Engineering Papers⌕ Search

Engineering topics

Vaughan, Evan

Publications and source records attributed to Vaughan, Evan.

Cyber Energy Emulation Platform (CEEP) [SWR-20-102]

NREL's Cyber-Energy Emulation Platform (CEEP) provides the capability to realize cyber-energy security and resilience through automation and orchestration of virtualized systems and software defined networks for the electric grid. CEEP enables testing and validation of grid-security and -control methodologies as the grid evolves to include smart technologies/systems, such as virtualization and containerization of grid components, software defined networking, simulation and co-simulation frameworks, and hardware in the loop. CEEP is a modular system that can be distributed and deployed across different hardware infrastructure sizes and network architectures. For example, CEEP can visualize, emulate, and/or coordinate the Smart-Grid Network Visualization, Intrusion Detection, and Network Healing system. Using CEEP, intrusion-detection and network-self-healing solutions can be deployed at grid control centers, within secure private clouds, and in cyber-energy appliances.

Rivera, Joshua↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗

HIDES (Hybrid Intrusion Detection for Energy Systems) [SWR-19-65]

Hybrid Intrusion Detection for Energy Systems (HIDES) is a conglomerate detector that incorporates three major components: (1) Signature-based detection that involves information technology (IT) related anomaly detection rules, (2) Behavior-based detection that utilizes specially crafted rulesets for detecting abnormal behavior regarding the power system's supervisory control and data acquisition (SCADA) communication streams, and (3) Learning-based detection that combines SCADA communication with phasor measurements to identify otherwise non-detectible attack vectors. The software itself interconnects intrusion detection engine (IDE) enabling communications between the generated OT and IT alerts with phasor measurements for the learning-based detection system. The resulting detection system can detect a wide array of IT, OT, and physical attacks in a real-time setting.

Rivera, Joshua↗