Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state,1 and to rapidly recover operational capabilities for essential functions after a successful attack.2 The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.”3 As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Security of DERs and Grid Edge Technologies [Slides]

Distributed energy resources (DERs) offer significant value for incorporating diverse generation technologies and improving reliability. They also present a new set of cybersecurity challenges. The move of generation to the grid edge can also mean more distributed control systems and expanded communication networks, resulting in an increase in attack surface. This presentation will discuss definitions and essential terms related to DERs; developments and deployment trends for DERs; recent cyber attacks on operational technology and industrial systems; cyber risk arising from distributed grid resources; and ways in which standards may help mitigate some of these risks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Improved microgrid resiliency through distributionally robust optimization under a policy-mode framework

Critical energy infrastructure are constantly under stress due to the ever increasing disruptions caused by wildfires, hurricanes, other weather related extreme events and cyber-attacks. Hence it becomes important to make critical infrastructure resilient to threats from such cyber-physical events. However, such events are hard to predict and numerous in nature and type and it becomes infeasible to make a system resilient to every possible such cyber-physical event. Such an approach can make the system operation overly conservative and impractical to operate. Furthermore, distributions of such events are hard to predict and historical data available on such events can be very sparse, making the problem even harder to solve. To deal with these issues, in this paper we present a policy-mode framework that enumerates and predicts the probability of various cyber-physical events and then a distributionally robust optimization (DRO) formulation that is robust to the sparsity of the available historical data. The proposed algorithm is illustrated on an islanded microgrid example: a modified IEEE 123-node feeder with distributed energy resources (DERs) and energy storage. Simulations are carried to validate the resiliency metrics under the sampled disruption events.

Nazir, Mohammad Nawaf↗

Leveraging High-Fidelity Datasets for Machine Learning-based Anomaly Detection in Smart Grids

Data-driven intrusion detection systems are increasingly becoming essential for protecting critical cyber-physical infrastructure, such as the power grid, against the growing number of sophisticated cyber-attacks. The development of such tools is reliant on the availability of high-fidelity cyber-physical datasets that cover a diverse variety of potential cyber events. In this work, a high-fidelity smart grid platform is utilized to develop an extensive dataset, which is used to train and test a machine learning-based intrusion detection system. The evaluation of the developed IDS shows robust performance even when tested with statistically diverse test data not used in training.

Hyder, Burhan↗

Canada-US Blended Cyber-Physical Security Exercise (Final Report)

The Canada-US Blended Cyber-Physical Exercise was a successful, first of its kind, multiorganization and multi-laboratory exercise that culminated years of complex system development and planning. The project aimed to answer three driving research questions, (1) How do cyberattacks support malicious acts leading to theft or sabotage [at a nuclear site]? (2) What are aspects of an effective combined cyber-physical response? (3) How to evaluate effectiveness of that response? Which derived the following primary objectives, 1. The May 2023 Cyber-Physical Exercise shall present a cyber-attack scenario that supports malicious acts leading to theft or sabotage. 2. The May 2023 Cyber-Physical Exercise shall define aspects of an effective combined cyber-physical response. 3. Analysis of the May 2023 Cyber-Physical Exercise shall evaluate the effectiveness of the incident response against pre-established exercise evaluation criteria. 4. Analysis of the May 2023 Cyber-Physical Exercise shall assess the effectiveness of the evaluation criteria itself. 5. Exercises shall be performed in a real-life environment. The team believes these objectives were met, and the evidence will be presented in this report. Due to the novelty of the exercise, there were several lessons learned that will be presented in this report.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Precursor Analysis Report: Doppelpaymer Ransomware Attack on Petroleos Mexicanos (PEMEX) 2019

The DoppelPaymer Ransomware Attack on Petroleos Mexicanos (PEMEX) 2019 Precursor Analysis Report leverages publicly available information about the PEMEX cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The 2019 DoppelPaymer ransomware attack on PEMEX, Mexico’s nationalized petroleum corporation, highlights a unique threat that ransomware and cybercriminal extortion poses to Operational Technology (OT) environments in critical infrastructure. The incident began with an employee downloading commodity malware that allowed adversaries to gain initial access to PEMEX’s enterprise environment. After conducting privilege escalation, tool ingress, and data exfiltration, the adversaries deployed DoppelPaymer ransomware throughout the PEMEX enterprise environment, resulting in the company having to take dozens of systems offline for at least several days. Although PEMEX stated that their operations were not affected, the data exfiltrated from PEMEX was made available for download on DoppelPaymer’s leak site, as well as on other illicit criminal forums. This stolen data included not only company information, but also sensitive OT-specific configuration data. This incident showcases how cybercriminal exfiltration and posting of sensitive OT architecture documentation can pose security concerns for the targeted organization for years due to the long lifespan of OT assets and architectures. Researchers and analysts identified 18 unique techniques utilized during the attack with a total of 190 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Fifteen of the identified techniques used during the DoppelPaymer ransomware attack were precursors to the triggering event. Analysis identified 163 observables associated with these precursor techniques, 34 of which were assessed to have an increased likelihood of being perceived in the 60 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems are becoming more widely deployed throughout the country, and as their presence continues to grow, it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity, and to the company that owns the facility. The two main mechanisms malicious actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when facility managers conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks applicable to a wide variety of hydrogen storage systems by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems may become more widely deployed throughout the country, and so it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity of the facility, and the company that owns the facility. The two main ways bad actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when companies conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks associated with a generic hydrogen storage system by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Net Load Redistribution Attacks on Nodal Voltage Magnitude Estimation in AC Distribution Networks

