Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Internet of things”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because it can aid in both cybersecurity analysis and the evaluation of other cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

cyber-physical systems↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because they can aid in both cybersecurity analysis and the evaluation of cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

alfalfa↗

Maximum-impact Adversary Design for Network-based Control System: A Case Study on Grid-interactive Efficient Buildings

The Internet of Things (IoT) technology has dramatically improved the efficiency of today's building operation and management. By connecting controllable devices into a communication network, control signals can be easily passed to the devices, and operating status can be acquired from measurable ends with minimal effort. However, this all-connected configuration could also expose the network-based control system (NBCS) to malicious actions, such as cyberattacks. One of the common NBCSs is the building automation system. With the promotion of grid-interactive efficient buildings (GEBs), there has been increasing attention on securing the buildings from the network perspective. This research proposes a maximum-impact adversary design framework so that the adversary can provide the most adversarial impact on the controlled system while remaining stealthy. The proposed framework is numerically demonstrated on a network-based building energy and control system. The building energy system is built in a Modelica-based simulation environment and controlled by the state-of-the-art ASHRAE Guideline 36 control sequences. The control commands at the supervisory level, generated from the Guideline 36 controller, are assumed to be sent to local devices through communication networks using the BACnet protocol. Simulation results show that the proposed maximum-impact adversary on such a system can stealthily affect the building system's performance to its maximum extent. It is anticipated that results can be used by researchers and practitioners in the building automation industry to design efficient and robust cyber-attack detection algorithms, especially for stealthy attacks.

Chu, Mengyuan↗

Modbus RTU for Embedded Cyber Secure Inverter Controller

The Modbus communication protocol is a widely adopted communication standard in industrial control systems. This communication protocol is known for being reliable and straightforward to implement while being versatile in terms of its operating parameters while supporting multiple formats over various hardware infrastructures and architectures. Many intelligent devices such as Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), Internet-of-Things (IoT), and various Operational Technologies (OT) utilize Modbus for their communication systems. These types of systems must communicate with each other through a standardized and central communication process. To support the integration of these modular systems, a Field-Programmable Gate Array (FPGA) can act as an embedded central routing fabric for this communication to take place. Embedded systems are versatile enough to interface with various devices and systems to accomplish various goals. Additionally, embedded systems require relatively small physical designs to minimize the required resources to facilitate the intended application by providing low-level system access. This minimization of system resources goes hand in hand with reducing the financial cost of a proposed solution or system. As remotely collaborating researchers often use FPGAs to prototype designs that are required to have a method for data transmission among systems, it is imperative to provide a baseline standard for communications among devices and systems. A typical method of implementing the Modbus RTU communication protocol in an embedded environment is using integrated logic architectures within the FPGA called “Intellectual Property (IP) cores.” IP cores can be designed using integrated logic or circuit designs to function as an embedded processor. These IP cores can then perform the required computational actions to support the Modbus RTU communication protocol by utilizing high-level programming languages such as the C programming language. The hardware description language of Very High-Speed Integrated Circuit Hardware Description Language (VHDL) allows for the control of real hardware at the logic gate and signal level. These logic gates and signals can be designed and controlled to perform desired actions based on the system design. Programming an FPGA using VHDL allows an individual to access the lowest abstraction level of the system during FPGA development. This level of abstraction is referred to as the register-transfer level (RTL), which gives access to manipulating values and variables at the register level. This register-level manipulation provides precision over creating the logical circuit within the FPGA, thus minimizing the required code to perform desired operations. The Modbus RTU communication protocol can be implemented within an FPGA using VHDL programming to establish a standardized and embedded serial communication pathway. This implementation provides a standardized communication protocol to streamline research efforts among researchers, thus increasing the efficiency of research efforts. Additionally, this Modbus RTU implementation requires fewer resources when compared to typical communication protocol implementations that utilize an IP core, reducing the hardware requirement for effective research efforts.

communication↗

Zapiary: Creating Visibility in IOT Networks

Zigbee and Z-Wave are the main networking protocols used by low-power Internet of Things (IOT) devices. These protocols use low frequencies. Mesh architecture, and unique address formats that make them not compatible with traditional network traffic tools like IX-Discovery Tools. Zapiary is a software that takes CSV files with Zigbee and Z-Wave traffic and generates Structured Threat Information eXpression (STIX) JSON bundles illustrating the communication within IOT networks. The bundles can then be viewed within Structured Threat Intelligence Graph (STIG) or used with AI/ML models to provide deeper visibility into nodes that make up the network and the ability to trend the mesh network over time.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Developing Smart Building Technology Modules to Enhance Workforce Preparedness: A Case for AI-Driven Academic and Professional Education

