Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

An End-to-End Framework for Verifying and Validating Manufacturing Design Integrity

Cyber attacks on networked automated manufacturing systems can severely impact part quality. In fact, malicious modifications may be introduced at any point during the manufacturing lifecycle. Therefore, it is vital to verify and validate that manufactured parts conform to their designs. This chapter describes a formal, end-to-end framework that verifies and validates the design integrity of manufactured parts by considering all potential points of alteration during precision manufacturing processes. The framework prevents unauthorized changes to computer-aided designs, verifies the correctness of translations from CAD models to G-code, maintains the integrity of G-code transferred to manufacturing machines, verifies the runtime execution of G-code and part geometry, and considers the contexts of manufacturing machine operations and how manufactured parts could be altered.

Jablonski, Matthew [Cybersecurity Manufacturing In↗

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.

Asmar Awad, Rima [ORNL] (ORCID:0000000233407742)↗

Optimizing power system restoration with damaged communications

Utility procedures for power system blackstart and restoration typically assume that energization decisions can be reliably communicated across the grid. In reality, the communications and control network would likely also be affected in power outages, such as those caused by extreme weather events or cyber-attacks. This paper studies the effect of damage to the power system communications and control infrastructure on restoration operations following a blackout. We model the communications infrastructure as a graph, overlaying the power grid, and imposing the requirement that every energized element in the power grid be observable from a control center. We expand on a specialized branch-and-bound algorithm from the literature to optimize the restoration process and devise an initialization heuristic and a rounding heuristic to improve solution speed. We perform numerical experiments on synthetic systems for Illinois and Texas with outages based on a solar flare or hurricane. We compare the results of our specialized branch-and-bound algorithm to the results from (i) the initialization heuristic alone, (ii) a variation of this heuristic that we use as a baseline, and (iii) the restoration optimization for the power system without communications constraints. Here, we find that damage to the communications infrastructure significantly increases the time required to re-energize the grid. Moreover, by simultaneously optimizing communications repairs and grid energization decisions, we are able to re-energize the grid significantly faster than if communications repairs and energization decisions were made independently or with partial coordination, motivating improvements to current industry practice.

97 MATHEMATICS AND COMPUTING↗

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

Cybersecurity Vulnerability Mitigation Framework through Empirical Paradigm: Enhanced Prioritized Gap Analysis

Existing cybersecurity vulnerability assessment tools were designed based on the policies and standards defined by organizations such as the U.S. Department of Energy and the National Institute of Standards and Technology (NIST). Frameworks such as the cybersecurity capability maturity model (C2M2) and the NIST Cybersecurity Framework (CSF) are often used by the critical infrastructure owners and operators to determine the cybersecurity maturity of their facility. Although these frameworks are exceptional at performing qualitative cybersecurity analysis and identifying vulnerabilities, they do not provide a means to perform prioritized mitigation of those vulnerabilities in order to achieve a desired cybersecurity maturity. To address that challenge, we developed a framework and software application called the cybersecurity vulnerability mitigation framework through empirical paradigm (CyFEr). This paper presents the detailed architecture of CyFEr’s enhanced prioritized gap analysis (EPGA) methodology and its application to CSF. The efficacy of the presented framework is demonstrated by comparing against existing similar models and testing against the cyber injects from a real-world cyber-attack that targeted industrial control systems (ICS) in critical infrastructures.

Gourisetti, Sri Nikhil G.↗

Omega-Limit Sets and Input-To-State Stability in Power Grids with Switching Equilibria

This paper studies a power transmission system with both conventional generators (CGs) and distributed energy assets (DEAs) providing frequency control. We consider an operating condition with demand aggregating two dynamic components: one that switches between different values on a finite set, and one that varies smoothly over time. Such dynamic operating conditions may result from protection scheme activations, external cyber-attacks, or due to the integration of dynamic loads, such as data centers. Mathematically, the dynamics of the resulting system are captured by a system that switches between a finite number of vector fields - or modes -, with each mode having a distinct equilibrium point induced by the demand aggregation. To analyze the stability properties of the resulting switching system, we leverage tools from hybrid dynamic inclusions and the concept of ..omega.. -limit sets from sets. Specifically, we characterize a compact set that is semi-globally practically asymptotically stable under the assumption that the switching frequency and load variation rate are sufficiently slow. For arbitrarily fast variations of the load, we use a level-set argument with multiple Lyapunov functions to establish input-to-state stability of a larger set and with respect to the rate of change of the loads. The theoretical results are illustrated via numerical simulations on the IEEE 39-bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

