Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Tensor Text-Mining Methods for Malware Identification and Detection, Malware Dynamics Characterization, and Hosts Ranking

Malware is one of the most persistent and costly cyber threats endangering reputation, confidentiality, integrity, and availability for organizations and national security. Consequently, many of the incident detection and prevention systems, and incident responders have begun to utilize machine learning as a helper in the fight against malware and other cyber threats. However, cyber defenders rely on interpretability and generalizability, yet the popular machine learning methods are black-box and often use traditional supervised solutions that do not generalize to novel malware. Therefore, there is a need to improve the existing solutions. At the same time, the majority of the prior research ignored essential evaluation criteria when reporting the results of their methods, which disables the safe reproducibility of the methods in a production environment. Tensor decomposition, on the other hand, enables interpretable unsupervised analysis of the large-scale data for the discovery of hidden patterns. Our findings, performed on real-world and large-scale experiments, show that tensor factorization-based methods yield performance results that surpasses or competes with existing supervised solutions with the added benefit of interpretability and generalizability. With the ability to analyze complex and large-scale data using tensors, we report results that reflect real-world production environments. We propose to develop new game- changing tools for malware identification and characterization that can trace malware evolution, rank the infected or malicious hosts, and streamline the work of incident response teams, malware analysts, and incident detection and prevention systems.

97 MATHEMATICS AND COMPUTING↗

Denial of Service Attack Detection via Differential Analysis of Generalized Entropy Progressions

Denial-of-Service (DoS) attacks are one the most common and consequential cyber attacks in computer networks. While existing research offers a plethora of detection methods, the issue of achieving scalability, a low false positive rate, and high detection accuracy remains open. In this work, we address this problem by developing a differential method based on generalized entropy progression. In this method, named as DoDGE, we continuously fit the line of best fit to the entropy progression of destination addresses and check if the derivative, that is, the slope of this line is less than the negative of the dynamically computed standard deviation of the derivatives. Furthermore, to distinguish from flash events, we leverage the symmetry that when a flash event occurs, the derivative of the entropy progression of source addresses is positive. With this design, we omit the usage of the thresholds and the results with five real-world network traffic datasets confirm that DoDGE outperforms threshold-based DoS attack detection by two orders of magnitude in terms of false positives on average. When compared to ten machine learning (ML) models, DoDGE achieves a balanced accuracy of 99%, while the average balanced accuracy for the ML models is 52%. Moreover, the results show that DoDGE successfully differentiates between a flash event and a DoS attack. Furthermore, since the main computation cost of DoDGE is the entropy computation, which is linear in the volume of the unit-time network flow, uses integer only operations, and works on a small fraction of the total flow, it is lightweight and scalable.

Cybersecurity, wireless communication↗

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation

Advanced persistent threats and cyberattacks can impact wide-area monitoring, protection, and control (WAMPAC) system operation. Many cyber-physical system (CPS) testbeds have been developed for attack-defense experimentation and attack-resiliency tools evaluation for WAMPAC, but they are limited to a simulation-and-emulation based environment. This paper presents a quasi-realistic CPS attack-defense testbed-based framework for WAMPAC applications using the industrial substation and control center platforms such as eTerra integrated with the hardware-in-the-loop CPS smart grid testbed available at Iowa State University. The proposed framework includes various combinations of industry-grade substation and control center platforms, communication topologies, real-time digital simulators, and a novel cyber-physical distributed intrusion-and-anomaly detection system (D-IADS) for WAMPAC applications. The D-IADS includes a master at the control center and geographically distributed sensor devices at each substation. Each D-IADS sensor deployed at a substation or control center network monitors ingress and egress traffic, detect intrusions, and dispatch alerts to the D-IADS master. The D-IADS master centrally monitors and analyze the alerts and controls D-IADS sensors. We considered an EMP60 synthetic CPS grid as a case study to demonstrate the framework and proposed D-IADS for WAMPAC applications against cyberattack vectors such as Man-in-the-Middle DNP3 attack, denial-of-service, and data-integrity attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Simulation and Modeling Concepts for Secure Airspace Operations

With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. This paper examines cyber security vulnerabilities of Urban Air Mobility operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, thus, improving the cyber resiliency of the current and future air traffic management system.

