Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Hybrid Data-Driven Based HVdc Ancillary Control for Multiple Frequency Data Attacks

The high voltage direct current (HVdc) intertie has been applied to provide ancillary-services for ac grids, utilizing the real-time feedback from phasor measurement units (PMUs). However, PMU data communication is vulnerable to false data injection attacks (FDIA) due to protocol defects, thus the HVdc ancillary control and system stability will be threatened. To address this issue, this article proposes a novel HVdc control strategy based on a hybrid data-driven (HDD) methodology. In this work, the HDD methodology is first proposed to detect the types and duration time of multiple frequency attacks. Specifically, the Hilbert Huang transform (HHT) is used to decompose the frequency data, using variational mode decomposition instead of the traditional empirical mode decomposition, to extract data features. Second, a multikernel support vector machine is proposed to classify the attacked data based on the designed distinctive features from HHT. Meanwhile, the attacking duration time is decided using an unsupervised technique. Third, an HDD-based HVdc ancillary control strategy is established to eliminate the effect of FDIAs on the HVdc frequency response. Comprehensive experiments of HDD-based HVdc ancillary controls under different FDIAs suggest that the proposed HDD could fast and accurately classify the FDIAs, and the HDD-based HVdc ancillary control strategy could significantly suppress the impact of the FDIAs.

97 MATHEMATICS AND COMPUTING↗

ThunderSecure: deploying real-time intrusion detection for 100G research networks by leveraging stream-based features and one-class classification network

Nowadays, data generated by large-scale scientific experiments are on the scale of petabytes per month. These data are transferred through dedicated high-bandwidth networks (40/100G) across distributed sites for processing, storage, and analysis. Like general purpose networks, research networks experience intrusions. However, monitoring anomalies in such high-speed network traffics is challenging given current cyber-infrastructure. Moreover, traditional network intrusion detection systems (NIDS) are signature based. However, anomaly patterns are difficult to define and that rulesets are often not updated frequently enough to reflect the changes of attack behaviors. We present ThunderSecure, a high-throughput, unsupervised learning-based intrusions detection system for 100G research networks. ThunderSecure implements an efficient packet processing and detection pipeline using multi-cores and GPUs. It extracts statistical and temporal features from real-time network data streams and feeds them to a one-class anomaly detection network. A baseline of normal distribution will be created based on the training observation. Testing traffic deviated from the learned profile will be marked as anomalies. We trained ThunderSecure on hundreds of billions of science data packets mirrored from two 100G network connections at Fermi National Accelerator Laboratory. The detection performance was evaluated on traffic captured from the same research network days and weeks after the training with different types of attack flows injected. Results show that ThunderSecure can recognize science data traffic captured long after the training and made nearly certain detection on the segment of the streams where anomalous flows were injected.

100G research network↗

Net Load Redistribution Attacks on Nodal Voltage Magnitude Estimation in AC Distribution Networks

A high penetration level of smart devices and communication networks increases the threat of cyber-attacks in the distribution system. In this paper, we model a hidden, coordinated, net load redistribution attack (NLRA) in an AC distribution system. Based on local information of an attack region, the attacker’s goal is to create violations in nodal voltage magnitude estimation. Acting as a system operator equipped with global AC state estimation and bad data detection, we validate the stealthiness of the hidden NLRA in multiple attack cases. Simulation results on a modified PG&E 69-node distribution system show the validity of the proposed NLRA. The influence of NLRA on the distribution system is assessed and the impact of attack regions, attack timing, and system observability is also revealed.

Zhang, Hang↗

Adaptive, self-tuning virtual sensing system for cyber-attack neutralization

An industrial asset may have a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time representing current operation of the industrial asset. An abnormality detection computer may determine that an abnormal monitoring node is currently being attacked or experiencing a fault. An autonomous, resilient estimator may continuously execute an adaptive learning process to create or update virtual sensor models for that monitoring node. Responsive to an indication that a monitoring node is currently being attacked or experiencing a fault, a level of neutralization may be automatically determined. The autonomous, resilient estimator may then be dynamically reconfigured to estimate a series of virtual node values based on information from normal monitoring nodes, appropriate virtual sensor models, and the determined level of neutralization. The series of monitoring node values from the abnormal monitoring node or nodes may then be replaced with the virtual node values.

