A data-based private learning framework for enhanced security against replay attacks in cyber-physical systems
Not provided.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not provided.
Deployment of digital technologies within a modern shift in cyber defense systems is essential for protecting the energy production units. One of the important components of defense is cyberforensics: once an attack has been detected to locate its origin. In this paper, a review of well-known cyberattacks in nuclear facilities is provided, with the lessons learned leading to the development of a machine learning approach implementing identification of internal at- tacks in the facility's data networks. Our approach may be seen as one of the layers in a defense-in-depth strategy that identifies if the attack comes from inside, which may result in identifying faster the attacker's origin. The presented model exploits network packet examination to cast accurate predictions on detailing the origin of malicious network connections. The approach fuses multiple mathematical functions within an artificial neural network to provide a response in the form of 0/1, i. e., whether the attack is identified as internal or not. The utilization of a variety of test cases is developed to explore the relevance and validity of the predictive approach. The proposed implementation is examined with network data packet variance, and the results obtained exhibit a highly accurate detection rate.
Cyber physical security of power systems with high penetration of renewable generation has attracted attention from researchers. One critical issue is that cyber-physical attacks, disguised as uncertain renewable generation, can target conventional power system state estimation (SE). Moving target defense (MTD) is a promising defense strategy to detect stealthy false data injection (FDI) attacks against SE. However, all existing studies myopically perturb the reactance of transmission lines equipped with distributed flexible AC transmission system (D-FACTS) devices without adequately considering the system voltage stability. Exacerbated by the renewable generation uncertainty, existing MTD may cause voltage instability when the power grid is under stress. To address this issue, we propose a novel MTD framework that explicitly considers system voltage stability by using continuation power flow. We utilize the sensitivity matrix of power injection to line impedance, on which an optimization problem for maximizing load margin is formulated. This framework is validated on the IEEE 14-bus system and the IEEE 118-bus system, in which net load redistribution attacks are launched by sophisticated attackers. Steady-state simulations and dynamic simulations on PSS/E show the effectiveness of the proposed framework in circumventing the voltage instability while maintaining the detection effectiveness of MTD. The impact of the proposed method on attack detection effectiveness is also revealed.
Technology related to evaluating cyber-risk for synchrophasor systems is disclosed. In one example of the disclosed technology, a method includes generating an event tree model of a timing-attack on a synchrophasor system architecture. The event tree model can be based on locations and types of timing-attacks, an attack likelihood, vulnerabilities and detectability along a scenario path, and consequences of the timing-attack. A cyber-risk score of the synchrophasor system architecture can be determined using the event tree model. The synchrophasor system architecture can be adapted in response to the cyber-risk score.
This final report provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company Services, Inc. at Alabama Power Company’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.
The report summarizes key tasks performed to develop a toolkit for detecting cyber-attack events in instrumentation and control (I&C) systems of nuclear power plants. The toolkit connects the state-of-the-art GPWR Simulator with the RELAP5 code providing best-estimate nuclear steam supply system (NSSS) analyses, via the application programming interface (API), and allows users to introduce potential cyber-attack scenarios into power plant operational simulation. This summary for the project reflects topical reports submitted during the project as well as a journal paper published in 2022. The focus areas of the summary include: (1) modeling I&C systems for the AP1000 Generation III+ nuclear plant and GPWR simulator, (2) simulation and monitoring of plant response to cyber-attack events, (3) API structure for the toolkit interfacing the GPWR simulator and RELAP5 code, and (4) restructuring of the three-loop NSSS software of GPWR to model the two-loop AP1000 structure. Discussed in some details are (a) the attack tree analysis assessing the susceptibility of the AP1000 I&C system, resulting in reactor trips, in terms of the attack possibility and component sensitivity and (b) realistic estimation of the time to steam generator trip due to cyber-intrusions in the GPWR Simulator. Finally, sample demonstrations of the cyber-security tool kit, in the form of the GPWR-RELAP5 API, are summarized.
The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.