Cybersecurity↗

CANShield: Signal-based Intrusion Detection for Controller Area Networks

Modern vehicles rely on complex cyber-physical systems made up of hundreds of electronic control units (ECUs) connected through controller area network (CAN) buses. However, the CAN bus attack surface is increasing due to advanced features in automobiles, making it prone to injection attacks. The ordinary injection attacks disrupt the typical timing properties of the CAN data stream, and the rule-based intrusion detection systems (IDS) can easily detect them. However, advanced attackers can inject false data to the signal level, maintaining the regular pattern/frequency of the CAN messages. Such attacks can bypass the rule-based IDS or any anomaly-based IDS built on binary payload data. To make the vehicles robust against such intelligent attacks, we propose CANShield, a signal-based intrusion detection framework for the CAN bus that consists of three modules. A data preprocessing module handles the high-dimensional CAN data stream at the signal level and make them suitable for any machine learning model. A data analyzer module consists of multiple deep autoencoder networks, each analyzing the time series data from a different perspective. Finally, an attack detection module uses an ensemble method to make the final decision. Evaluation results on a standard signal-based dataset show the effectiveness of the CANShield in detecting five advanced attacks.

Shahriar, Md Hasan↗

A Review of Cyber-Physical Security for Photovoltaic Systems

In this paper, the challenges and a future vision of the cyber-physical security of photovoltaic (PV) systems are discussed from a firmware, network, PV converter controls, and grid security perspective. The vulnerabilities of PV systems are investigated under a variety of cyber-attacks, ranging from data integrity attacks to software-based attacks. A success rate metric is designed to evaluate the impact and facilitate decision making. Model-based and data-driven methods for threat detection and mitigation are summarized. In addition, the blockchain technology that addresses cyber-attacks in software and cyber networks is described. Simulation and experimental results that show the impact of cyber-attacks at the converter (device) and grid (system) levels are presented. Finally, potential research opportunities are discussed for next-generation, cyber-secure power electronics systems. These opportunities include multi-scale controllability, self-/event-triggering control, artificial intelligence/machine learning, hot patching, and online security. As of today, this study will be one of the few comprehensive studies in this emerging and fast-growing area.

14 SOLAR ENERGY↗

Robust and cybersecure coordinated unintentional island detection for microgrids

Unintentional islanding (UI) of a circuit of distributed energy resources (DERs) may leave area electrical power systems (EPS), external to the DER circuit, energized. Thus, UI detection methods have been developed to detect unintentional islanding and trigger a UI response. However, individual UI detection methods have various deficiencies. Thus, a consensus-based UI detection process is disclosed that builds a consensus from multiple UI detection sources, optionally implementing different UI detection methods. The redundancy in this consensus-based UI detection process provides robust, sensitive, selective, and cybersecure UI detection for the entire DER circuit. For example, the consensus-based UI detection process may eliminate or reduce non-detection zones, avoid false positives, thwart cyber-attacks, and/or the like.

Brissette, Alex↗

Cybersecurity for the Operational Technology Environment (CyOTE)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop CyOTE. This research initiative addresses cybersecurity threats against operational technology (OT) networks by sharing intelligence about adversarial tactics and techniques with the energy sector. CyOTE improves the sector’s ability to detect anomalous behavior that indicates potential malicious cyber activity in OT networks.

99 GENERAL AND MISCELLANEOUS↗

A hardware-in-the-loop (HIL) testbed for cyber-physical energy systems in smart commercial buildings

