Engineering Papers⌕ Search

Engineering topics

Paul, Shuva

Publications and source records attributed to Paul, Shuva.

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

Cybersecurity for Energy Systems: Foundational Concepts for Bangladesh Electric Utilities [Slides]

This slide deck was developed for a training for the Northern Electricity Supply Company (NESCO) in Rajshahi, Bangladesh. The topics include: understanding the cybersecurity landscape in power utilities, fundamentals of cybersecurity for power utilities, regulatory compliance and standards, and best practices and strategies. The concepts in this slide deck are relevant for electric utilities throughout Bangladesh.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Resilience assessment and planning in power distribution systems: Past and future considerations

High impact low probability (HILP) events such as hurricanes, heat waves, and floods have instigated widespread power outages and blackouts around the globe in the past decade. With the increasing challenges concerning the threats to the power distribution systems and the growing need to mitigate the impacts of the HILP events, resilience has become a crucial requirement for the power grid infrastructures. Numerous efforts have been made to define, measure, and characterize the resilience of power distribution systems. This study thoroughly reviews the state-of-the-art methods on the existing resilience evaluation framework and metrics. Here, the desirable characteristics of resilience metrics are highlighted, and the challenges associated with formulating, developing, and calculating such metrics are discussed. Next, we detail the state-of-the-art literature on planning solutions to ensure distribution system resilience. This paper aims to extract a deep insight into this challenging and critical research area and envision future opportunities that can guide the power distribution system operators/planners to formulate more effective mitigation strategies to enhance the resilience of power distribution systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Experimental Setup for Grid Control Device Software Updates in Supply Chain Cyber-Security

Supply chain cyberattacks that exploit insecure third-party software are a growing concern for the security of the electric power grid. These attacks seek to deploy malicious software in grid control devices during the fabrication, shipment, installation, and maintenance stages, or as part of routine software updates. Malicious software on grid control devices may inject bad data or execute bad commands, which can cause blackouts and damage power equipment. This paper describes an experimental setup to simulate the software update process of a commercial power relay as part of a hardware-in-the-loop simulation for grid supply chain cyber-security assessment. The laboratory setup was successfully utilized to study three supply chain cyber-security use cases.

Keller, Joseph↗

Signal-Based Fast Tripping Protection Schemes for Electric Power Distribution System Resilience

This report is a summary of a 3-year LDRD project that developed novel methods to detect faults in the electric power grid dramatically faster than today’s protection systems. Accurately detecting and quickly removing electrical faults is imperative for power system resilience and national security to minimize impacts to defense critical infrastructure. The new protection schemes will improve grid stability during disturbances and allow additional integration of renewable energy technologies with low inertia and low fault currents. Signal-based fast tripping schemes were developed that use the physics of the grid and do not rely on communication to reduce cyber risks for safely removing faults.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Resilient Design Methodology for Microgrids

Recent advancement in tools has helped with microgrid design, development, planning and operation. Microgrids offer a unique application based on users with different requirements for tools. The process of designing, constructing, commissioning, and assessing a microgrid is not always straightforward due to these distinct requirements. Additionally, metrics are needed for performance evaluation. This panel will offer an overview and description of tools that helps with microgrid design, construction, planning, operation, cyber security, and metrics-driven performance assessment driven by multiple diverse applications and use cases.

CCE↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