SeqMask: Behavior Extraction Over Cyber Threat Intelligence Via Multi-Instance Learning

Abstract Identification and extraction of Tactics, Techniques and Procedures (TTPs) for Cyber Threat Intelligence (CTI) restore the full picture of cyber attacks and guide the analysts to assess the system risk. Existing frameworks can hardly provide uniform and complete processing mechanisms for TTPs information extraction without adequate knowledge background. A multi-instance learning approach named SeqMask is proposed in this paper as a solution. SeqMask extracts behavior keywords from CTI evaluated by the semantic impact, and predicts TTPs labels by conditional probabilities. Still, the framework has two mechanisms to determine the validity of keywords. One using expert experience verification. The other verifies the distortion of the classification effect by blocking existing keywords. In the experiments, SeqMask reached 86.07% and 73.99% in F1 scores for TTPs classifications. For the top 20% of keywords, the expert approval rating is 92.20%, where the average repetition of keywords whose scores between 100% and 90% is 60.02%. Particularly, when the top 65% of the keywords were blocked, the F1 decreased to about 50%; when removing the top 50%, the F1 was under 31%. Further, we also validate the possibility of extracting TTPs from full-size CTI and malware whose F1 are improved by 2.16% and 0.81%.

Ge, Wenhan↗

Self-Security for Grid-Interactive Smart Inverters Using Steady-State Reference Model

Smart inverters exchange information with other devices through a shared communication link, making the inverters more prone to receive harmful commands from external parties. This erroneous data can be received due to an anomaly in the system, such as a device fault, unintentional utility operator action, or a cyber-attack. In this paper, a device-level self-security strategy is implemented using reference models for a grid-interactive inverter to examine the incoming power setpoints, detect the anomalies, and protect the system accordingly. The PQ setpoints received from the utility supervisory controller are autonomously examined using the inverter’s normal and stable operating regions before engaging the setpoints to the inverter’s local controller. Grid parameters are estimated in real-time during the examination process. The efficacy of the self-security algorithm is tested using a three-phase 3-kVA SiC-MOSFET inverter and a 12-kW NHR 9410 regenerative grid emulator. The results verify that the proposed method can detect harmful PQ setpoints that can cause abnormal or unstable inverter operation.

Gursoy, Mehmetcan↗

An Active Detection Scheme for Sensor Spoofing in Grid-tied PV Systems

In this paper an active detection scheme for sensor spoofing (manipulated externally via a cyber attack) in grid-tied PV systems is discussed. The core of the proposed active detection scheme is to introduce a private (secret) watermarking signal into the control inputs of the DC-DC converter and DC-AC inverter stages to detect any malicious spoofing (manipulation) of voltage/current sensor measurements controlling both the DC-DC converter maximum power point tracking (MPPT) stage and the DC-AC inverter of the grid-tied PV system. Several types of possible spoofing mechanisms (attack models) are discussed. The proposed sensor spoofing attack detector system consists of injecting a small magnitude of digital watermarking signal (DWS) and conduct three statistical watermark tests on the reported sensor measurements to determine if a) the proposed system is healthy and operating as expected b) if sensor signals were spoofed (manipulated) externally or c) if a particular sensor is malfunctioning due to a faulty hardware. It is shown via extensive simulations that the proposed DWS approach is robust in detecting malicious external manipulation of sensors controlling the grid tied PV system. A testing platform is currently under development and the experimental results will be discussed in the conference presentation.

Ibrahim, Hasan↗

Strengthening Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Based Infrastructure

In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.

