for receiving all responses in one connection MITR  Minimum time between requests in one connection MATR  Maximum time between requests in one connection NROC  Number of requests in one connection **NOTE** If you use this dataset in your research/publication please cite us using the following: Mohamed Faisal Elrawy, Lenos Hadjidemetriou, Christos Laoudias, Maria K. Michael, Detecting and classifying man-in-the-middle attacks in the private area network of smart grids, Sustainable Energy, Grids and Networks,2023,pp.1-13, https://doi.org/10.1016/j.segan.2023.101167
European data infrastructure with broad catalog discovery, free evaluation access and production-grade API options.
190K+
indexed dataset pages
32
countries and EU institutions
2019
API-first since
Free API quota
for evaluation and prototypes
SLA
history and push on production APIs
FAQ

Questions before production use

Practical answers on evaluation, licensing, freshness, versioning and support.

api.store is built and operated by Apitalks s.r.o. Company details and a direct contact path are linked in the footer for vendor checks and procurement review.
Yes. Selected APIs include a free API quota, so your team can validate coverage, freshness, response shape and workflow fit before asking for a production plan.
Often yes, but usage rights depend on the source license and dataset. We surface source, license and update metadata where available, and can help review terms before a production integration.
Maintained APIs include update metadata where available. For production integrations, we can add history, monitoring and push updates so changes are easier to detect and act on.
Production APIs can add SLA, stable identifiers, versioning support, history, push updates and direct support around the data your product or AI workflow depends on.

Didn't find the API you need?

Let us know and we will figure it out for you.

European data discovery with free evaluation access and production-grade API options.

Copyright © 2026. Made by Apitalks