Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Disrupting EV Charging Sessions and Gaining Remote Code Execution with DoS, MITM, and Code Injection Exploits using OCPP 1.6

Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565

99 GENERAL AND MISCELLANEOUS↗

Maximum-impact Adversary Design for Network-based Control System: A Case Study on Grid-interactive Efficient Buildings

The Internet of Things (IoT) technology has dramatically improved the efficiency of today's building operation and management. By connecting controllable devices into a communication network, control signals can be easily passed to the devices, and operating status can be acquired from measurable ends with minimal effort. However, this all-connected configuration could also expose the network-based control system (NBCS) to malicious actions, such as cyberattacks. One of the common NBCSs is the building automation system. With the promotion of grid-interactive efficient buildings (GEBs), there has been increasing attention on securing the buildings from the network perspective. This research proposes a maximum-impact adversary design framework so that the adversary can provide the most adversarial impact on the controlled system while remaining stealthy. The proposed framework is numerically demonstrated on a network-based building energy and control system. The building energy system is built in a Modelica-based simulation environment and controlled by the state-of-the-art ASHRAE Guideline 36 control sequences. The control commands at the supervisory level, generated from the Guideline 36 controller, are assumed to be sent to local devices through communication networks using the BACnet protocol. Simulation results show that the proposed maximum-impact adversary on such a system can stealthily affect the building system's performance to its maximum extent. It is anticipated that results can be used by researchers and practitioners in the building automation industry to design efficient and robust cyber-attack detection algorithms, especially for stealthy attacks.

Chu, Mengyuan↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Device-Centric Ransomware Detection using Machine Learning-Based Memory Forensics for Smart Inverters

Ransomware attacks are the fastest-growing form of cyberattacks worldwide. Recently, ransomware attacks have targeted industrial control systems (ICSs), including power grids. Lessons learned from recent incidents in ICSs show that ransomware groups can deliver ransomware into not only the organization’s control servers, but also the operational technology (OT) devices such as smart inverters and smart grid devices. This paper proposes a machine learning (ML)- based memory forensics method enabling the detection of ransomware binaries stored in the memory of a commercial smart inverter. Device firmware binary files are extracted from a Serial Peripheral Interface (SPI) flash memory, and samples of both benign and ransomware binaries are generated by a binary manipulation method and a real-world ransomware encryption, separately. A deep transfer learning (DTL) method is used to retrain a convolutional neural network (CNN)-based ransomware detection algorithm using the generated samples. The experimental result validates that the proposed ML-based memory forensics method can accurately detect ransomware files.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity Considerations for Emerging Energy Technologies

AI, cloud computing, post-quantum cryptography, zero-trust architectures, microgrids, and virtual power plants. What do these things have in common? They are all emerging technologies in the clean energy space that will be a critical part of grid modernization efforts. As we work towards clean energy and decarbonization targets, these technologies, developed to solve real-world problems, will help us reach goals and achieve new efficiencies as the paradigm of grid operation shifts. However, there are growing concerns about the cybersecurity risks associated with these trending topics as they are used in critical infrastructure applications. This talk will cover gaps, challenges, and opportunities for the secure implementation of grid modernization solutions and novel energy applications of state-of-the-art networking and communications. Proactive risk mitigation strategies, including the application of cyber-informed engineering, will be discussed. Practical applications of these techniques will help provide countermeasures to the impact of cyberattacks on critical infrastructure technologies in a new, digitized grid landscape.

14 SOLAR ENERGY↗

Engineering in Cyber Resilience with Cyber-Informed Engineering

Engineers have super powers to provide cybersecurity resilience with deterministic engineering solutions and to protect systems from the most catastrophic consequences that a cyber saboteur could cause. Come to this session to learn how to use engineering risk management skills to harden your engineered systems from cyberattacks. Objective 1 Identify what system functions could be digitally induced to cause undesired high-impact consequences. Objective 2 Analyze how loss or instability of digital controls in a subsystem could lead to high-impact consequences. Objective 3 Analyze how loss or instability in the digital connectivity between systems could lead to high-impact consequences. Objective 4 Identify engineering controls which could build resilience by eliminating digital loss or instability pathways or reduce the impact of digital loss or instability. This presentation will introduce Cyber-Informed Engineering, described below, and walk participants through specific engineering use cases to show how engineers can consider the potential for cyber sabotage in their existing system designs and enact deterministic engineering-based controls which eliminate pathways for attack or mitigate specific consequences. A wide variety of application use cases will be considered so that audience members can align the material with familiar engineering applications. CIE is an engineering approach that integrates cyber resilience into the conception, design, build, and operation of any physical system that has digital connectivity, sensors, monitoring, or control. CIE offers the opportunity to use engineering to eliminate or mitigate avenues for cyber attack—starting from the earliest stage of design and continuing throughout the system’s lifecycle. Today, engineers and industrial control system (ICS) technicians build engineered systems with specific goals for safety, reliability, and functionality. While systems engineering includes considerable safety and failure mode analysis, cybersecurity risks are often not specifically addressed—particularly the risks of intentional cyber compromise, exploitation, and misuse. Cyber-Informed Engineering pairs well with traditional cyber defenses and offers an extra designed-in protection to eliminate the most catastrophic consequences which can be realized by an adversary should traditional cyber defenses fail.

