Industrial and Critical Infrastructure Security: Technical Analysis of Real-Life Security Incidents
Not Available
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not Available
Module-OT is a bump- in- the- wire solution acting as a secure conduit for data between devices or systems across a network. Using the latest in open-source cryptographic libraries, all defined communications undergo authentication, authorization, and encryption. The core system can be easily installed through industry standard processes, and the use of popular open-source packages allows for it to be customizable customized by the developer community or deployed in unique embedded environments.
As electric power systems undergo a transformative upgrade with the integration of advanced technologies to enable the smarter electric grid, professionals who work in the area require a new understanding of the evolving complexity of the grid. Cyber Infrastructure for the Smart Electric Grid delivers a comprehensive overview of the fundamental principles of smart grid operation and control, smart grid technologies, including sensors, communication networks, computation, data management, and cyber security, and the interdependencies between the component technologies on which a smart grid's security depends. The book offers readers the opportunity to critically analyze the smart grid infrastructure needed to sense, communicate, compute, and control in a secure way.
This report describes the results of Discrete Fracture Network (DFN) simulations for the Topopah Spring Aquifer (TSA), Lava Flow Aquifer, and Tiva Canyon Aquifer (TCA), at Pahute Mesa on the Nevada National Security Site (NNSS), formerly the Nevada Test Site. The research focuses on calculating upscaled groundwater flow and contaminant transport parameters using DFNs generated according to fracture characteristics observed in the TSA, LFA and TCA at Pahute Mesa. The highly fractured and heterogeneous nature of these aquifers makes them candidates for stochastic DFN modeling of radionuclide transport on a small scale with subsequent upscaling. One hundred independent DFN realizations are generated for each aquifer, and the upscaled parameters for continuum simulations of subsurface flow and transport in fractured media at Pahute Mesa are calculated. Our goal is to implement a modeling approach that can translate parameters to larger-scale models that account for local-scale flow and transport processes, such as channelization of flow and transport along a few well connected, large fractures. Additionally, to simulate advective and advective-diffusive transport through the fracture networks, the Time Domain Random Walk (TDRW) approach is applied to account for matrix diffusion into a finite half-space. Moreover, a novel approach to calculate dynamic (active) fracture surface area to reflect flow channeling is implemented. This work will improve the representation of radionuclide transport processes in largescale, regulatory-focused models by providing estimates of hard-to-measure flow and contaminant transport parameters at large scales. In this report, we (1) show recent results of flow and transport simulations on multiple DFN realizations of the TSA, LFA, TCA; (2) discuss the resulting distributions of estimated upscaled parameters; (3) describe the estimation of upscaled parameters for an equivalent parallel-plate continuum model and (4) present a comparison between simulated transport from the equivalent continuum model and an actual DFN.
Write-optimized data structures (WODS), offer the potential to keep up with cyberstream event rates and give sub-second query response for key items like IP addresses. These data structures organize logs as the events are observed. To work in a real-world environment and not fill up the disk, WODS must efficiently expire older events. As the basis for our research into organizing security monitoring data, we implemented a tool, called Diventi, to index IP addresses in connection logs using RocksDB (a write-optimized LSM tree). In this work, we extended Diventi to automatically expire data as part of the data structures’ normal operations. We guarantee that Diventi always tracks the N most recent events and tracks no more than N + k events for a parameter k < N, while ensuring the index is opportunistically pruned. To test Diventi at scale in a controlled environment, we used anonymized traces of IP communications collected at SuperComputing 2019. We synthetically extended the 2.4 billion connection events to 100 billion events. We tested Diventi vs. Elasticsearch, a common log indexing tool. In our test environment, Elasticsearch saw an ingestion rate of at best 37,000 events/s while Diventi sustained ingestion rates greater than 171,000 events/s. Our query response times were as much as 100 times faster, typically answering queries in under 80 ms. Furthermore, we saw no noticeable degradation in Diventi from expiration. We have deployed Diventi for many months where it has performed well and supported new security analysis capabilities.
