Engineering Papers⌕ Search

DOE OSTI · 2221826

A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems

Abstract

This paper demonstrates a novel randomization-based approach for verifying power system control signals with application to detecting cyberattacks. We consider fully connected hierarchical systems containing multiple local agents and a global "trust" agent. The global agent uses a time-varying randomized assignment scheme to identify corrupt network links based on principles of zero trust and majority rule. To evaluate the performance of this detection approach, we implement our algorithm in MATLAB and run it against nearly 43 million unique attack scenarios spanning a range of system sizes. For each scenario, the algorithm determines whether the identified corruptions satisfy a set of validity constraints reflecting network topology and uses that result to say whether the recovered state value for one or more local agents is malicious. We compare the algorithm's determination to the true state of the system to assess performance and find that classification accuracy converges to 100% as system size increases, suggesting that the validity constraints become more difficult to satisfy for larger systems. We further explore the scenarios that evade detection to understand practical implications for employing this detection approach.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Murphy, Sinnott, Macwan, Richard, Singh, Vivek Kumar, Chang, Chin-Yao. 2023-11-08. A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems. https://doi.org/10.1109/secdev56634.2023.00029

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related reports

Programmable Digital Devices used in Advanced Reactors

This paper introduces the concepts of common cause failure, diversity, and defense-in-depth used by the nuclear industry to analyze resilience in reactors. A survey of publicly traded and private companies building advanced reactors and their licensing status is presented. Safety and non-safety systems found in the NuScale Power design are summarized and the likely hardware and software categories used by those systems are enumerated. The importance of industry partners is highlighted. This paper also identifies an alternate path forward without industry partners to advance the knowledge needed to use artificial intelligence to analyze HBOMs and SBOMs to better understand reactor resiliency.

cybersecurity↗

Enhancing the Survivability of Power Systems With Grid-Edge DERs Against DoS Attacks

Power system survivability, defined as the ability of a system to maintain steady-state functionality under varying operational conditions, reflects its resilience against disturbances. While existing research primarily focuses on physical-layer disturbances, the increasing prevalence of grid-edge DERs, which are primarily used for integrating renewable energy, has significantly expanded the cyber attack surface. As a result, operational disruptions caused by cyber threats are posing significant challenges to system survivability and cannot be overlooked. To fill this gap, we redefine system survivability to incorporate the cyber layer’s status and propose a Distributionally Robust Optimization (DRO) approach to enhance power system survivability against potential cyber-physical threats. In this paper, we first analyze the operational guidelines of systems with a high penetration of DERs under various cyber network conditions and redefine survivability in this context. Next, we focus on the most common cyber threat, Denial-of-Service (DoS) attacks, and develop a corresponding attack model. This model allows for the creation of a kernel-based ambiguity set that captures attack uncertainties using historical data. Finally, we transform the proposed DRO model as a tractable optimization problem, with its solution providing an optimal cyber redundancy plan to enhance system survivability in DoS attack scenarios. Simulation results on the IEEE 13-node and 123-node test feeders demonstrate the effectiveness of our proposed model in improving system survivability. This model can also be expanded to include other types of common attacks and serve as a comprehensive planning tool to improve overall cyber physical survival of the system.

cybersecurity↗

IBR Digital Supply Chain Gap Analysis and Recommendations

The adoption of clean energy technologies, including solar photovoltaics, continues to introduce non-traditional stakeholders to the operations and planning of the electric system. Stakeholders such as manufacturers, vendors, owners, aggregators, and others are enabling the adoption, integration, and optimum operations of solar technologies at accelerated rates. Inverters form the foundation of many digitally controlled energy sources for clean energy technologies, including Solar, Battery Energy Storage Systems, Hybrid Systems, and Hydrogen Fuel Cells. Their supply chain is complex, a series of microchips, electronic switches and other components making up its primary functions. The complexity of this space and the growing digitization associated with these components can create supply chain cyber risks. One measure to mitigate cybersecurity attacks is proper digital supply chain security. The U.S. Department of Energy (DOE) Solar Energy Technologies Office (SETO), in partnership with the Cybersecurity, Energy, Security, and Emergency Response (CESER) office, is hosting a workshop to bring together solar vendors and services providers to discuss digital supply chain security for solar systems and challenges and opportunities in the transitioning to a fully domestic supply chain for solar energy in the U.S. This workshop will support the Securing Solar for the Grid (S2G) and Energy Cyber Sense program activities. During the workshop, industry experts and researchers from DOE National Laboratories will discuss the current solar supply chain landscape and the transition to domestic manufacturing of solar components in the U.S. Tools and techniques to better manage and secure the digital supply chain of solar devices and systems will be discussed.

cybersecurity↗