A high penetration level of smart devices and communication networks increases the threat of cyber-attacks in the distribution system. In this paper, we model a hidden, coordinated, net load redistribution attack (NLRA) in an AC distribution system. Based on local information of an attack region, the attacker’s goal is to create violations in nodal voltage magnitude estimation. Acting as a system operator equipped with global AC state estimation and bad data detection, we validate the stealthiness of the hidden NLRA in multiple attack cases. Simulation results on a modified PG&E 69-node distribution system show the validity of the proposed NLRA. The influence of NLRA on the distribution system is assessed and the impact of attack regions, attack timing, and system observability is also revealed.

Zhang, Hang↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

GraphCH: A Deep Framework for Assessing Cyber-Human Aspects in Insider Threat Detection

Insider threat is one of the most damaging cyber attacks that could cause the loss of intellectual property and enterprise data security breaches. Action sequence data such as host logs are used to investigate such threats and develop anomaly-based AI detectors. However, insider threat actions are similar to legitimate user activities, causing AI detectors to fail and suffer from high false alarm rates. Therefore, user cyber activity logs are inadequate to fully unfold insider threats. In this study, we adopt human psychological principles of risk-taking and impulsiveness along with host data to assess the influence and usefulness of human behavioral aspects in insider threat detection. Here, we hypothesize that individuals' impulsive and risk-taking behavior correlates with cyberspace activities. To validate our hypothesis, we conducted an IRB-approved study recruiting 35 participants who work in a large U.S. university and collected their cyber and psychological data for 90 days. Host and human-behavioral data analysis and mapping indicate that impulsive and risk-taking users trigger more system errors causing (un)intentional insider threats and are susceptible to attackers' social engineering and cognitive hacking. Utilizing cyber-human aspects, we introduce a Cyber-Human Graph Neural Network (GNN) based framework GraphCH to identify abnormal user behaviors and detect insider threats.

97 MATHEMATICS AND COMPUTING↗

Detecting False Data Injection Attacks in Smart Grids: A Semi-Supervised Deep Learning Approach

The dependence on advanced information and communication technology increases the vulnerability in smart grids under cyber-attacks. Recent research on unobservable false data injection attacks (FDIAs) reveals the high risk of secure system operation, since these attacks can bypass current bad data detection mechanisms. To mitigate this risk, this paper proposes a data-driven learning-based algorithm for detecting unobservable FDIAs in distribution systems. We use autoencoders for efficient dimension reduction and feature extraction of measurement datasets. Further, we integrate the autoencoders into an advanced generative adversarial network (GAN) framework, which successfully detects anomalies under FDIAs by capturing the unconformity between abnormal and secure measurements. Also, considering that the datasets collected from practical power systems are partially labeled due to expensive labeling costs and missing labels, the proposed method only requires a few labeled measurement data in addition to unlabeled data for training. Numerical simulations in three-phase unbalanced IEEE 13-bus and 123-bus distribution systems validate the detection accuracy and efficiency of this method.

97 MATHEMATICS AND COMPUTING↗

Mitigate: An Adaptive Network Data Anonymization Tool Using Condensation-Based Differential Privacy

