Engineering Papers⌕ Search

Engineering topics

Gourisetti, Sri Nikhil G.

Publications and source records attributed to Gourisetti, Sri Nikhil G..

Cybersecurity Risk Assessment Framework for Externally Exposed Energy Delivery Systems

Securing the energy delivery system (EDS) from complex, nonlinear, and evolving cyber threats requires a complex set of changing and interwoven classes of technologies, policies, relationships, and personnel. One key area in this technological milieu is assessment methodologies to compare information, gathered by a variety of means, about networked devices with publicly known possible threat information about said devices. This information is used to generate risk-based characterizations that allow for the adjudication and proper corresponding management action chains to be assigned.

Gourisetti, Sri Nikhil G.↗

Evaluation and Demonstration of Blockchain Applicability Framework

Blockchain technology has been gaining great interest from a variety of industry sectors, including financial, food processing, and power and energy markets. Realizing the strength of blockchain technology beyond the successful application in the cryptocurrency arena, researchers have been evaluating and using blockchain for applications such as supply chain management, transactive industry (both financial and energy), system integrity, device cybersecurity, identity management, and much more. One of the unique elements of the blockchain technology that made it such a captivating technology to researchers is its plethora of features. Some of the features include smart contracts, cryptocurrency and tokenizing, immutable distributed ledger, cryptographic hashing, and digital signature. In addition, there are multiple types of blockchains, such as permissioned/private and permissionless/public, and various consensus models, such as proof-of-work, proof-of-authority, proof-of-burn, and proof-of-stake. Therefore, it is often non-trivial to determine if an application requires a blockchain. If so, what kind of blockchain and consensus is most appropriate? This paper discusses the blockchain applicability framework (BAF), which was specifically designed with the purpose to answer those questions. BAF is divided into five domains, 18 subdomains, and about 100 controls. It is designed to ingest detailed user requirements to perform a weighted evaluation that is built on mathematical constructs to determine the ideal combination of blockchain that is appropriate for an application. Along with the core logical formulation of BAF, this paper depicts the efficacy of BAF through two use cases

Gourisetti, Sri Nikhil G.↗

Cyber Threat Dictionary Using MITRE ATT&CK Matrix and NIST Cybersecurity Framework Mapping

Cyber-attack and defense frameworks offer numerous ways to protect systems and networks from threats. However, only a few of these numerous attack and defense frameworks provide countermeasures by linking multiple frameworks. Due to the lack of attack-defense mapped frameworks, a number of cyber security practitioners are often puzzled how to cope with cyber-attacks when it occurs. The objective of this paper is to present a tool called the “Cyber Threat Dictionary” to solve the problem . Cyber Threat Dictionary offers approaches and practical solutions to the threats by mapping MITRE ATT&CK Matrix to the NIST Cybersecurity Framework. By providing immediate solutions to cyber security practitioners, Cyber Threat Dictionary enables effective responses against cyber-attacks.

MITRE ATT&CK MATRIX, NIST Cybersecurity Framework,↗

IS BLOCKCHAIN A SUITABLE TECHNOLOGY FOR ENSURING THE INTEGRITY OF DATA SHARED BY LIGHTING AND OTHER BUILDING SYSTEMS?

Increasing amounts of data are available from lighting and other building systems. In commercial buildings, these data can be used to improve system and energy performance, detect and diagnose faults, and facilitate maintenance. Building data are not only of interest to owners and operators of the building systems, however. Owners and operators of similar buildings, manufacturers of building systems, utilities, and city agencies also have interesting use cases. Energy data can, for example, be used to verify the performance of energy-conservation measures, issue renewableenergy certificates, and financially settle grid services. Increased data sharing, however, significantly expands the cyber-attack surface, creating new challenges. In this work, blockchain is explored as an option for ensuring the integrity of data that are shared by lighting and other building systems. Blockchain fundamentals and variants are briefly reviewed, and value propositions relevant to building systems are discussed. A recently developed blockchain applicability framework (BAF) that builds upon and addresses the limitations of previous applicability models is also briefly reviewed. The BAF is used to assess the suitability of blockchain over other technologies or approaches for building-data applications, using emerging connected lighting systems as an example use case.