The frequency and severity of spruce bark beetle outbreaks are increasing in boreal forests leading to widespread tree mortality and fuel conditions promoting extreme wildfire. Detection of beetle infestation is a forest health monitoring (FHM) priority but is hampered by the challenges of detecting early stage (“green”) attack from the air. There is indication that green stage might be detected from vertical gradients of spectral data or from shortwave infrared information distributed within a single crown. To evaluate the efficacy of discriminating “non-infested”, “green”, and “dead” health statuses at the landscape scale in Alaska, USA, this study conducted spectral and structural fusion of data from: (1) Unoccupied aerial vehicle (UAV) multispectral (6 cm) + structure from motion point clouds (~700 pts per sq. m); and (2) Goddard Lidar Hyperspectral Thermal (G-LiHT) hyperspectral (400 to 1000 nm, 0.5 m) + SWIR-band lidar (~32 pts per sq.m). We achieved 78% accuracy for all three health statuses using spectral + structural fusion from either UAV or G-LiHT and 97% accuracy for non-infested/dead using G-LiHT. We confirm that UAV 3D spectral (e.g., greenness above versus below median height in crown) and lidar apparent reflectance metrics (e.g., mean reflectance at 99th percentile height in crown), are of high value, perhaps capturing the vertical gradient of needle degradation. In most classification exercises, UAV accuracy was lower than G-LiHT indicating that collecting ultra-high spatial resolution data might be less important than high spectral resolution information. While the value of passive optical spectral information was largely confined to the discrimination of non-infested versus dead crowns, G-LiHT hyperspectral band selection (~400, 675, 755, and 940 nm) could inform future FHM mission planning regarding optimal wavelengths for this task. Interestingly, the selected regions mostly did not align with the band designations for our UAV multispectral data but do correspond to, e.g., Sentinel-2 red edge bands, suggesting a path forward for moderate scale bark beetle detection when paired with suitable structural data.
This paper provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company at Alabama Power’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.
Modern vehicles rely on complex cyber-physical systems made up of hundreds of electronic control units (ECUs) connected through controller area network (CAN) buses. However, the CAN bus attack surface is increasing due to advanced features in automobiles, making it prone to injection attacks. The ordinary injection attacks disrupt the typical timing properties of the CAN data stream, and the rule-based intrusion detection systems (IDS) can easily detect them. However, advanced attackers can inject false data to the signal level, maintaining the regular pattern/frequency of the CAN messages. Such attacks can bypass the rule-based IDS or any anomaly-based IDS built on binary payload data. To make the vehicles robust against such intelligent attacks, we propose CANShield, a signal-based intrusion detection framework for the CAN bus that consists of three modules. A data preprocessing module handles the high-dimensional CAN data stream at the signal level and make them suitable for any machine learning model. A data analyzer module consists of multiple deep autoencoder networks, each analyzing the time series data from a different perspective. Finally, an attack detection module uses an ensemble method to make the final decision. Evaluation results on a standard signal-based dataset show the effectiveness of the CANShield in detecting five advanced attacks.
The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.
The Industroyer2 and Wiper Malware Targeting Ukrainian Energy Provider 2022 Precursor Analysis Report leverages publicly available information about the Industroyer2 cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. An adversary attempted to cause a blackout in Ukraine in April 2022 by using the Industroyer2 malware against a regional Ukrainian energy provider. The adversary targeted eight high-voltage electrical substations and utilized the malware in tandem with disk wipers for Windows, Linux, and Solaris operating systems in an attempt to make response and recovery efforts more difficult. The adversary reused a piece of the original Industroyer malware designed to open circuit breakers and de-energize target substations. The adversary gained initial access to the victim’s enterprise network through unknown means in February 2022 and was able to perform reconnaissance, pivot to the operations network, and reside in the system for at least 51 days. This gave the adversary a detailed understanding of the environment and allowed them to customize the Industroyer2 malware to the victim’s operations network. However, defenders detected and stopped the attack before the adversary could achieve their intended impact. Had the Industroyer2 attack been successful, it could have caused a blackout for more than two million people during the early stages of Russia’s invasion of Ukraine. Researchers and analysts identified 22 unique techniques (used in a sequence of 31 steps) utilized during the attack with a total of 297 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-three of the identified techniques used during the Industroyer2 cyber attack were precursors to the triggering event. Analysis identified 224 observables associated with these precursor techniques, 122 of which were assessed to have an increased likelihood of being perceived in the 51 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.
