KIT | KIT-Bibliothek | Impressum | Datenschutz

On Automated and Standardized Asset, Vulnerability and Patch Management in the Power Grid

Liu, Qi ORCID iD icon; Attar, Arman A. ORCID iD icon 1; Bao, Kaibin ORCID iD icon 1; Noglik, Peter; Gottschalg, Martin; Hagenmeyer, Veit ORCID iD icon 1
1 Institut für Automation und angewandte Informatik (IAI), Karlsruher Institut für Technologie (KIT)

Abstract:

Proper and timely vulnerability and patch management depend on a comprehensive, accurate and easily maintainable asset inventory, which in turn rests on standardized and automated information gathering procedures. In practice, the information gathering process may not provide all information required to determine if a device is vulnerable and the criticality of patching it. This considerably slows down the patch processes. Challenges in information gathering arise due to the heterogeneity of devices and systems deployed in an environment like the power grid and the lack of standardized protocols across the industry. In this article, we examine existing popular protocols, and identify their deficiencies for asset information gathering. We highlight the challenges in automated vulnerability and patch management through our experiments, in which we also evaluate and compare commercial products. Following this, we propose a new schema to streamline the information gathering process and improve the consistency during information gathering across devices of various vendors, which would ultimately contribute to proper and timely vulnerability and patch management.


Verlagsausgabe §
DOI: 10.5445/IR/1000196510
Veröffentlicht am 01.09.2026
Originalveröffentlichung
DOI: 10.1109/TPEL.2026.3725276
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Automation und angewandte Informatik (IAI)
Publikationstyp Zeitschriftenaufsatz
Publikationsjahr 2026
Sprache Englisch
Identifikator ISSN: 0885-8993, 1941-0107
KITopen-ID: 1000196510
Erschienen in IEEE Transactions on Power Electronics
Verlag Institute of Electrical and Electronics Engineers (IEEE)
Seiten 1–6
Vorab online veröffentlicht am 19.08.2026
Schlagwörter Asset inventory, vulnerability management
Nachgewiesen in OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page