In recent years, there has been a growing trend toward the development of smart buildings that rely on cyber-physical systems (CPS) to optimize occupant comfort, safety, and energy efficiency. To ensure the reliable and efficient operation of CPS with designed control strategies, it is important to evaluate their performance under various scenarios before deploying them in the real world. This is where a Hardware-in-the-loop (HIL) testbed designed for studying sensor and control-related studies in smart buildings can be highly valuable. With the growing threat of cyber-attacks and physical faults targeting smart buildings, it is essential to ensure the security of building operations. A HIL testbed can emulate cyber-attack and physical fault scenarios, allowing researchers to develop and test threat detection and mitigation algorithms. This enables researchers to identify potential issues and optimize the algorithms in a safe and controlled environment before they are deployed in real-world settings, reducing the risk of failures that can negatively impact occupant comfort, safety, and energy efficiency. Therefore, this paper developed a HIL testbed designed for cyber-physical energy systems (e.g. buildings automation system (BAS)) in smart commercial buildings. The HIL testbed is comprised of a real-time building and Heating, Ventilation, and Air-Conditioning (HVAC) emulator using Modelica-based dynamic models, a set of BAS controllers, and a BAS computer server. The data generation capability of the HIL testbed is demonstrated by tracking normal and faulty operating data in the BAS, as well as monitoring detailed network traffic in the local BAS network. Here, this study further demonstrates the HIL testbed’s capability by conducting case studies on real-time physical fault and cyber-attack experiments using a Department of Energy (DOE) prototype commercial building. It is anticipated that the fully functional HIL testbed will be utilized for a variety of sensor and control-related studies, including but not limited to testing, developing, validating of different HVAC control strategies, fault detection & diagnosis, energy monitoring and analysis, cyber security study, etc.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Does practice make perfect? Lessons learned from full-scale power system incident response exercise

While threats to the energy sector occur daily, few utilities get the opportunity to fully test out their detection and response mechanisms to advanced threats in the real world. With the high demand for reliability, few grid operators would allow execution of simulated cyber-attacks on their live systems. The DOE-funded Liberty Eclipse project offers a unique opportunity for small and large utilities and coops to practice their combined IT/OT responses to a live red team executing attacks against an isolated power system on an island in New York. Both cyber teams and power operations teams must work together to detect and respond to attacks, even restoring the power system against extreme impacts. Lessons learned from these exercises reveal key takeaways for understanding what a real attack against the electric sector will look like, gaps in execution of the best-laid plans when the pressure of a real event is bearing down, and how organizations can better prepare for advanced attacks by optimizing participation in exercises. This presentation will discuss successes and opportunities for improvement both in how utilities can prepare for and respond to events, as well as how full-scale IT/OT exercises can be coordinated.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distributed Intrusion Detection System using Semantic-based Rules for SCADA in Smart Grid

Cyber-physical system (CPS) security for the smart grid enables secure communication for the SCADA and wide-area measurement system data. Power utilities world-wide use various SCADA protocols, namely DNP3, Modbus, and IEC 61850, for the data exchanges across substation field devices, remote terminal units (RTUs), and control center applications. Adversaries may exploit compromised SCADA protocols for the reconnaissance, data exfiltration, vulnerability assessment, and injection of stealthy cyberattacks to affect power system operation. In this paper, we propose an efficient algorithm to generate robust rule sets. We integrate the rule sets into an intrusion detection system (IDS), which continuously monitors the DNP3 data traffic at a substation network and detects intrusions and anomalies in real-time. To enable CPS-aware wide-area situational awareness, we integrated the methodology into an open-source distributed-IDS (D-IDS) framework. The D-IDS facilitates central monitoring of the detected anomalies from the geographically distributed substations and to the control center. The proposed algorithm provides an optimal solution to detect network intrusions and abnormal behavior. Different types of IDS rules based on packet payload, packet flow, and time threshold are generated. Further, IDS testing and evaluation is performed with a set of rules in different sequences. The detection time is measured for different IDS rules, and the results are plotted. All the experiments are conducted at Power Cyber Lab, Iowa State University, for multiple power grid models. After successful testing and evaluation, knowledge and implementation are transferred to field deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Leveraging High-Fidelity Datasets for Machine Learning-based Anomaly Detection in Smart Grids

Data-driven intrusion detection systems are increasingly becoming essential for protecting critical cyber-physical infrastructure, such as the power grid, against the growing number of sophisticated cyber-attacks. The development of such tools is reliant on the availability of high-fidelity cyber-physical datasets that cover a diverse variety of potential cyber events. In this work, a high-fidelity smart grid platform is utilized to develop an extensive dataset, which is used to train and test a machine learning-based intrusion detection system. The evaluation of the developed IDS shows robust performance even when tested with statistically diverse test data not used in training.