Spectrum Sharing (SS) has seen a renewed set of initiatives in 5G with the availability of shared and unlicensed spectrum bands that can be used by multiple cellular service providers and private cellular networks. Beam based transmission, instead of the traditional sector based transmission in conjunction with the spectrum agility of the 5G New Radio (NR) has brought new opportunities to optimized sharing of spectrum. Currently in the U.S., a centralized Spectrum Access Server (SAS) is used to co-ordinate spectrum sharing among networks sharing the same spectrum band. However, SAS becomes a focal point for security attacks and a performance bottleneck. In addition, SAS relies on an Environmental Sensor Network (ESN), separate from the 5G network. Without trusted spectral occupancy information, false reporting of spectrum sensing data can create sub-optimal and unfair spectrum usage. This paper summarizes our recent research findings in using a decentralized scheme for multiple networks to securely share spectrum with autonomous beam scheduling : 1) A new stochastic network framework based on Lyapunov Optimization approach is developed to optimize scheduling at the base stations; 2) Game theoretic (GT) approach is used to formulate the distributed scheduler; 3) Another distributed scheduler with Q-learning is presented that utilizes the Reinforcement Learning (RL) approach; 4) The performance and convergence rate of these distributed solutions to use shared and unlicensed spectrum are compared with existing solutions. Conditions under which the performance of these schedulers approach the theoretical upper bound, which is the performance possible with no interference among the operators sharing the spectrum, are presented; 5) The ability of a base station to use its own user equipment as sensors, for optimal spectrum sharing with base stations in other operator networks, is demonstrated to be an effective approach.
The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.
Communication networks in power systems are a major part of the smart grid paradigm. It enables and facilitates the automation of power grid operation as well as self-healing in contingencies. Such dependencies on communication networks, though, create a roam for cyber-threats. An adversary can launch an attack on the communication network, which in turn reflects on power grid operation. Attacks could be in the form of false data injection into system measurements, flooding the communication channels with unnecessary data, or intercepting messages. Using machine learning-based processing on data gathered from communication networks and the power grid is a promising solution for detecting cyber threats. In this paper, a co-simulation of cyber-security for cross-layer strategy is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection as well as identification of anomalies in the operation of the power grid. The framework is implemented on the IEEE 118-bus system. The system is constructed in Mininet to simulate a communication network and obtain data for analysis. A distributed three controller software-defined networking (SDN) framework is proposed that utilizes the Open Network Operating System (ONOS) cluster. According to the findings of our suggested architecture, it outperforms a single SDN controller framework by a factor of more than ten times the throughput. This provides for a higher flow of data throughout the network while decreasing congestion caused by a single controller’s processing restrictions. Furthermore, our CECD-AS approach outperforms state-of-the-art physics and machine learning-based techniques in terms of attack classification. The performance of the framework is investigated under various types of communication attacks.
High-fidelity quantum entanglement enables key quantum networking capabilities such as secure communication and distributed quantum computing, but long-distance entanglement distribution is limited by noise and loss. Entanglement distillation protocols address this problem by extracting high-fidelity Bell pairs from multiple noisy ones. The primary objective is minimizing the resource overhead: the number of noisy input pairs needed to distill each high-fidelity output pair. While protocols achieving optimal overhead are known in theory, they often require complex decoding operations that make practical implementation challenging. We circumvent this challenge by introducing protocols that use quantum scrambling—the spreading of quantum information under chaotic dynamics—through random Clifford operations. Based on this scrambling mechanism, our protocol maintains asymptotically constant overhead, independent of the desired output error rate $\bar{𝜖}$ , and can be implemented with shallow quantum circuits of depth 𝑂(poly log log $\bar{𝜖}$ −1 ) and memory 𝑂(poly log $\bar{𝜖}$ −1 ). Our protocol remains effective even with noisy quantum gates. By incorporating error correction, our protocol achieves state-of-the-art performance: starting with pairs of 10% initial infidelity, we require only seven noisy inputs per output pair to distill a single Bell pair with infidelity $\bar{𝜖}$ =10 −12 , substantially outperforming existing schemes. We demonstrate the utility of our protocols for quantum repeater networks.