Smart building technologies are resources that improve building energy efficiency and resilience, reduce carbon emissions, and provide load flexibility to the grid. However, in both academic curricula and building professionals’ continuing education, there is a lack of systematic instruction on methods to integrate multiple energy systems including distributed energy resources (DER), smart building technologies, AI (Artificial Intelligence) tools and key concepts, components, and controls, including “Internet of Things” (IoT) devices. In today’s dynamic workforce, this major gap in smart building technology education prevents stakeholders from being able to attract talent with an understanding and preparation to adopt smart building technologies in building design and operations. A federally funded project included a partnership between Slipstream and Texas A&M University (TAMU) to develop a semester-long smart building curriculum for engineering college students with the ability to adapt the contents for workforce development of professionals in building services. The final product consists of 16 training videos adapted for building professionals and the public. The educational content and training materials cover the benefits of building energy systems, the latest sensor technologies and IoT devices, all with a focus on smart building technologies. The key drivers are on topics related to smart building controls (i.e., energy management information systems), smart building control platforms, cybersecurity, grid-interactive-efficient buildings (GEBs), smart building control methods, and occupant-centric control. Although not explicitly included the technologies nod to the need for AI driven technologies to prepare engineers and industry professionals to be future ready. This paper describes the project approach, provides outlines of the training materials, and identifies lessons learned in creating the content for this course. The authors suggest ways to scale the instruction of smart building concepts to empower the workforce to accelerate the adoption of smart building technologies and AI-based teaching and learning in higher education and building sector.

99 GENERAL AND MISCELLANEOUS↗

Engineering Out Industry 4.0 Cyber Risk Presentation for EnCyCriS

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

99 GENERAL AND MISCELLANEOUS↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

‪A Novel Methodology for Longitudinal Studies of Home Thermal Comfort Perception and Behavior

Human-building interactions significantly influence building energy consumption and affect peak energy demand. For example, heating and cooling contribute 46% of daily peak residential energy demand. Grid-interactive efficient buildings (GEBs) can potentially increase energy-demand flexibility and accelerate the adoption of renewables. However, traditional demand response (DR) programs focused on shedding peak loads disregard the human-building interactions leading to occupant thermal frustration. Specifically, they do not model occupants’ ability to override thermostat controls, nor how indoor environmental conditions and sociocultural factors affect the timing and magnitude of overrides. Studies have found 20% of occupants override thermostat setpoints during DR events longer than 6 hours yet lack detail about the motivation that might guide more successful efforts. Balancing energy-demand flexibility with occupant thermal comfort requires understanding dynamic occupant behavior, the underlying psychophysiological drivers, in the context of homes. This paper presents methods for scalable longitudinal studies of residential occupant behavior dynamics to inform the development of psychophysiological occupant-centric building models. Smart sensors were installed to measure local environmental conditions in 20 homes in two regions of the United States. Just-in-time ecological momentary assessments (EMAs) provided qualitative data on occupant thermal comfort and local environmental conditions not captured in Internet-of-Things (IoT) based studies or existing datasets. Participant interviews provided insight into environmental attitudes, mental models, and the role of economics in comfort and behavior, which in turn may affect thermostat interactions. Based on these data, interventions in the next phase of the study will collect data and monitor occupant behavior during simulated DR events.

Kane, Michael↗

Fusing Edge Computing with Transport Security by Leveraging the Controller Area Network Transport Security Tracking and Reporting (C-STAR) Unit

Rapid advances in embedded system complexity and capability provides exciting opportunities for transportation security deployment. Manufacturers and developers of these embedded systems continue to provide lower cost and more powerful solutions that can be leveraged by researchers and engineers. Furthermore, deploying these devices at the “edge” of the Internet-of-Things (IoT) infrastructure provides opportunities for highly capable applications in transport security. In an edge computation architecture, the device is co-located at the source of the data in the larger IoT structure – this provides computational capability at the location directly where the data is collected. For shipment transport security, this provides a direct compute node for digestion of data and mitigation actions in real-time. In our application, the vehicle provides a significant amount of this data that can be processed in real-time via the Controller Area Network Transport Security Tracking and Reporting (C-STAR) edge device. Utilization of a computational node located on the vehicle, such as the C-STAR, capitalizes on previously discussed opportunities of edge architectures. In this paper, we will discuss this security solution’s usability, current deployments, and scalability to further applications in transport security. First, we will cover the supported vehicle platforms that can leverage the C-STAR technology. This will be particularly relevant to medium- and heavy-duty vehicles transporting high-risk shipments. Second, we will speak to current deployments of the C-STAR that are ongoing. Finally, we will discuss additional areas for expansion such as maturing the onboard algorithms through continuing collaborations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

