Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Cyber-Informed Engineering Power Generation Guide [Slides]

The CIE for Power Generation: Insights and Case Studies guide is being developed to assist engineers at utilities, asset owner-operators developers, and cybersecurity teams to build in robustness and cyber resiliency into their designs using cyber-informed engineering practices. This guide will break out these topics including use cases by chapters for areas such as Nuclear, IBRs, Geothermal, natural gas, etc.

97 MATHEMATICS AND COMPUTING↗

The NREL Cyber Range

With the National Renewable Energy Laboratory's (NREL's) cyber range, researchers can replicate cybersecurity scenarios as they would occur on real, complex energy systems. With supercomputing and advanced emulation capabilities, the cyber range allows users to build digital twins of real systems and connect the emulated environment to actual physical devices throughout NREL's laboratories. The space offers unlimited potential to test the frontier of energy systems security.

cyber range↗

Exploring Applied Cryptosystems to Formally Verify Security in Cyber-Physical Systems

This project aims to evaluate RSA as a method for public-key encryption for cyber-physical systems (CPS). As technology advances, cyber attacks are increasing, and with them, the need for cybersecurity advances; the average cost for cybercrime in the world was estimated at $6 trillion in 2021. A public-key cryptosystem that has been around since 1977, RSA has recently garnered some critiques for its fragility, computational cost, and lazy implementation. In this project I will review the mathematical derivation of RSA, analyze the practical implications of such mathematical framework for the security of RSA, and propose a formal methods based approach to verify encryption schemes for CPS.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Guidance—Implementing CIE in Early Systems Engineering Lifecycle Stages

Traditionally, cybersecurity is not considered in the design process. Design engineers typically focus on building safety and reliability into their products and applications. Security against malicious cyber incidents is often an afterthought, resulting in deployment of security solutions during installation or operation. Unfortunately, waiting to consider cybersecurity until later in the systems engineering lifecycle often results in less effective and more expense security. Idaho National Laboratory (INL) developed the concept of Cyber-Informed Engineering (CIE) in 2015 to provide a framework that enables cybersecurity to be built into systems beginning at the conceptual design stage. In addition to ongoing research by INL, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response has recently developed a National CIE Strategy document for incorporating CIE into the design and operation of infrastructure systems reliant on digital monitoring or controls. This paper provides a brief review of this National CIE Strategy as well as a roadmap to historical, current, and future CIE research by INL through the U.S. DOE Office of Nuclear Energy (NE) Cybersecurity Crosscutting Technology Development Program. A near-term focus of the DOE-NE’s research and development is to extend the foundational CIE work into detailed guidance for implementation during initial systems engineering stages in nuclear digital instrumentation and control projects and to demonstrate use of the guidance in an integrated energy systems project.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Informed Engineering Overview: Joint NERC/INL/E-ISAC Webinar

In July, NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), and Idaho National Laboratory (INL) will host a joint informational webinar to highlight areas focused on integrating cyber and physical security with conventional engineering practices (security integration). NERC's work on these topics represents one of the first focused applications of Cyber-Informed Engineering (CIE). INL is leading the development of philosophy and practices to identify and mitigate the inherent risks of digital technology by including cybersecurity as a core element of engineering risk management. This presentation will provide an overview of CIE, a discussion of how NERC's work represents one of the first new discipline-specific applications of CIE, and an update on significant milestones and resources from the CIE program.

24 POWER TRANSMISSION AND DISTRIBUTION↗

End-to-End Encryption for Cyber-Physical Systems Using Fully Homomorphic Encryption

Cyber-physical systems require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This presentation introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

97 MATHEMATICS AND COMPUTING↗

Cyber Threat Assessment of Solar PV Energy

This presentation discusses cyber threats to solar energy systems. Through a discussion of the cyber risk elements of threat, vulnerability, and consequence, we present examples of these risks in the solar industry. Then, we present 8 real-world events from the last 5 years that have affected the solar industry or solar companies.

14 SOLAR ENERGY↗

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING↗

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS↗

Cyber-Informed Engineering: Incorporating CIE into Engineering Curricula

Cyber-Informed Engineering (CIE) is an engineering approach that mitigates the consequences of cyber risk to critical infrastructure by integrating engineered controls into system design and operation. CIE-focused education is necessary to prepare future engineers and technicians to understand and mitigate digital risk in modern engineered systems. This session explores how universities can incorporate CIE into their curricula, provides examples of how existing universities are already leveraging CIE in their programs, and highlights resources to support adoption.

99 - GENERAL AND MISCELLANEOUS↗

Assurance by Design for Cyber Physical Data-Driven Systems

Currently, Cyber Physical Data-Driven Systems (CPDDS) employ machine learning for the classification, data fusion, and control of our nation’s infrastructure, such as the power grid, transportation networks (e.g., fuel distribution, air traffic control), and DoD long-duration collaborative autonomous platforms including unmanned underwater, ground, surface, space, and aerial systems. Many CPDDSs are system-of-systems that should be designed to communicate over disadvantaged networks. It is important to assure that the CPDDSs are resilient against physical and cyber threats by design. Additionally, their design should tolerate misclassification errors resulting from natural and/or adversarial distribution shifts within their data driven components. The all-domain nature of the problem of assuring the design of CPDDSs requires a multi-disciplinary perspective as outlined in this chapter.

