Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Understanding How Organizations Handle Cybersecurity

If there is anything we can learn from the media, it is the frequency and severity of cyber-attacks is increasing and there are not enough qualified people to combat the risk organizations are facing. Current estimates say there are 3.5 million available cybersecurity related jobs globally and there has been a 350% growth in cybersecurity jobs since 2013 (Group, 2020). The Idaho Cyber Research Project (ICRP) is focused on finding an implementing solution to the problems in the workforce development pipeline. Our team consists of Cohort 2 of the ICRP, we are tasked with solving issues faced by organizations hiring new cyber personnel. To provide solutions to these issues we focused our research on four components of workforce availability and competency: resume and transcript analysis, apprenticeships, cyber incident response plan development, and adversarial mindset training. From this research we have produced the following focus areas and subsequent steps for each component of workforce capability: transcript and knowledge skills abilities (KSA) focused analysis, cybersecurity apprenticeships programs, the value of an adversarial mindset, and a guide to setting up cyber incident response plans for underprepared organizations. These solutions can be further developed and implemented to reduce the gap in workforce demand and talent.

97 MATHEMATICS AND COMPUTING↗

A Localized Cyber Threat Mitigation Approach For Wide Area Control of FACTS

We propose a localized oscillation amplitude monitoring (OAM) method for the mitigation of cyber threats directed at the wide area control (WAC) system used to coordinate control of Flexible AC Transmission Systems (FACTS) for power oscillation damping (POD) of active power flow on inter-area tie lines. The method involves monitoring the inter-area tie line active power oscillation amplitude over a sliding window. We use system instability - inferred from oscillation amplitudes growing instead of damping - as evidence of an indication of a malfunction in the WAC of FACTS, possibly indicative of a cyber attack. Monitoring the presence of such a growth allows us to determine whether any destabilizing behaviors appear after the WAC system engages to control the POD. If the WAC signal increases the oscillation amplitude over time, thereby diminishing the POD performance, the FACTS falls back to POD using local measurements. The proposed method does not require an expansive system-wide view of the network. We simulate replay, control integrity, and timing attacks for a test system and present results that demonstrate the performance of the OAM method for mitigation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

A Robust Method to Secure Multi-Inverter Grid Tied PV and Battery Energy Storage Systems Against Cyber Intrusions

This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.

Ibrahim, Hasan↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

SCEPTRE: A Cyber-Physical Emulation Capability

Cyber-physical systems form a critical but vulnerable backbone to US critical infrastructure. Recent high-profile cyber-attacks have shown the need for increased assessment and hardening of these systems. However, such assessments and investigations into advanced technologies to harden these systems is difficult due to their operational nature. Instead, modeling of these systems is heavily leveraged. Investigation into these complex systems and their potential cascading failures requires comprehensive modeling of both the cyber and physical components of the system. This paper introduces SCEPTRE, an emulation capability to address this need.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS): A Probabilistic Approach

In this project, we employ a layered protection strategy incorporating advanced optimization and detection techniques using a probabilistic approach. The probabilistic approach is not only applied when detecting cyber attacks, but also incorporated in control strategies, which greatly increases the attacking difficulties. Hackers need to understand both probabilistic detection algorithms and uncertainty modeling methods in control in order to execute any effective attacks. The end-to-end solutions enable us to provide Building Intelligence with Layered Defense using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS).

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Cyber Physical Protection for Natural Gas Compression

The secure transport of natural gas through North American pipelines is vital for both home and industrial purposes. GE in collaboration with Baker Hughes and Idaho National Laboratory, completed a US Department of Energy grant program to develop a new cyber-physical protection system that monitors the large compressor stations used to boost pressure and maintain proper gas flow. Algorithms were developed to detect the presence of a cyber-attack that impacts the compressor station physical processes, locate the critical functions being manipulated, and potentially neutralize the attack allowing continued operations. The technology was successfully demonstrated at an operating compressor facility located in New York state.

03 NATURAL GAS↗

Comparison of Socio-Technical Threat Models

Given the adoption of emerging technologies and the increasing complexity of managing such systems with a lifecycle much shorter than that of critical infrastructure systems, there is a practical need to be able to analyze sociotechnical dependencies and their associated evolving risks. Threat models based on social influence techniques can be used to implement adversarial tactics analogous to the cyber kill chain and attested to within the MITRE ATT&CK for ICS framework including Initial Access, Persistence, Collection, and Impact. Furthermore, as with cyber disruptions, the impact of social influence threat models can have an asymmetric impact that is not spatially-localized. Finally, unlike cyber attacks with a reasonably short duration (ransomware takes days to months), social influence based attacks have the potential to persist for much longer as they are based on long-term strategic infrastructure investments within the private sector. Given the increased importance of electric vehicle charging stations as a long-term, strategic infrastructure investment within the Energy and Transportation Sectors, we provide initial results that compare the impact of a Loss of Availability (T0826) realized through cyber and social influence based threat models. The analysis employs techniques from automated reasoning and measures of network complexity to understand evolving dominance of EV payment and charging networks within geographic region of interest. Within this context, we compare the impact of a loss of availability due to ransomware versus that of loss of support due to a merger and acquisition. Results across several different metro areas will be provided.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Discovery of False Data Injection Attacks on Power Grid Frequency Controllers with Reinforcement Learning [Poster]