System Engineers and Decisions: It?s All about Knowledge

In order to guarantee that a system meets adequate levels of reliability and availability, system performances are continuously monitored and analyzed thanks to the technological advancements driving the Industry 4.0 revolution. An Industry 4.0 approach is typically based on advanced statistical, big data mining, machine learning, and internet-of-things methods designed to detect anomalies in the behavior of system, detect the most likely failure modes, and provide indications to system engineers on when maintenance activities should be performed before system performance are deemed unacceptable (which can be generated by diagnostic and prognostic methods). However, these analyses, which are designed to automatize and increase the efficacy of the system maintenance program, require large amount of data which can come in various forms: numeric, textual, images, sounds etc. Such data constitutes the historic knowledge benchmark to track system performances and support system engineer decisions. Here we claim that data is not sufficient to support this kind of analyses when applied to systems characterized by complex architectures and behaviors. Robust system engineer decisions require the ability to understand the system operational context that lies behind the observed data elements. In this respect, system models are in fact necessary to “put data in context” and capture relationships between data elements. Industry 4.0 methods require in fact contextual knowledge as a basis upon which hypotheses can be generated and assumptions tested. In our view, for complex systems, model-based system engineering (MBSE) models can afford this contextual knowledge, as they are typically used to describe systems architecture and dynamic behaviors. System knowledge is here intended as the blending of collected data and system architecture which takes the form of a “knowledge graph”. A knowledge graph is a database which consists of a large set of nodes (in our case an entity can be either a data or an MBSE element) which are linked to each other. The types of nodes and links follow a pre-defined topology, sometimes also refers as an ontology, that is designed to fit the actual decisions that needs to be performed. We show here how a knowledge graph can be defined to support system engineer maintenance decisions and how the same graph can be built based on system MBSE models and pre-processed data from numeric (through anomaly detections and diagnostic methods) and textual elements (through technical language processing TLP).

97 - MATHEMATICS AND COMPUTING↗

Detecting Process Equipment Failures Using Acoustic Data and Machine Learning

Nuclear power plant (NPP) process equipment such as fans, motors, valves, and pumps generate frequent or continuous noise, and deviations from the normal operational sounds made by this equipment can indicate potential issues. These deviations can be identified via automated acoustic anomaly detection, which involves using acoustic sensors (i.e., microphones) alongside detection algorithms to continuously monitor for changes in acoustic signatures. This task is made challenging by the substantial background noise that exists, such as operators opening and closing doors, manipulating valves, and conversing—in addition to typical plant noises. In collaboration with a nuclear power utility partner, this effort assessed the efficacy of acoustic anomaly detection when using a specific acoustic sensor that compresses data into a fixed set of features that are transferable over a standard Internet of Things communication protocol, thereby improving usability but potentially degrading detection performance. Two methods of performing automated acoustic anomaly detection were evaluated: one-class support vector machine (OC-SVM) and isolation forest (iForest). To enable the use of high-quality acoustic data encompassing both normal and anomalous conditions, the study utilized the publicly available Malfunctioning Industrial Machine Investigation and Inspection dataset, which includes real measured acoustic sensor data for a range of equipment types, model numbers, and signal-to-noise ratios (SNRs), along with a benchmark set of detection results. Using this dataset, the methods were tested and then compared against the benchmark results. The results indicated that although the specific acoustic sensor did not enable as rich a feature set extraction, the proposed methods with the limited feature set performed just as well. This provides solid justification for both the methods and the use of the proposed acoustic sensor.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗

Cyber-Physical System Implementation for Manufacturing With Analytics in the Cloud Layer

