Engineering PapersSearch

DOE OSTI · 3364044

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Abstract

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Francis, Paul-Ann Shannon [Idaho National Laboratory (INL), Idaho Falls, ID (United States)]. 2025-08-02. Evidence-based Graph Adversary Mapping (EGRAM) [Poster]. https://doi.org/10.2172/3364044

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related reports

Validating Protection System Behavior with Machine Learning in a Master State Overseer

As power system protection devices continue the widespread transition from analog to digital, they become increasingly intricate. The internal functions and communication between critical grid components must now be significantly more complex to keep up with the demands of the modern smart grid. This brings increased difficulty in maintenance and monitoring, making it harder to identify potential misoperation, power anomalies, and cyber threats. Such issues are often only pinpointed after an exhaustive and costly post-mortem analysis, when a major outage or damage has already occurred. A solution is needed for validating protection systems as they operate, independently evaluating grid state and confirming whether the protection system is behaving accordingly. As opposed to incident response, this acts as a constant verification mechanism that raises a flag when subtler issues are noticed, catching them earlier and preventing larger incidents. This work presents the implementation of such a system, expanding on the prototype developed by the authors in a previous paper. This is accomplished with a machine learning (ML) system capable of validating the performance of protection systems by classifying anomalous events and characterizing protection system responses based solely on available current and voltage measurements. Additionally, this system is contextualized within a larger, modular Master State awareness Overseer (MSO) framework, responsible for monitoring, analyzing, and managing an electric grid.

24 - POWER TRANSMISSION AND DISTRIBUTION

SULI End of Summer Presentation

This presentation made on Power Point is a brief summary of my work enhancing the Supervisory Control and Data Acquisition (SCADA) architecture for Idaho National Lab’s Critical Infrastructure Test Range Complex (CITRC). This work was part of an on-going project to create a digital twin of CITRC that will be implemented for resiliency research. Resiliency is growing more important as extreme weather, aging infrastructure, and increasing load all exert stress on the United States power grid. This presentation highlights how I documented the existing devices and data flow on site and then updated specific device settings to better support the needs of the project. It also examines future use of this data in the digital twin data warehouse (DeepLynx), and future Artificial Intelligence and Advanced Distribution Management System applications. It will be presented to the B751 Water and Energy Systems Analysis group at INL during my last week.

24 - POWER TRANSMISSION AND DISTRIBUTION

Data Management for Digital Twin Implementation: Enhancing Existing SCADA Architecture for INL's CITRC Test Distribution System

The United States power grid will continue to experience stress from aging infrastructure, extreme weather, and increasing loads. In order to strengthen resiliency, researchers need to run tests and simulations that model real-life infrastructure. Idaho National Laboratory (INL) is creating a digital twin of its Critical Infrastructure Test Range Complex (CITRC). CITRC is an at-scale grid testbed which can be configured in utility-realistic distribution scenarios for a variety of tests, such as advanced grid protection and control. A digital twin of this infrastructure would support in-depth tests/simulations without risking physical consequences, before trialing devices under test at-scale. This project focuses on the data acquisition part of constructing a digital twin. It investigates the Supervisory Data Acquisition and Control (SCADA) system of CITRC and explores ways to utilize this system for the twin. Future “ideal” at-scale implementations such as upgraded equipment, modern communication protocols, and automation applications are also explored.

24 - POWER TRANSMISSION AND DISTRIBUTION