While inverter-based DER (distributed energy resources) are instrumental to integrating renewable energy into the power grid, they reduce the grid's mechanical inertia, thereby increasing the risk of frequency instabilities. To compensate for frequency instability risks, the grid must also undergo a transformation to include digital technologies that allow for two-way communication between the utility and customers. The current and future state of the power grid allows for building a cleaner energy landscape. However, the grid may also become vulnerable to novel cyber threats. To preemptively protect the power grid against elaborate cyber-attacks, we propose to discover potential threats via reinforcement learning. In this work, the focus is on studying false data injection attacks that target the control logic of frequency controllers. We show that a reinforcement learning agent can successfully discover how to best inject false data into linear droop controllers.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Engineering-In Cybersecurity

Cyber-Informed Engineering is a framework which allows engineers to build resiliency to the impacts of cyber attack into engineered systems starting in the early design phases. This article introduces the framework and provides a description of some of its principles and resources for learning more.

42 ENGINEERING↗

Perturbation-Based Diagnosis of False Data Injection Attack Using Distributed Energy Resources

Modern smart grid relies on various sensor measurements for its operational control. In a successful false data injection attack, the attacker manipulates the measurements from the grid sensors such that undetected errors are introduced into the estimates of the system parameters leading to catastrophic situations. This paper proposes a novel perturbation based false data injection attack detection mechanism that utilizes inverter based distributed energy resources (DERs) to create low magnitude perturbation signal in the distribution system voltage that is inconsequential to the normal grid operation. Two voltage sensitivity analysis based algorithms are designed to identify the optimal set of DERs that can create the voltage perturbation signal of desired magnitude. An analytical method of voltage sensitivity analysis is used to compute the magnitude of voltage perturbation signal at each node in a computationally efficient manner. Then, a detection mechanism is developed that checks for the presence of the perturbation sequence in each sensor measurement. A sensor measurement is deemed authentic if the voltage perturbation signal is present in the data. In case of sensor malfunction or cyber-attack, the perturbation signal will not be present in the measurement data. Performance of the proposed attack detection mechanism is validated via simulation of the IEEE 69 bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Impact Analysis of Data Integrity Attacks on FACTS-based Wide-Area Voltage Control System

Energy management system (EMS) consists of several wide-area control applications that serve as a backbone for security, stability, and reliability of the power system. Wide-area voltage control system (WAVCS), one of the critical wide-area applications, operates in coordination with local Flexible AC Transmission System (FACTS) devices to provide voltage security and optimal management of active and reactive power resources. Since the WAVCS relies on wide-area communication and data sharing devices, possible cybersecurity vulnerabilities have to be addressed to ensure the closed-loop operation of WAVCS. In this paper, we present a methodology for performing an impact analysis of cyber-attacks in WAVCS cybersecurity. In particular, different types of data integrity attacks, such as malicious tripping, fault replay, and signal altering attacks, are considered, and detailed impact analysis is conducted in a testbed environment using the Kundur's four machine two-area system. For performing an impact analysis, the transient voltage stability of the sensitive bus voltage is studied, followed by the quantitative assessment and severity ranking using the voltage profile index. Our experimental evaluation reveals that the data integrity attacks on control signals exhibit a higher attack severity than on the measurement signals. Further, the severity of these attacks varies with nature (static or dynamic), location, and types of attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Design and Development of a High Fidelity Cyber-Physical Testbed

In order to ensure that future critical infrastructure systems are resilient to various types of such advanced and persistent threats, it is important to develop and integrate tailored solutions that holistically address cyber-attack detection and mitigation in a timely manner such that adverse system impacts that impact a large population are avoided. Further, it is essential to create environments that allow control, protection and communication to exist within a realistic environment to analyze the effects of adverse conditions and system operating modes. This project aims to establish a high-fidelity testbed environment for modeling and simulating a single microgrid all the way up to a network of microgrids along with baseline controls, protection, and associated cyber communication. This is an important activity because accurately modeling and simulating the various power-electronics-based DERs and loads in a microgrid is critical to adequately capturing their behaviors over a wide range of off-normal conditions, as well as to evaluate the resilience of the system using the developed controls. The work presented in this report focuses on the process of building this high-fidelity testbed and the associated experimentation it enables. The model enables the creation of high-fidelity use cases and associated datasets that have been used extensively within the initiative to study resilience and support novel control development and prototyping. The work heavily leverages existing capability that is part of the high-fidelity cyber-physical system experimentation lab to create a power hardware-in-the-loop setup. The report also details the creation of an automated model building platform that can enable high-fidelity real-time models to be built without much effort allowing existing low-fidelity models to be analyzed in higher fidelity. Lastly, the report also discusses efforts center around scaling to large complex power system models to make the experimentation more effective.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