Hyder, Burhan↗

Cybersecurity Center for Offshore Wind Energy (Final Project Report)

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models with SCADA infrastructure, and deployed a scaled physical turbine and associated sensors. High-resolution operational and side-channel data streams were collected and used to refine machine-learning (ML)-based attack detection systems and to extend the WindCRAFT framework to multi-turbine threat scenarios. The project demonstrated a realistic, scalable environment for evaluating cyber threats, validated attack detection approaches using enriched datasets, and identified new multi-turbine and inter-turbine communication attack vectors. The resulting testbed, models, and security mechanisms provide a foundation for ongoing R&D and deployment of cyber-resilient offshore wind energy systems.

17 WIND ENERGY↗

Sequence-Based Anomaly Detection in Critical Infrastructure Networks

United States critical infrastructure faces new cyber threats from adversarial nation-state actors in the form of malware-free attacks. Traditional cybersecurity techniques use rules-based methods to identify indicators of compromise on networks, often missing these sophisticated attacks. Our approach leverages multiple state of the art machine learning models in a pipeline to identify abnormal network events through sequential analysis. We combine both device and packet-level information into individual events to characterize anomalous network actions. The model is trained and tested on real network traffic from the Idaho National Lab High Performance Computing (HPC) with greater than 98% precision. It is capable of flagging malicious tactics used by adversaries in malware-free attacks, severe changes to the network, and abnormal user activity by network devices.

99 - GENERAL AND MISCELLANEOUS↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗

Situational Awareness of Grid Anomalies (SAGA) for Visual Analytics—Near-Real-Time Cyber-Physical Resiliency Through Machine Learning

The Situational Awareness of Grid Anomalies (SAGA) project built upon foundational power system tools developed at the National Renewable Energy Laboratory (NREL) integrated with an ever-increasing set of Gridmetrics data extracted from the cable television (CATV) broadband network infrastructure while assimilating other time-series geospatial data and information, such as weather and cyber-physical phenomena, to demonstrate a disruptive technology for power system data analytics relying on existing infrastructure. Three research thrusts supported (1) visual analytics, (2) cyber-physical power system simulation, and (3) anomaly detection. SAGA created technology that leverages, couples, and fortifies two vastly different realms - power and broadband - to increase the resiliency of the power grid in the face of increasing cyberattacks and operational challenges related to integrating DERs. The exploration of potential synergies of broadband-enabled grids resulted in identifying a mutually beneficial symbiosis that can increase the resiliency of both power and broadband services. Broadband networks perform better with reliable power and are good at providing real-time measurements that identify where the grid is under attack, is failing, or is weak. Likewise, sensor-starved distribution grids perform better and can be more reliable when their operation is buttressed with observations of broadband-detected anomalies. Future research can explore broadband's contribution to continuing to improve grid resiliency, reliability, and cost-effective operation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Detecting CAN Masquerade Attacks with Signal Clustering Similarity

Vehicular Controller Area Networks (CANs) are susceptible to cyber attacks of different levels of sophistication. Fabrication attacks are the easiest to administer—an adversary simply sends (extra) frames on a CAN—but also the easiest to detect because they disrupt frame frequency. To overcome time-based detection methods, adversaries must administer masquerade attacks by sending frames in lieu of (and therefore at the expected time of) benign frames but with malicious payloads. Research efforts have proven that CAN attacks, and masquerade attacks in particular, can affect vehicle functionality. Examples include causing unintended acceleration, deactivation of vehicle’s brakes, as well as steering the vehicle. We hypothesize that masquerade attacks modify the nuanced correlations of CAN signal time series and how they cluster together. Therefore, changes in cluster assignments should indicate anomalous behavior. We confirm this hypothesis by leveraging our previously developed capability for reverse engineering CAN signals (i.e., CAN-D [Controller Area Network Decoder]) and focus on advancing the state of the art for detecting masquerade attacks by analyzing time series extracted from raw CAN frames. Specifically, we demonstrate that masquerade attacks can be detected by computing time series clustering similarity using hierarchical clustering on the vehicle’s CAN signals (time series) and comparing the clustering similarity across CAN captures with and without attacks. We test our approach in a previously collected CAN dataset with masquerade attacks (i.e., the ROAD dataset) and develop a forensic tool as a proof of concept to demonstrate the potential of the proposed approach for detecting CAN masquerade attacks.

Moriano Salazar, Pablo↗