Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Self-Secure Inverters Against Malicious Setpoints

The next generation of grid-interactive inverters brings a communication feature that allows data sharing from utility supervisory controllers and smart devices that are connected to the same network. This feature enhances the control capabilities of grid-interactive inverters to provide services beyond active power injection. However, communication networks entail more vulnerable surfaces to malicious attacks that may result in modifying active and reactive power setpoints and causing weak-grid conditions or abnormal inverter operation. In this paper, steady-state and the dynamic behavior of the inverter for the incoming setpoints are analyzed to detect false data injection attacks and provide device-level security. The steady-state behavior of the inverter in the operating region is determined from the grid parameters such as the grid voltage and the grid impedance. These estimations are accomplished by the proposed self-security technique through a low-frequency signal injection-based approach combined with the recursive least square method. Moreover, a reduced fourth-order inverter model is used as the dynamic reference model, and grid parameters as well as the incoming setpoints are implemented to the reference model to verify whether the dynamic behavior of the inverter is inside the permissible region of operation. The validity and performance of the proposed method are verified experimentally through Allen-Bradley Powerflex 755 three-phase inverter and a 12 kW NHR 9410 regenerative power grid emulator. The results show that the self-secure smart-inverter is able to accept or reject the incoming commands and thus is protected from malicious cyber-physical attacks.

Hossen, Tareq↗

L-Basin Microbial Monitoring Program - Evaluation of 20 Years of Monitoring

The SRNL L-Basin corrosion surveillance and microbial monitoring programs provide early detection and characterization of corrosion attack to the fuel and storage system materials resulting from prolonged exposure to the L-Basin water environment and of changes to and impact of the diverse microbial population, respectively. The early detection of corrosion allows for adjustment of the water quality, engineering management, and fuel storage configurations to mitigate excessive corrosion attack. While microbial influenced corrosion in L-Basin has not been detected, tracking and understanding the effect of microbial populations on the stored fuel and basin water will aid in identifying remedial measures to mitigate any detrimental impact. This report reviews the microbial monitoring activities since initial characterizations in the mid-1990s.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Electrical Fault Detection, Power Quality, Distributed Energy Resource Use Cases, and Cyber Event Applications with the Cyber Grid Guard System Using Distributed Ledger Technology

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation and are associated with distributed energy resources (DERs). The integrity and confidentiality of data from IEDs is crucial, and distributed ledger technology (DLT) could improve the resilience of microgrids by helping to make these data more secure. The most popular applications using blockchain technology for electrical utilities is in the field is based on energy trading. However, the dynamism of the penetration of customer owned DERs and the deployment of sensors with IEDs have led to the identification of new applications using DLT that are focused on other areas, such as monitoring, operation and management of the grid and its assets. In addition, the majority of studies on electrical grid applications with blockchain were validated with software simulations. Although general monitoring of power systems for using DLT could be evaluated in operational electric grids, other DLT research applications such as defense against cyber-attacks and/or electrical fault detection are not likely to be performed in a real infrastructure because of possible risks to the network/equipment security. This report summarizes the application of power system applications using distributed ledger technology (DLT), providing a secure DLT framework for collecting data from IEDs like power meters and protective relays inside and outside of an electrical substation and/or between two different electrical utilities. In this study, the use case scenarios were created and assessed for different power system application by using DLT. The electrical fault detection for faulted phases (1), power quality monitoring of phase voltage magnitudes, frequency levels and load power factor (2), DERs use case monitoring (3), and cyber-event applications (4) were performed in a test bed with a Cyber-Grid Guard (CGG) system using DLT. It had a real-time simulator with power meters and protective relays in-the-loop. The first section of this report presents a literature review of power system applications using blockchain at research level. The second section shows the theory and equations used on this report. The third section shows the description of the test bed, equipment, architecture, and electrical grid diagrams. The fourth section shows the experimental models and use case scenarios that were performed for the electrical fault detection, power quality, DERs use case, and cyber event applications with the CGG system using DLT. The fifth section shows the results collected from the tests based on comparing the time stamped events of the analog signals from the IEDs, DLT computer and real time simulator. The sixth section performed the discussion of the results for the use case scenarios. Finally, section seven presents the conclusions for this report were presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Community detection robustness of graph neural networks

Graph neural networks (GNNs) are increasingly widely used for community detection in attributed networks. They combine structural topology with node attributes through message passing and pooling. However, their robustness or lack thereof with respect to different perturbations and targeted attacks in conjunction with community detection tasks is not well understood. To shed light on latent mechanisms behind GNN sensitivity on community detection tasks, we conduct a systematic computational evaluation of six widely adopted GNN architectures graph convolutional network, graph attention network, graph sample and aggregate (GraphSAGE), differentiable pooling (DiffPool), minimum cut pooling (MinCUT), and deep modularity networks (DMoN). The analysis covers three perturbation categories: node attribute manipulations, edge topology distortions, and adversarial attacks. We use element-centric similarity as the evaluation metric on synthetic benchmarks and real-world citation networks. Our findings indicate that supervised GNNs tend to achieve higher baseline accuracy, while unsupervised methods, particularly DMoN, maintain stronger resilience under targeted and adversarial perturbations. Furthermore, robustness appears to be strongly influenced by community strength, with well-defined communities reducing performance loss. Across all models, node attribute perturbations associated with targeted edge deletions and shifts in attribute distributions tend to cause the largest degradation in community recovery. These findings highlight important trade-offs between accuracy and robustness in GNN-based community detection and offer insights into selecting architectures resilient to noise and adversarial attacks.