42 ENGINEERING↗

Trends in Cybersecurity Threats to Clean Energy

As deployments of clean energy generation and storage assets continue to grow, the increased attack surface creates a greater risk for cyber threats, but is clean energy truly a target for cyber adversaries? This poster will present research on the trends in cyber incidents that have affected clean energy companies and assets as well as the trends in disclosed and exploited vulnerabilities. From a series of ransomware attacks on European wind manufacturers, to vulnerabilities exploited in solar assets to turn controllers into botnets, to attacks on communication infrastructure that have resulted in extended outages of remote control and monitoring, we explore the techniques used and the impacts to the clean energy sector. Key takeaways include understanding of how OT-focused malware is becoming more flexible and more destructive, how known vulnerabilities are being exploited, the growing number of IT and OT attacks that use built in tools and functionalities. Additionally, we highlight the presumed motivations and targeted sectors for various identified cyber adversaries. Viewers will leave with an understanding of how recent headlines fit into the development of cyberattack trends and what preventions they may need to take to protect against increasingly popular tactics.

14 SOLAR ENERGY↗

Visualizing a Vulnerability: Its Connections to Hardware and Software

All Hazards Analysis (AHA) is a framework developed by Idaho National Laboratory that provides capabilities to collect, store, analyze, and visualize critical infrastructure information. A core function of AHA is its ability to simulate faults or outages in networks of infrastructure originating from a plethora of causes, ranging from natural disasters to cyberattacks. AHA utilizes Hardware and Software Bills of Material (HBOM and SBOM, respectively) along with Known Exploited Vulnerabilities (KEVs) to document the potential attack vectors for each piece of infrastructure. The objective of this contribution to AHA was to create a visualization tool that could capture the small details held in each individual artifact as well as preserve the large-scale connections that link them together to aid threat modeling.

58 GEOSCIENCES↗

Short-term Electricity Price Forecasting with Constrained Regressors

The volatility of electricity price presents a challenge to market participants as their decision-making process are highly depend on the accuracy of price forecasts. However, there is growing empirical evidence of increasing price volatility and price spikes in electricity markets as a result of variable renewable energy generation, extreme weather events, and other factors. The distribution shift caused by spikes in electricity price data differentiates the forecasting tasks from other renewable energy sources. Moreover, the observations may be compromised by cyberattacks and thus not available in the testing phase. To this end, we propose a Similarity-Enhanced Electricity Decomposition Forecasting model (SEED-Forecaster) to address the missing response problem and spikes capturing in short-term electricity price forecasting. The effectiveness of the proposed framework is tested on real-world electricity price data from California Independent System Operator (CAISO). Numerical results of case studies show that the proposed SEED-Forecsater can enhance forecasting performance, particularly in capturing electricity spikes, even under conditions without regressors during testing stage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Towards Secure Autonomous Vehicles: An Integrated Edge and Multi-Modal Machine Learning Framework for Intrusion Detection

Autonomous vehicles (AVs) are vulnerable to cyberattacks targeting both internal communication networks and external perception sensors. While edge-based intrusion de- tection for Controller Area Network (CAN) buses offers real-time protection, it cannot detect cross-modal threats. Conversely, multi-modal fusion approaches improve coverage but often lack efficiency for in-vehicle deployment. This thesis integrates two complemen- tary solutions: (1) a lightweight, edge-deployable machine learning framework for CAN bus intrusion detection, and (2) a late-fusion system combining CAN FD and LiDAR data. Together, they form a hierarchical defense capable of handling single-modality and coordi- nated attacks. Simulations show that CAN-only models reach 93% accuracy on simulated DoS, spoofing, replay, and fuzzy attacks, while the fusion system achieves 0.87 AUC and 0.82 F1-score at 2 ms latency. This unified framework establishes a scalable, explainable, and field-ready strategy for AV cybersecurity.

97 MATHEMATICS AND COMPUTING↗

Design Choices in Anomaly Detection for Industrial Control Systems: Insights from Gas Pipeline Data

Industrial control systems (ICS) remain vulnerable to increasingly sophisticated cyberattacks, yet evaluating anomaly detection models in these environments is challenging due to temporal dependencies, missing-not-at-random patterns, and extremely imbalanced datasets. These factors make common practices—especially random data splits and naïve imputation—prone to severe temporal leakage, which can inflate reported performance and obscure real-world limitations. In this work, we systematically examine classical machine learning models, temporal deep learning architecture, and tensor-decomposition–based methods on a gas-pipeline dataset using a fully temporally separated evaluation pipeline designed to mimic realistic deployment conditions. Our findings show that proper temporal handling and MNAR-aware preprocessing significantly alter the relative performance of popular anomaly-detection methods, providing practical guidance for designing reliable, leakage-resistant ICS intrusion-detection systems.