Despite the recent development of several scalable, robust, and resilient control approaches with superior convergence properties considering an increasing penetration of distributed energy resources (DERs), cognitive oversights often simplify several aspects of the cyber–physical power system in the controller development. Here, following the identification of the limitations of classical controller definitions, we justify alternative definitions of voltage control approaches classifiers considering three inter-disciplinary domains: (i) power system, (ii) optimization and decision-making, and (iii) networking and cyber-security, to develop a taxonomy for helping in real-world comparative performance analysis and deployability of these controllers. We observe that classical and introduced domain-based definitions together can better classify the control algorithms.
Proper characterization of quantum correlations in multimode optical quantum states is critical for applications in quantum information science. However, standard entanglement measurements can lead to incomplete state reconstruction and characterization. Here, we implement a resonator-based detection system that reveals entanglement between sideband modes of twin beams, achieving full tomography and retrieving often ignored quantum correlations. Unlike standard spectral measurements such as homodyne detection, resonator detection can independently address the sidebands of each beam, thereby accessing these hidden correlations. Additionally, we show how phase shifts between the carrier and the sideband modes of the involved fields redistribute information and modify the observation of entanglement for different witnesses. The ability of the resonant detection to independently address sideband modes of entangled states can contribute to enhancing the capacity for secure communication and quantum networking protocols.
“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.
The software implements the methodology of cybersecurity training architecture and is leveraged to build a turn-key based simulated cyberattack game in which the player assumes the facility manager's role and must defend the OT network from adaptive cyberattacks by directly configuring the physical network environment and implementing security policies.
Automated fault management is at the forefront of next-generation optical communication networks. The increase in complexity of modern networks has triggered the need for programmable and software-driven architectures to support the operation of agile and self-managed systems. In these scenarios, the European Telecommunications Standards Institute zero-touch network and service management approach is imperative. The need for machine learning algorithms to process the large volume of telemetry data brings safety concerns as distributed cloud-computing solutions become the preferred approach for deploying reliable communication network automation. This paper’s contribution is twofold. First, we propose a simple yet effective method to guarantee the confidentiality of the telemetry data based on feature scrambling. The method allows the operation of third-party computational services without direct access to the full content of the collected data. Additionally, the effectiveness of four unsupervised machine learning algorithms for soft-failure detection is evaluated when applied to the scrambled telemetry data. The methods are based on factor analysis, principal component analysis, nonlinear principal component analysis, and singular value decomposition. Most dimensionality reduction algorithms have the common property that they can maintain similar levels of fault classification performance while hiding the data structure from unauthorized access. Evaluations of the proposed algorithms demonstrate this capability.
Although ubiquitous in modern vehicles, Controller Area Networks (CANs) lack basic security properties and are easily exploitable. A rapidly growing field of CAN security research has emerged that seeks to detect intrusions or anomalies on CANs. Producing vehicular CAN data with a variety of intrusions is a difficult task for most researchers as it requires expensive assets and deep expertise. To illuminate this task, we introduce the first comprehensive guide to the existing open CAN intrusion detection system (IDS) datasets. We categorize attacks on CANs including fabrication (adding frames, e.g., flooding or targeting and ID), suspension (removing an ID’s frames), and masquerade attacks (spoofed frames sent in lieu of suspended ones). We provide a quality analysis of each dataset; an enumeration of each datasets’ attacks, benefits, and drawbacks; categorization as real vs. simulated CAN data and real vs. simulated attacks; whether the data is raw CAN data or signal-translated; number of vehicles/CANs; quantity in terms of time; and finally a suggested use case of each dataset. State-of-the-art public CAN IDS datasets are limited to real fabrication (simple message injection) attacks and simulated attacks often in synthetic data, lacking fidelity. In general, the physical effects of attacks on the vehicle are not verified in the available datasets. Only one dataset provides signal-translated data but is missing a corresponding “raw” binary version. This issue pigeon-holes CAN IDS research into testing on limited and often inappropriate data (usually with attacks that are too easily detectable to truly test the method). The scarcity of appropriate data has stymied comparability and reproducibility of results for researchers. As our primary contribution, we present the Real ORNL Automotive Dynamometer (ROAD) CAN IDS dataset, consisting of over 3.5 hours of one vehicle’s CAN data. ROAD contains ambient data recorded during a diverse set of activities, and attacks of increasing stealth with multiple variants and instances of real (i.e. non-simulated) fuzzing, fabrication, unique advanced attacks, and simulated masquerade attacks. To facilitate a benchmark for CAN IDS methods that require signal-translated inputs, we also provide the signal time series format for many of the CAN captures. Our contributions aim to facilitate appropriate benchmarking and needed comparability in the CAN IDS research field.