Modern network devices collect a large amount of data that can be analyzed to identify bottlenecks, anomalies, cyber-attacks, etc. Therefore, there is often a need to analyze such collections of network data quite often by an external expert or by the research community. However, these collections of data contain sensitive, proprietary information. In order for the network data to be shared, it must first be anonymized. The overall objective of this project is to develop an innovative privacy management tool to anonymize network data and achieve sufficient privacy, acceptable data utility, and efficient data analysis at the same time. No existing anonymization methods can achieve all of these at the same time. The core of this technology is a differential private clustering algorithm that provides strong privacy protection, preserves data properties important for subsequent analysis, and allows the party receiving the anonymized data to conduct analysis directly on anonymized data without the need of decryption or any extra processing. The research carried out was to design, implement and verify a solution to this problem by completing the following tasks: 1) developing the core technology; 2) developing a context based method that automatically recommends fields that must be anonymized; 3) conducted experiments showing superior results using our approach compared to existing tools, and 4) developed an intuitive but basic user interface. The research that was conducted generated novel algorithmic techniques that utilize state-of-the-art methods such as condensation, differential privacy preservation, clustering, automated tuning based on contextual awareness, and recommendation techniques to specify columns to users for anonymization leading to optimal privacy that allows research analysis on the dataset. Experiments were conducted to evaluate the efficacy of these novel algorithmic techniques by performing analysis on original non-anonymized datasets, then conducting analysis on the same yet anonymized datasets and comparing the results of the analyses. Overall, the anonymized analysis results were within 1% of the original results, verifying that the generated technology not only guarantees a high level of privacy but also enables research analysis as if it were conducted on the original dataset. Potential applications of this technology include anonymization of any type of structured network datasets that contain sensitive identifiers, such as IP addresses, that can be used in multiple applications. For example, to create an AI or machine learning model for cyber security, e.g., to detect attacks, or for performance analysis, e.g., identify bottlenecks or predict performance. In addition, a market analysis that was conducted for potential applications of this technology identified a broader range of applications of our anonymization technology beyond the network sector that includes healthcare, banking, insurance, securities, finance (FISB), data brokering, cloud services, ad sales, and government.

97 MATHEMATICS AND COMPUTING↗

Micro Baselines for Operational Technology Environments

Critical infrastructure stakeholders need to baseline their networks to understand expected communications. Top-down approaches to baselining rely on observables that are generally available but lack properties upon which traditional statistical tools depend. We propose to construct micro-baselines: signatures within operational networks based on observables associated with specific events. Such observables are informed by precursor analysis reports of historical cyber attacks on operational environments developed by Cybersecurity for Operational Technology Environments (CyOTE). Baseline measurements depend upon context beyond the cyber domain. An energy plant's baseline running in the summer may statistically differ from a similar facility in a colder region. Domain knowledge must be integrated to apply general micro-baselining algorithms to a facility-specific context. Therefore, we propose to explore the feasibility of transferring micro baselining algorithms across different facilities. Facilities that implement the same processes in different geographic locations will be compared relative to observable measurements used in micro-baselining for comparable events. One evaluation approach would condition or augment dynamic observables measured within a facility network testbed with additional observables derived from geographic context or infrastructure dependencies such as those provided by the All-Hazards Analysis tool.

97 MATHEMATICS AND COMPUTING↗

On the Limits of EM Based Detection of Control Logic Injection Attacks In Noisy Environments

The difficulty in applying traditional security mechanisms in Industrial Control System (ICS) environments makes a large portion of these mission-critical assets vulnerable to cyber attacks. Therefore, there is a dire need for the development of novel security mechanisms specifically designed to protect such critical systems. Recently a lot of attention has been given to mechanisms that exploit the EM emanations of devices for defense purposes. Such practices may lead to the development of robust external and non-intrusive anomaly detection systems. Nevertheless, the majority of current work in the area neglects to consider the implications of real-life environments, particularly environmental noise. In this work, we explore the limits of EM-based anomaly detection towards identifying injection attacks in control logic software in noisy environments. Our study conducted upon both synthetically generated and real signals identified that indeed environmental noise might significantly degrade the accuracy of the anomaly detection process. Experiments done upon synthetic data indicated that assuming that signals are captured with high sampling rates, even minor code injections can be detected with above-90% accuracy in noisy environments where SNR is up to -2dB. This is true even if naive detection methods are considered. Moreover, experiments done using a real-life testbed attest that even single-instruction injections can be detected with near-perfect accuracy in relatively clean environments. Finally, noise-elimination techniques can drastically improve the reliability of the detection mechanism even in noisy environments.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Case Study of an Integrated Hydrogen Generation Plant

Strategies for securing digital instrumentation and control (I&C) systems within the nuclear industry are provided by multiple standards and guidance documents. However, since selection and use of security controls outlined in these documents are frequently only considered during or after installation, there are often limitations on their use, such as technological constraints related to design or operation. Furthermore, alternative controls intended to provide the same or similar security countermeasure as the primary control may also be infeasible at these stages, leaving the I&C system vulnerable to cyber-attacks. The limitations associated with ‘bolting on’ security controls late in the systems engineering lifecycle can be reduced by integrating Cyber-Informed Engineering (CIE) into the process. This paper evaluates the use of CIE during the high-level design stage of a hydrogen generation project where heat and electricity are provided by a nuclear power plant. Applying CIE to this project highlighted potential cyber vulnerabilities of the initial design, leading to recommendations for process flow and I&C system design modifications to reduce, and at times eliminate, the risk from both deliberate and unintentional cyber incidents.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