Effective and efficient modern manufacturing operations require the acceptance and incorporation of the fourth industrial revolution, also known as Industry 4.0. Traditional shop floors are evolving their production into smart factories. To continue this trend, a specific architecture for the cyber-physical system is required, as well as a systematic approach to automate the application of algorithms and transform the acquired data into useful information. This work makes use of an approach that distinguishes three layers that are part of the existing Industry 4.0 paradigm: edge, fog, and cloud. Each of the layers performs computational operations, transforming the data produced in the smart factory into useful information. Trained or untrained methods for data analytics can be incorporated into the architecture. A case study is presented in which a real-time statistical control process algorithm based on control charts was implemented. The algorithm automatically detects changes in the material being processed in a computerized numerical control (CNC) machine. The algorithm implemented in the proposed architecture yielded short response times. The performance was effective since it automatically adapted to the machining of aluminum and then detected when the material was switched to steel. The data were backed up in a database that would allow traceability to the line of g-code that performed the machining.

97 MATHEMATICS AND COMPUTING↗

MaDEVIoT: Cyberattacks on EV Charging Can Disrupt Power Grid Operation

Extensive roll-out of electric vehicles (EVs) requires large-scale deployment of high-power EV Charging Stations (EVCSs). EVCSs are connected to the internet using Internetof- Things (IoT) such as smartphones, to improve the charging experience of users and increase their profitability. This paper studies the feasibility of demand-side cyberattacks launched on power grids via such internet-connected highpower EVCSs. The attack mechanism distorts power grid frequency and voltage, and has the potential to trigger systemwide outages. The case study, based on the power grid and EV deployment plans in Manhattan, New York, illustrates potential impacts of such attacks. The results show that such attacks will become feasible in Manhattan, New York in 2030, as EV adoption increases. Furthermore, the attacks in 2030 are feasible even compromising a single company’s EVCS server in Manhattan, New York. The attacks can cause line overloads and trip over-frequency protection relays, causing system-side blackout in the power grid in Manhattan, New York. The paper informs planning authorities and power grid operators involved with the roll-out of EV charging infrastructure about potential cyberthreats to power grids via manipulating internet-connected high-power EVCSs.

Acharya, Samrat S.↗

A Dive into Underwater Solar Cells

Our oceans are vast, mostly unexplored and difficult to monitor. Large-scale implementation of a fully autonomous 'Internet of Underwater Things' would transform how we collect and share data from this domain; however, deployment is prohibited by the lack of persistent power sources. In principle, underwater solar-energy generation can complement the use of batteries and provide a solution, although dedicated research is needed since traditional silicon solar cells do not perform well underwater due to water's strong absorption of near-infrared light. In this Perspective we present examples of solar-powered underwater applications and discuss which types of solar-harvesting materials could be appropriate, including GaInP variants, CdTe, organic semiconductors, and perovskite semiconductors. We also discuss challenges that need to be addressed, such as the development of effective antifouling coatings and new certification standards given that underwater conditions are starkly different from those in terrestrial environments.

antifouling coatings↗

Precursor Analysis Report: Conti Ransomware Attack on the Health Service Executive of Ireland 2021

The Conti Ransomware Attack on the Health Service Executive (HSE) of Ireland 2021 Precursor Analysis Report leverages publicly available information about the attack and catalogs anomalous observables for each technique employed by the adversary. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The HSE provides public healthcare corporate services and operational services throughout Ireland, with critical functions including the acute national ambulance service, acute hospital service, and community healthcare service. On 14 May 2021, Conti ransomware encrypted 80 percent of the HSE’s Information Technology (IT) infrastructure across corporate, hospital, community, and electronic health record services. Conti is a ransomware-as-a-service operation that encrypts local files, uses double extortion against victims, and is facilitated by many intrusion tools. The attack forced the HSE to shut down its entire IT infrastructure to contain the ransomware, forcing employees to revert to pen and paper recordkeeping and leading to the cancellation of many appointments and procedures. The adversary also exfiltrated 700 GB of data, compromising the confidentiality of patients’ protected health information. Had the adversary targeted the COVID-19 cloud systems or operational technology assets, such as Internet of Medical Things medical devices or smart building management systems, the impact of the attack would almost certainly have been far more severe. Researchers and analysts identified 21 unique techniques (used in a sequence of 23 steps) likely utilized during the attack with a total of 1,185 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-one of the identified techniques used during the attack on the HSE were precursors to the triggering event. Analysis identified 1,086 observables associated with these precursor techniques, 850 of which were assessed to have an increased likelihood of being perceived in the 57 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