blockchain, connected lighting system, data integr↗

Electricity Subsector Transmission Resilience Maturity Model (TRMM) User Guide

The electric transmission sector is facing a range of threats to its functionality that are either new, more severe than experienced in earlier years, or more well understood. Such threats include more frequent and more severe extreme weather events, wildfires, droughts, and human-caused physical and cyberattacks. They also include geological, electromagnetic, and biological events. The novelty or increasing severity of these threats creates a significant need for transmission owners to implement programs to prevent, prepare for, respond to, and recover from such incidents. The national and economic security of the United States depends on the reliable functioning of the Nation’s critical infrastructure in the face of such threats, and the transmission networks are essential components of that infrastructure. The Electricity Subsector Transmission Resilience Maturity Model (TRMM) is a tool that a transmission organization can use to objectively evaluate and benchmark its currently established transmission resilience strategies, programs, policies, and investments, in order to target and prioritize enhancements where needed. The TRMM was developed to address the unique characteristics of the transmission system. The model can enable users to: • evaluate and benchmark their organization’s resilience capabilities, effectively and consistently • prioritize actions and investments to improve the resilience of their systems • share transmission-related knowledge, best practices, and relevant references within their organization and with business partners as a means to improve resilience capabilities • contribute to increasing the overall resilience of the Nation’s transmission systems. The TRMM provides descriptive rather than prescriptive industry-focused guidance. The model content is presented at a high level of abstraction so that it can be interpreted by transmission organizations of various types, structures, and sizes. The model is designed to an be easy-to-use, self-assessment tool.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Facility Cybersecurity Framework Best Practices

Federal facilities are increasingly adopting automation and connecting to the Internet creating an energy-internet-of-things environment that converges operational technology (OT) and information technology (IT). Today's buildings increasingly weave together networked sensors and cyber and physical systems that enable data to be collected, aggregated, exchanged, stored and monetized in new ways. Building technological advances have created new energy technology, services, markets and value creation opportunities (e.g. transactive energy, two-way grid communications, machine learning, and increased use of renewable and distributed energy resources). But as larger data sets are being exchanged at faster speeds between an increasing number of OT systems, it becomes more difficult to protect the security of the data lifecycle and the physical equipment it interacts with. These challenges are especially difficult to overcome because the economic and environmental gain (interoperability, big data, social networks and ubiquitous information sharing) are driving these prominent trends in the digital age. Often cybersecurity is an afterthought. The U.S. Department of Energy’s (DOE) Federal Energy Management Program (FEMP) funded the Pacific Northwest National Laboratory (PNNL) to develop various cybersecurity tools, trainings, and reports to aid federal facility managers – and other building owners and operators – in better applying frameworks and lessons learned from the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), risk management framework (RMF), DOE’s cybersecurity capability maturity model (C2M2), and a wide variety of industry best practices and guidance documents (i.e., NIST 800 series, Department of Defense United Facilities Criteria). This set of tools, collectively known as the FEMP Facility-Related Control System Cyber Toolkit (FRCS Cyber Toolkit)2, is focused on cybersecurity concerns from facility-related control systems and other operational technology (OT), such as industrial control systems (ICS). The FRCS Cyber Toolkit can be applied across six of the sixteen critical infrastructure sectors designated by the Department of Homeland Security, including government facilities, healthcare and public health, commercial facilities (e.g., public assembly, offices, lodging), financial services (e.g., banking and insurance), emergency services (e.g., fire and police stations), and information technology. With increasingly converged IT and OT systems, it is crucial to address OT cybersecurity considerations and assess how the seam of these two systems could impact the overall cybersecurity posture of a facility. The objective of this report is to provide an overview of the best possible method to use FRCS Cyber Toolkit (section 2.0) and distilled cybersecurity best practices for the federal facilities to address growing non-linear cyber threats (section 3.0). Recommendations in this document are aggregated from several NIST and other documents (see Appendix A for additional details).

97 MATHEMATICS AND COMPUTING↗