Engineering Papers⌕ Search

Engineering topics

Dawson, Joel

Publications and source records attributed to Dawson, Joel.

Detection of Control Injection Attacks using Energy Data Anomalies in CNC Machining

The widespread adoption of networked devices, sophisticated automation, and data-driven processes in the industry - also known as Industry 4.0 - has boosted the quantity and quality of manufacturing products. With these benefits, however, comes a substantial increase in the attack surface of these systems. In addition to affecting the readiness and the quality of critical products, the attacks against manufacturing processes and systems carry the potential to have severe physical consequences, including human injury and death. In this paper we present the results of a remote network-based control injection attack on a CNC mill. Specifically, we focus on the impact of this type of the attack on the movement of CNC mill during operation. Evaluating the physical effect of these attacks on a workpiece, we provide machine agnostic, affordable, and scalable solution for their monitoring. We then demonstrate a simple threshold-based method for the detection of these attacks and evaluate the effectiveness of detection.

Taylor, Curtis↗

Stealthy Cyber Anomaly Detection On Large Noisy Multi-material 3D Printer Datasets Using Probabilistic Models

As Additive Layer Manufacturing (ALM) becomes pervasive in industry, its applications in safety critical component manufacturing are being explored and adopted. However, ALM's reliance on embedded computing renders it vulnerable to tampering through cyber-attacks. Sensor instrumentation of ALM devices allows for rigorous process and security monitoring, but also results in a massive volume of noisy data for each run. As such, in-situ, near-real-time anomaly detection is very challenging. The ideal algorithm for this context is simple, computationally efficient, minimizes false positives, and is accurate enough to resolve small deviations. In this paper, we present a probabilistic-model-based approach to address this challenge. To test our approach, we analyze current measurements from a polymer composite 3D printer during emulated tampering attacks. Our results show that our approach can consistently and efficiently locate small changes in the presence of substantial operational noise.

Yoginath, Srikanth↗

Heartbeat: Detecting Malware by Periodic Power Signal Injection and Monitoring

Rootkits and other stealthy malware attempt to conceal their presence on a computer by making changes to the host computer’s operating environment. ORNL’s Heartbeat technology detects these changes, and thus the malware itself. Heartbeat operates by directly monitoring the DC power consumption of the computer while a set of operations, the “heartbeat,” is executed periodically. These operations exercise parts of the operating system that are common targets of malware tampering. The power consumption during these heartbeat events is monitored and then compared to a previously learned baseline, with any significant deviation detected and analyzed. This technology has been tested and validated in a laboratory environment, and ORNL is currently seeking a deployment partner to allow for further in-context development and testing of this technology.

97 MATHEMATICS AND COMPUTING↗

VAC: A Software Approach to Resilient SCADA Automation

To better secure critical infrastructure, especially power systems, this paper introduces a virtual SCADA automation controller. The automation controller is a gateway into a power subsystem, making it a valuable target for cyber-attacks that could cut it off from the control center and cause a loss of view and control. To prevent this, the Virtual Automation Controller (VAC) is a backup device that mirrors the capabilities of the physical controller. It can communicate via Modbus and DNP3 and is containerized so it can be deployed on a variety of platforms. Furthermore, it utilizes software-defined networking to quickly disconnect a failed automation controller and preserve its state for forensics. The VAC gives system operators time to replace the failed controller and prevents dangerous and costly damage to power systems. The VAC is compared against the SEL 3505-3 RTAC and shown to have the necessary features to act as a failover controller.

Johnson, Jordan↗

Rootkit detection system

A system and method (referred to as the system) detect infectious code. The system injects a repetitive software code that causes malware in a monitored device to render a detectable direct current power consumption profile. A guide wave generator generates a guide wave signal that establishes an observational window that is applied to data that represent a direct current source power consumption of the monitored device. An extraction device extracts a portion of the data that represent the direct current source power consumption of the monitored device. A deviation engine identifies the malware on the monitored device without processing data associated with a prior identification of the malware or identifying a source of the malware or identifying a location of the malware on the monitored device.

Dawson, Joel↗

Control-Theory-Informed Feature Selection for Detecting Malicious Tampering in Additive Layer Manufacturing Processes

Additive layer manufacturing (ALM) is rapidly becoming an appealing solution to the low-volume manufacturing of metal, polymer, or composite parts. However, ALM’s reliance on digital part specifications, microcontrollers, and modern networking makes these devices vulnerable to malicious tampering by cyber attackers, which can negatively affect part performance and even result in catastrophic failure. We present a hybrid analytic approach to feature discovery using control theoretic techniques and linear modelling on input-output data collected from a representative controller system. Employing this approach, we design, train, and test an anomaly detection system. The preliminary results show that the proposed approach effectively discovers useful input-output relationships for anomaly detection in a simulated ALM process. Application to larger and more complex systems are discussed.

Dawson, Joel↗