Huang, Peng-Hao↗

Hybrid Data-Driven Physics-Based Model Framework Implementation: Towards a Secure Cyber-Physical Operation of the Smart Grid

False data injection cyber-attack detection models on smart grid operation have been much explored recently, considering analytical physics-based and data-driven solutions. Recently, a hybrid data-driven physics-based model framework for monitoring the smart grid is developed. However, the framework has not been implemented in real-time environment yet. In this paper, the framework of the hybrid model is developed within a real-time simulation environment. OPAL-RT real-time simulator is used to enable Hardware-in-the-Loop testing of the framework. IEEE 9-bus system is considered as a testing grid for gaining insight. The process of building the framework and the challenges faced during development are presented. The performance of the framework is investigated under various false data injection attacks.

false data injection attack, machine learning, sta↗

A Proactive Stochastic Framework for Cyber-Physical Power Systems Security

This paper presents a framework for cyberphysical power systems security in which defensive action is proactive, striving to mitigate the harm from strategic cyber attacks before they occur. The prospect is formulated in a previously-studied context of state estimation via the Kalman filter under false data injection attacks. Assuming a cognitive attacker who is both advanced and persistent, the proactive defense rests upon stochastically influencing the sensors, Phasor Measurement Units, such that subsequent falsification attacks are countered. Examples are crafted to illustrate both the efficacy of the proactive approach in ideal situations and the practical challenges implied by non-ideal situations.

El Mezyani, Touria↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗

A Novel Framework to Quantify Power Grid Resilience

The quantification of an operating power grid’s resilience is highly significant today, given its criticality as an enabler of other infrastructures, complexity, and the threat it faces due to a wide range of detrimental events, from extreme climate to cyber attacks. Currently, there exist no standardized definitions and metrics for measuring the resilience of an operating grid. In this paper, we introduce a novel resilience quantification framework and demonstrate a method to measure the flexibility towards topological/structural changes due to potential failures in the power grid to assess operational resilience. We start with the state estimation data from a large utility and use the graph analysis methods and power flow simulation tools to compute the identified resilience parameters.

Yoginath, Srikanth↗

Robust Medium-Voltage Distribution System State Estimation using Multi-Source Data

Due to the lack of sufficient online measurements for distribution system observability, pseudo-measurements from short-term load or distributed renewable energy resources (DERs) forecasting are used. However, the accuracy of them is low and thus significantly limits the performance of distribution system state estimation (DSSE). In this paper, a robust DSSE that integrates multi-source measurement data is proposed. Specifically, the historical low-voltage (LV) side smart meters are used to forecast load and DERs injections via the support vector machine (SVM) with optimally tuned parameters. By contrast, the online smart meters at LV side are utilized to derive equivalent power injections at the MV/LV transformers, yielding more accurate pseudo-measurements compared to the forecasted injections. Furthermore, to deal with bad data caused by communication loss, instrumental errors and cyber attacks, robust DSSE that relies on generalized maximum-likelihood (GM)-estimation criterion is developed. The projection statistics are developed to adjust the weights of each measurement, leading to better balance between pseudo- and real-time measurements. Numerical results conducted on modified IEEE 33-bus system with DG integration demonstrate the effectiveness and robustness of the proposed method.

distribution system state estimation↗

VAC: A Software Approach to Resilient SCADA Automation

To better secure critical infrastructure, especially power systems, this paper introduces a virtual SCADA automation controller. The automation controller is a gateway into a power subsystem, making it a valuable target for cyber-attacks that could cut it off from the control center and cause a loss of view and control. To prevent this, the Virtual Automation Controller (VAC) is a backup device that mirrors the capabilities of the physical controller. It can communicate via Modbus and DNP3 and is containerized so it can be deployed on a variety of platforms. Furthermore, it utilizes software-defined networking to quickly disconnect a failed automation controller and preserve its state for forensics. The VAC gives system operators time to replace the failed controller and prevents dangerous and costly damage to power systems. The VAC is compared against the SEL 3505-3 RTAC and shown to have the necessary features to act as a failover controller.

Johnson, Jordan↗

A Data-Driven Democratized Control Architecture for Regional Transmission Operators

As probably the most complicated and critical infrastructure system, U.S. power grids become increasingly vulnerable to extreme events such as cyber-attacks and severe weather, as well as higher DER penetrations and growing information mismatch among system operators, utilities (transmission or generation owners), and end-users. This paper proposes a data-driven democratized control architecture considering two democratization pathways to assist transmission system operators, with a targeted use case of developing online proactive islanding strategies. Detailed discussions on load capability profiling at transmission buses and disaggregation of DER generations are provided and illustrated with real-world utility data. By Combining network and operational constraints, transmission system operators can be equipped with new tools built on top of this architecture, to derive accurate, proactive, and strategic islanding decisions to incorporate the wide range of dynamic portfolios and needs when facing extreme events or unseen grid contingencies.

Power System Reliability, Islanding, Democratized ↗