Chikkagoudar, Satish↗

Programmable intrusion detection for distributed energy resources in cyber–physical networked microgrids

We present a programmable intrusion detection method is presented to identify the malicious attacks to distributed energy resources (DERs) in the cyber-physical networked microgrids. The proposed method injects small programmable signals into the system and uses the response to identify abnormal conditions. Because of the low or even zero inertia induced by integrations of DER power-electronic-interfaces, microgrids have very limited resilience capability; and thus, being sensitive to attacks. One microgrid's malfunction caused by attacks can easily propagate to its neighboring systems when several microgrids are connected, leading to catastrophic electricity supply failures. Through the presented method, malicious intrusions can be effectively detected, located, and defended for securing microgrids. Theoretical derivations are provided to define the programmable detection rules. The detection rule is easy and flexible to update, making it difficult for attack actors to gain the knowledge of the detection rules, in order to avoid being detected. Numerical results on a cyber-physical networked microgrids system show that the proposed method is effective and efficient in precisely locating intrusion attacks to the microgrids system.

42 ENGINEERING↗

Electrical substation grid testbed for DLT applications of electrical fault detection, power quality monitoring, DERs use cases and cyber-events

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation, and are associated with customer-owned distributed energy resources (DERs). The integrity and confidentiality of data from these IEDs, like power meters and protective relays, is crucial. Blockchain technology could improve the resilience of microgrids by improving the security of data sharing. The penetration of customer-owned DERs (renewable energy sources) and the increasing deployment of IEDs can lead to integrate power system applications with Distributed Ledger Technology (DLT). In this study, we implemented the electrical faulted phase detection and power quality monitoring algorithms with a Cyber Grid Guard (CGG) system using DLT. In addition, the DERs (wind turbine farms) use case and protective relay cyber-event tests were assessed, by using the CGG system with DLT. In the experimental model, the testbed was created by using a real-time simulator and CGG system with power meters/ protective relays in-the-loop. The data collected from the CGG system and IEDs were compared with the same time stamp source. These results had shown the successful assessment of protection, control and monitoring applications using a CGG system with DLT. In the future, the ESGT with DERs and the CGG system will be used in other power system applications, based on implementing smart contracts between electrical utilities with customer-owned DERs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

SeqMask: Behavior Extraction Over Cyber Threat Intelligence Via Multi-Instance Learning

Abstract Identification and extraction of Tactics, Techniques and Procedures (TTPs) for Cyber Threat Intelligence (CTI) restore the full picture of cyber attacks and guide the analysts to assess the system risk. Existing frameworks can hardly provide uniform and complete processing mechanisms for TTPs information extraction without adequate knowledge background. A multi-instance learning approach named SeqMask is proposed in this paper as a solution. SeqMask extracts behavior keywords from CTI evaluated by the semantic impact, and predicts TTPs labels by conditional probabilities. Still, the framework has two mechanisms to determine the validity of keywords. One using expert experience verification. The other verifies the distortion of the classification effect by blocking existing keywords. In the experiments, SeqMask reached 86.07% and 73.99% in F1 scores for TTPs classifications. For the top 20% of keywords, the expert approval rating is 92.20%, where the average repetition of keywords whose scores between 100% and 90% is 60.02%. Particularly, when the top 65% of the keywords were blocked, the F1 decreased to about 50%; when removing the top 50%, the F1 was under 31%. Further, we also validate the possibility of extracting TTPs from full-size CTI and malware whose F1 are improved by 2.16% and 0.81%.

Ge, Wenhan↗

Cyber Protection of Grid-Connected Devices Through Embedded Online Security

Cybersecurity research regarding the electric power grid has primarily been focused on protecting the communication layer of grid-connected devices against cyber-attack threats. Although many developed methods have greatly reduced the effects of a cyber-attack on the vulnerabilities of grid-connected devices, discovering new vulnerabilities is inevitable and a constant threat. As a result, the overall reliability and security of network communications with regard to grid-connected devices is a concern. Here, this paper proposes a method that further secures a system by focusing on the control and hardware layer of grid-connected devices. The device’s controller firmware will be validated and authenticated using integrated device emulation resources prior to being activated to control the grid-connected device. This verification process is performed while the controller is online and actively controlling power flows related to the device. Therefore, an attack to the system through a malicious firmware patch would be detected by the online security and rejected while safely maintaining continuous and stable control of the device. This method integrates the concepts of firmware hot-patching, digital twins, and active monitoring into an overall cybersecurity protection system.

cybersecurity↗

Detection of Cyber Attacks in Grid-tied PV Systems Using Dynamic Watermarking

This paper presents of an active detection scheme for detecting cyber attacks on sensors controlling a grid-tied PV systems. Several cyber vulnerabilities in Grid tied PV Systems are discussed. The defense mechanism introduces a private (secret) watermarking signal into the control inputs of the grid-tied inverter system. This will enable the detection of any malicious manipulation of sensor measurements. Based on the measured data, two statistical tests are conducted to identify anomalies in the system using the presence of the watermarking signal. It shown that when a sensor data is compromised and/or replaced by a pre-recorded healthy signal, both test 1 and 2 exhibit high values indicating a possible malicious activity. The robustness of the proposed algorithm is tested and validated with several attack scenarios on a grid tied PV system. Select results from an experimental setup are discussed.

Ibrahim, Hasan↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