Securing Vehicle Charging Infrastructure

As the US electrifies the transportation sector, cyber attacks targeting vehicle charging could bring consequences to electrical system infrastructure. This is a growing area of concern as charging stations increase power delivery and must communicate to a range of entities to authorize charging, sequence the charging process, and manage load (grid operators, vehicles, OEM vendors, charging network operators, etc.). The research challenges are numerous and are complicated because there are many end users, stakeholders, and software and equipment vendors interests involved. Poorly implemented electric vehicle supply equipment (EVSE), electric vehicle (EV), or grid communication system cybersecurity could be a significant risk to EV adoption because the political, social, and financial impact of cyberattacks - or public perception of such - ripples across the industry and has lasting and devastating effects. Unfortunately, there is no comprehensive EVSE cybersecurity approach and limited best practices have been adopted by the EV/EVSE industry. There is an incomplete industry understanding of the attack surface, interconnected assets, and unsecured interfaces. Thus, comprehensive cybersecurity recommendations founded on sound research are necessary to secure EV charging infrastructure. This project is providing the power, security, and automotive industry with a strong technical basis for securing this infrastructure by developing threat models, determining technology gaps, and identifying or developing effective countermeasures. Specifically, the team is creating a cybersecurity threat model and performing a technical risk assessment of EVSE assets, so that automotive, charging, and utility stakeholders can better protect customers, vehicles, and power systems in the face of new cyber threats.

33 ADVANCED PROPULSION SYSTEMS↗

Hypergames and Cyber-Physical Security for Control Systems

The identification of the Stuxnet worm in 2010 provided a highly publicized example of a cyber attack that physically damaged an industrial control system. This raised public awareness about the possibility of similar attacks against other industrial targets—including critical infrastructure. Here, we use hypergames to analyze how strategic perturbations of sensor readings and calibrated parameters can be used to manipulate a system that employs optimal control. Hypergames form an extension of game theory that enables us to model strategic interactions where the players may have significantly different perceptions of the game(s) they are playing. Past work with hypergames has focused on relatively simple interactions consisting of a small set of discrete choices for each player. Here, we apply single-stage hypergames to larger systems with continuous variables. We find that manipulating constraints can be a more effective attacker strategy than manipulating objective function parameters. Moreover, the attacker need not change the underlying system to carry out a successful attack—it may be sufficient to deceive the defender controlling the system. It is possible to scale our approach up to even larger systems, but this will depend on the characteristics of the system in question, and we identify several characteristics that will make those systems amenable to hypergame analysis.

97 MATHEMATICS AND COMPUTING↗

Electrical Fault Detection, Power Quality, Distributed Energy Resource Use Cases, and Cyber Event Applications with the Cyber Grid Guard System Using Distributed Ledger Technology

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation and are associated with distributed energy resources (DERs). The integrity and confidentiality of data from IEDs is crucial, and distributed ledger technology (DLT) could improve the resilience of microgrids by helping to make these data more secure. The most popular applications using blockchain technology for electrical utilities is in the field is based on energy trading. However, the dynamism of the penetration of customer owned DERs and the deployment of sensors with IEDs have led to the identification of new applications using DLT that are focused on other areas, such as monitoring, operation and management of the grid and its assets. In addition, the majority of studies on electrical grid applications with blockchain were validated with software simulations. Although general monitoring of power systems for using DLT could be evaluated in operational electric grids, other DLT research applications such as defense against cyber-attacks and/or electrical fault detection are not likely to be performed in a real infrastructure because of possible risks to the network/equipment security. This report summarizes the application of power system applications using distributed ledger technology (DLT), providing a secure DLT framework for collecting data from IEDs like power meters and protective relays inside and outside of an electrical substation and/or between two different electrical utilities. In this study, the use case scenarios were created and assessed for different power system application by using DLT. The electrical fault detection for faulted phases (1), power quality monitoring of phase voltage magnitudes, frequency levels and load power factor (2), DERs use case monitoring (3), and cyber-event applications (4) were performed in a test bed with a Cyber-Grid Guard (CGG) system using DLT. It had a real-time simulator with power meters and protective relays in-the-loop. The first section of this report presents a literature review of power system applications using blockchain at research level. The second section shows the theory and equations used on this report. The third section shows the description of the test bed, equipment, architecture, and electrical grid diagrams. The fourth section shows the experimental models and use case scenarios that were performed for the electrical fault detection, power quality, DERs use case, and cyber event applications with the CGG system using DLT. The fifth section shows the results collected from the tests based on comparing the time stamped events of the analog signals from the IEDs, DLT computer and real time simulator. The sixth section performed the discussion of the results for the use case scenarios. Finally, section seven presents the conclusions for this report were presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