97 MATHEMATICS AND COMPUTING↗

A Real-Time Implementation and Validation of Federated Learning for Grid Services

Grid-edge devices are becoming increasingly important in the energy transition. Preserving privacy was not previously considered an important aspect for power grid operations, but with the increased proliferation of customer-owned assets, it is now an essential consideration. Several mechanisms have been proposed to provide privacy for non-utility owned assets in the power grid. Federated learning (FL) is one method gaining prominence in this area. Although FL has been used for other applications, such as auto-complete in phones, there has not been much investigation into whether these approaches are feasible for grid applications. In this work, we use a research platform with real-time simulators and hardware-in-the-loop capabilities to investigate how FL can be applied to grid-edge devices, and we present the potential grid services that can be derived for these devices. We discuss the computational challenges with deploying complex FL approaches, and we explore several grid services, including participation in retail electricity markets, voltage control, and resilience-driven reconfiguration.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Device-Centric Firmware Malware Detection for Smart Inverters using Deep Transfer Learning

Since future power grids are inverter-dominant grids and inverters are getting smarter by incorporating remote access and seamless firmware update, it is anticipated that malware attackers will directly target smart inverters. However, malware threats targeting smart inverters have been less studied yet. This paper explores potential malware attacks targeting smart inverters and proposes a deep transfer-learning (DTL)-based malware detection framework for smart inverters. The proposed DTL method can significantly reduce development time and efforts for an artificial intelligence-based malware detection algorithm while improving detection accuracy. The experimental result shows that the proposed method achieves 98% of firmware malware detection accuracy. Furthermore, this approach will be transformative to other smart grid devices enabling seamless firmware update.

artificial intelligence↗

Model-Based Detection of Coordinated Attacks (DCA) in Distribution Systems

The fast-paced growth in digitization of smart grid components enhances system observability and remote-control capabilities through efficient communication. However, enhanced connectivity results in heightened system vulnerability towards cybersecurity risks in the cyber-physical power system. Coordinated cyber-attacks (CCA), when undetected, lead to system-wide impact in terms of large disturbances or widespread outages. Detecting CCA in the cyber layer is critical to thwart cyber-attacks in real-time before the attack impacts the physical system. The challenge of locating CCA stems from the complex grid dynamics, making it difficult to distinguish between normal operational variations and cyber-attack impact. CCA often employs multiple attack vectors targeting geographically distributed components, further complicating CCA identification. Existing research in intrusion detection is primarily focused on the transmission network and limited to detecting individual attacks. In this paper, a novel proactive DCA strategy is proposed for early detection of CCA by establishing correlations among distinct attack events through model-based reinforcement learning that utilizes abductive reasoning to conclude the attacker goal. The solution includes understanding the system model, learning the system dynamics, and correlating individual cyber-attacks to extract the attacker’s objective. The developed learning algorithm identifies the most probable attack path to reach the attacker’s objective by predicting the next attack steps. A DNP3-based cyber-physical co-simulation testbed is developed to test the proposed algorithm using the IEEE 13-node test feeder.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hybrid Data-Driven Based HVdc Ancillary Control for Multiple Frequency Data Attacks

The high voltage direct current (HVdc) intertie has been applied to provide ancillary-services for ac grids, utilizing the real-time feedback from phasor measurement units (PMUs). However, PMU data communication is vulnerable to false data injection attacks (FDIA) due to protocol defects, thus the HVdc ancillary control and system stability will be threatened. To address this issue, this article proposes a novel HVdc control strategy based on a hybrid data-driven (HDD) methodology. In this work, the HDD methodology is first proposed to detect the types and duration time of multiple frequency attacks. Specifically, the Hilbert Huang transform (HHT) is used to decompose the frequency data, using variational mode decomposition instead of the traditional empirical mode decomposition, to extract data features. Second, a multikernel support vector machine is proposed to classify the attacked data based on the designed distinctive features from HHT. Meanwhile, the attacking duration time is decided using an unsupervised technique. Third, an HDD-based HVdc ancillary control strategy is established to eliminate the effect of FDIAs on the HVdc frequency response. Comprehensive experiments of HDD-based HVdc ancillary controls under different FDIAs suggest that the proposed HDD could fast and accurately classify the FDIAs, and the HDD-based HVdc ancillary control strategy could significantly suppress the impact of the FDIAs.

97 MATHEMATICS AND COMPUTING↗