Battery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/ physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks.
Smart buildings, especially Grid-interactive Efficient Buildings (GEBs), suffer from cyber-attacks and physical faults due to the integration of a large number of sensors and controls, connected devices, and associated communication networks. This study demonstrated a real-time advanced building resilient platform, called CYber Defense and REsilient System (CYDRES), which is deployable for existing and emerging Building Automation Systems (BASs). CYDRES aims to empower GEBs with cyber-attack-immune capabilities through multi-layer prevention and adaptation mechanisms to monitor, detect, and respond to cyber-attacks and physical operational faults. CYDRES is demonstrated through real-time experiments in a Hardware-in-the-Loop (HIL) testbed.
In this paper, an intrusion proof adjustable speed drive system controlling a critical process in an industrial control system is detailed. In such a system, should the motor speed sensor signal data be compromised and/or altered via a cyber-attack, the system can potentially be unregulated, over speed and/or malfunction thereby disrupting the critical process. The proposed active detection scheme detailed in this paper introduces a private (secret) random signal termed as "watermark" into the inverter control signal that determines the PWM gating signals of the DC-AC inverter powering the motor. The watermarking signal introduced into the PWM modulation for the DC-AC inverter is shown to propagates its unique signature, which appears in all sensors signals at the inverter output such as voltage/current/speed used to control the motor. Now employing the measured data (from sensors), two statistical variance tests are conducted to identify anomalies if any in the presence of the watermarking signal. It is shown when an intrusion occurs to manipulate the sensor data to disturb and/or destabilize the process, the proposed tests immediately display a high value indicating a compromise in sensor data. It is shown that the proposed system is capable of immediate detection of a sophisticated attacks such as record/reply attack in which the actual speed sensor is disconnected and a prerecorded speed signal from the past of the same magnitude is played back to the controller. Several types of cyber-attacks such as speed reduction/increase including vibration have been tested. Extensive simulation results verify the proposed concepts. Experimental results will be discussed in the conference presentation.
The urgent need for the decarbonization of power grids has accelerated the integration of renewable energy. Concurrently, increasing distributed energy resources (DER) and advanced metering infrastructure (AMI) have transformed the power grids into a more sophisticated cyber-physical system with numerous communication devices. While these transitions provide economic and environmental value, they also impose increased risk of cyber attacks and operation al challenges. This paper investigates the vulnerabilit y of the power grids with high renewable penetration against an intraday false data injection (FDI) attack on DER dispatch signals and proposes a kernel support vector regression (SVR) based detection model as a countermeasure. The intraday FDI attack scenario and the detection model are demonstrated in a numerical experiment using the HCE 187-bus test system.
With the increasing deployment of Flexible AC Transmission System (FACTS) devices in wide-area voltage control systems (WAVCS) for achieving improved voltage stability of bulk power systems, the possibility for cyber attacks on these systems is also increasing. Successful stealthy cyber attacks that are difficult to detect by traditional informational technology (IT)-based cybersecurity solutions or threshold-based bad data detectors can lead to a voltage collapse in power grid. This paper presents the testbed-based attacks implementation and real-time evaluation of machine learning (ML) algorithm for detecting and mitigating stealthy cyber attacks on FACTS-based WAVCS on a hardware-in-the-loop (HIL) testbed. Initially, we discuss the implementation of a fuzzy logic controller (FLC) that controls a Static VAR Compensator (SVC) device deployed in a two-area four-machine Kundur power system for improving transient voltage stability. Later, the ML-based Anomaly Detection and Mitigation (ADM) system is implemented on the cyber-physical HIL testbed to detect and mitigate various stealthy cyber attacks, which are injected in real-time over the wide-area network (WAN). The experimental results show accurate and effective performance of ADM system in detecting and mitigating anomalies while keeping the grid stable and within the system operating limits, as defined by the North America Electric Reliability Corporation (NERC).