Goel, Jaidev [Virginia Polytechnic Inst. and State↗

Safe and Robust Binary Classification and Fault Detection Using Reinforcement Learning

In this paper, we propose a learning-based method utilizing the Soft Actor-Critic (SAC) algorithm to train a binary Support Vector Machine (SVM) classifier. This classifier is designed to identify valid input spaces in high-dimensional, highly constrained systems while minimizing the total runtime of offline simulations. The simulations adapt their runtime based on the likelihood that a given training input will be informative to the classifier. Furthermore, we introduce a method for using the trained SAC model to predict whether a desired system input is likely to violate constraints, along with a technique to adjust the input as necessary. Additionally, we explore the potential of this model to detect faults or adversarial attacks within the system. The effectiveness of our approach is demonstrated through various simulations of challenging classification problems and a constrained quadrotor model.

Netter, Josh [Georgia Institute of Technology, Atl↗

Deception-Based Cyber Attacks on Hierarchical Control Systems using Domain-Aware Koopman Learning

Industrial control systems are subject to cyber attacks that produce physical consequences. These attacks can be both hard to detect and protracted. Here, we focus on deception-based sensor bias attacks made against a hierarchical control system where the attacker attempts to be stealthy. We develop a a data-driven, optimization-based attacker model and use the Koopman operator to represent the system dynamics in a domain-aware and computationally efficient manner. Using this model, we compute several different attacks against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. Finally, we discuss some computational considerations and identify avenues for future research.

koopman operator, Cyber-Physical Security, machine↗

Cyote Research Tool Library

The software is a library of individual proof-of-concept tools to be further developed in research efforts with partner utilities to detect indicators of Cyber Attacks within the Operational Technology Environments.

Wellman, LawrenceR.↗

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using provenance tags and customizable policy

A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path.A corresponding method and computer-readable medium are also disclosed.

Source record↗

Model-Agnostic Algorithm for Real-Time Attack Identification in Power Grid using Koopman Modes

Malicious activities on measurements from sensors like Phasor Measurement Units (PMUs) can mislead the control center operator into taking wrong control actions resulting in disruption of operation, financial losses, and equipment damage. In particular, false data attacks initiated during power systems transients caused due to abrupt changes in load and generation can fool the conventional model-based detection methods relying on thresholds comparison to trigger an anomaly. In this paper, we propose a Koopman mode decomposition (KMD) based algorithm to detect and identify false data attacks in real-time. The Koopman modes (KMs) are capable of capturing the nonlinear modes of oscillation in the transient dynamics of the power networks and reveal the spatial embedding of both natural and anomalous modes of oscillations in the sensor measurements. The Koopman-based spatio-temporal nonlinear modal analysis is used to filter out the false data injected by an attacker. The performance of the algorithm is illustrated on the IEEE 68-bus test system using synthetic attack scenarios generated on GridSTAGE, a recently developed multivariate spatio-temporal data generation framework for simulation of adversarial scenarios in cyber-physical power systems.

Nandanoori, Sai Pushpak↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Faster-than-real-time Simulation with Demonstration for Resilient DER Integration

The US electric grid is facing operational, stability, and security challenges. Transmission system operators need some measure of visibility into distribution system renewable generation. Distribution system generation needs to support transmission system voltage. The grid is experiencing an expansion in measurement systems. How to take full advantage of this expansion and defend against attacks, both cyber and physical, poses additional challenges. The Faster-than-real-time Simulation with demonstration for Resilient DER Integration project set out to do the following: a. Flatten the voltage profile through the feeders and system for cost saving and voltage stabilization needs. b. Increase the amount of intermittent distributed energy resources (IDERs) that could be deployed on a utility feeder and provide 100% or more energy needed for the demands on that feeder, and c. based on an accurate model (Digital Twin) of the utilities system, be able to detect any abnormalities on the utilities distribution system. To manage the voltage and increase IDER penetration (a,b), Graph Trace Analysis is employed in a time-series, optimal power flow to coordinate the time-varying feedback control setpoints of a distribution feeder’s utility control devices. Under the coordinated control are a Load Tap Changing Transformer, a voltage regulator, and five switched capacitor banks. The feeder serves over 2000 customers, the feeder secondaries are modeled, and the feeder has 2.3 MW of PV generation, corresponding to a 17.4% penetration of PV generation. The feeder model has over 12,000 components, where every customer load bus and PV generator are modeled. The accuracy of the power flow solution is compared against historical meter voltage measurements, the improvement in conservation voltage reduction energy savings as a function of the coordinated control desired voltage profile is investigated, and the increase in PV penetration of the coordinated control over the existing control is presented. To achieve improved control performance while observing system operation constraints, bellwether Advanced Metering Infrastructure (AMI) voltage measurements are used to adjust the desired voltage profile used by the optimal power flow analysis. To detect and alleviate or negate attacks or failures on the distribution and transmission utility grids (c) the grid needs to be resilient and self-healing. In this project software was designed to do just that. At the center of the software is an Integrated System Model (ISM) that spans from transmission to secondary distribution. The ISM is employed in real-time abnormality detection, voltage stability forecasting, and multi-mode control. Testing results are presented for: 1—attacks on utility infrastructure; 2—energy savings from optimal control; 3—distribution system control response during a low voltage transmission system event; 4—cyber-attacks on PV inverters, where physical inverters are used in hard-ware-in-the-simulation-loop studies. Contributions of this work include real-time analysis that spans from three-phase transmission through secondary distribution; an approach for detecting abnormalities that employs measurements from three independent measurement systems; and a multi-mode distribution system control that responds to cyber-attacks, physical attacks, equipment failures, and transmission system needs.

Integrated System Model, Graph Trace Analysis, Adv↗