The U.S. Department of Energy (DOE) Electric Vehicles at Scale Lab Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. This network will be critical to support tens of millions of light-, medium-, and heavy-duty EVs on American roads by 2030. The EVs@Scale Lab Consortium brings together national laboratories and key stakeholders to conduct infrastructure research and development (R&D) that advances innovations in, and sets unified standards for, high-power and wireless charging. The effort will also develop technologies to integrate vehicle charging with the power grid, and develop cybersecurity measures to protect drivers, vehicles, equipment, and the grid. The first hybrid EVs@Scale Lab Consortium Biannual Stakeholder Meeting was held at NREL on August 17, 2022, to identify research, development, and deployment needs to accelerate technology development for electric vehicles at scale and explore opportunities for collaboration across government, academia, and industry.
Oak Ridge National Laboratory (ORNL) is pleased to provide our response to the NITRD RFI on Digital Twins Research and Development. Digital twins are virtual representations of physical systems, leveraging real-time data to simulate and predict behaviors. ORNL is advancing digital twin technology across various disciplines, including neutron scattering, networking, science ecosystems, supercomputing, secure facilities, mobility technologies, materials design and discovery, power systems, fusion reactors, biological sciences, and earth observation. These efforts aim to enhance scientific research, operational efficiency, and decision-making processes. ORNL facilities, such as the High Flux Isotope Reactor (HFIR), Grid-C, Spallation Neutron Source (SNS), and Oak Ridge Leadership Computing Facility (OLCF), provide the infrastructure to develop and demonstrate these digital twin technologies. In this document, we lay out key challenges, research gaps, and future opportunities based on our experience with digital twins that aim to serve as useful contributions towards a National Digital Twins R&D Strategic Plan. In the remaining document, we address nine of the thirteen topic areas specified in the RFI.
Electric power systems provide the backbone of modern industrial societies. Enabling scalable grid analytics is the keystone to successfully operating large transmission and distribution systems. However, today's power systems are suffering from ever-increasing computational burdens in sustaining the expanding communities and deep integration of renewable energy resources, as well as managing huge volumes of data accordingly. These unprecedented challenges call for transformative analytics to support the resilient operations of power systems. Recently, the explosive growth of quantum computing techniques has ignited new hopes of revolutionizing power system computations. Quantum computing harnesses quantum mechanisms to solve traditionally intractable computational problems, which may lead to ultra-scalable and efficient power grid analytics. This paper reviews the newly emerging application of quantum computing techniques in power systems. We present a comprehensive overview of existing quantum-engineered power analytics from different operation perspectives, including static analysis, transient analysis, stochastic analysis, optimization, stability, and control. We thoroughly discuss the related quantum algorithms, their benefits and limitations, hardware implementations, and recommended practices. We also review the quantum networking techniques to ensure secure communication of power systems in the quantum era. Finally, we discuss challenges and future research directions. This paper will hopefully stimulate increasing attention to the development of quantum-engineered smart grids.