Abbaszadeh, Masoud↗

The NREL Sensor Laboratory Detection of Hydrogen Emissions

The development of a functional hydrogen detection system is a multifaceted process that integrates hardware, deployments strategies, and analytics which can be supported by the NREL Sensor Laboratory: 1. Support of the design, validation and optimization of sensing prototypes; 2. Guide optimized sensing element development, including control electronics; 3. Laboratory testing to validate/optimize metrological performance (measurement range, detection limit, etc.); 4. Provide test sites for field deployments representative of real-world scenarios with controlled hydrogen releases; 5. Develop sensor placement and operation guidance; 6. Provide guidance on electronics to accommodate facility integration; 7. Electrical safety designs to allow for operation within restricted zones; 8. Integration into facility monitoring and control systems; 9. Guide incorporation of cyber security elements to protect facilities from malicious attacks; 10. Modeling and application of advanced analytics to detect and quantify emissions; 11. Higher Order dispersion models to guide sensor placement for reliable detection; 12. Advanced analytics for improved metrological performances, and to inform inverse modeling; 13. Market support and commercialization (national and international markets); 14. Commercial deployments in H2@SCALE markets (e.g., HUBs and other large-scale hydrogen markets); and 15. Leverage off international collaborations/partnerships (e.g., NREL is on the advisory board for the European initiative "pre-Normative Research on Hydrogen Releases Assessment"-NHyRA).

08 HYDROGEN↗

Robust and cybersecure coordinated unintentional island detection for microgrids

Unintentional islanding (UI) of a circuit of distributed energy resources (DERs) may leave area electrical power systems (EPS), external to the DER circuit, energized. Thus, UI detection methods have been developed to detect unintentional islanding and trigger a UI response. However, individual UI detection methods have various deficiencies. Thus, a consensus-based UI detection process is disclosed that builds a consensus from multiple UI detection sources, optionally implementing different UI detection methods. The redundancy in this consensus-based UI detection process provides robust, sensitive, selective, and cybersecure UI detection for the entire DER circuit. For example, the consensus-based UI detection process may eliminate or reduce non-detection zones, avoid false positives, thwart cyber-attacks, and/or the like.

Brissette, Alex↗

Developing an AI-Powered Zero-Trust Cybersecurity Framework for Malware Prevention in Nuclear Power Plants

This study presents the development of an AI-powered Zero-Trust cybersecurity framework for malware prevention in nuclear power plants. The framework aims to enhance the security of critical systems within nuclear power plants by adopting the principles of Zero-Trust and leveraging artificial intelligence (AI) technologies. By assuming no implicit trust in any user or device and continuously authenticating and authorizing access, the framework ensures a robust defense against malware attacks. The integration of AI allows for the detection and prevention of malware through behavioral analytics, endpoint protection, network segmentation, and continuous monitoring. The paper discusses the key considerations, steps, and technologies involved in developing this framework, emphasizing the importance of regular updates, training, compliance, and auditing. The proposed framework serves as a comprehensive approach to safeguarding nuclear power plants from sophisticated malware threats and protecting the integrity and safety of critical infrastructure.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Generating and Analyzing Program Call Graphs using Ontology

Call graph or caller-callee relationships have been used for various kinds of static program analysis, performance analysis and profiling, and for program safety or security analysis such as detecting anomalies of program execution or code injection attacks. However, different tools generate call graphs in different formats, which prevents efficient reuse of call graph results. In this paper, we present an approach of using ontology and resource description framework (RDF) to create knowledge graphs for specifying call graphs to facilitate the construction of full-fledged and complex call graphs of computer programs, realizing more interoperable and scalable program analyses than conventional approaches. We create a formal ontology-based specification of call graph information to capture concepts and properties of both static and dynamic call graphs so different tools can collaboratively contribute to more comprehensive analysis results. Our experiments show that ontology enables merging of call graphs generated from different tools and flexible queries using a standard query interface. Index Terms—Callgraph, ontology, knowl

Dorta, E.↗

Anomaly Detection and Mitigation for Dynamic Frequency Regulation in Hydropower-Battery Systems

Hydropower operators and energy storage providers are increasingly interested in participating in frequency regulation services, driven by the incentives offered by independent system operators, such as the PJM Interconnection. This transition, however, unfolds against the backdrop of a modernizing and rapidly digitizing power grid, exposing the integrated legacy infrastructure to a multitude of cybersecurity threats. This work presents an approach for developing an anomaly detection and mitigation system to address cybersecurity challenges during the participation of a hydropower-integrated battery energy storage system (BESS) in a frequency regulation market. The applied anomaly detector utilizes machine learning algorithms to provide detailed classification of cyber-physical events. Later, the applied mitigation system triggers predefined corrective actions to minimize the impact of data integrity attacks on the regulation market and system stability. We evaluated the proposed approach on a hydropower-integrated BESS topology, specifically analyzing the slow regulation signal (Reg A) coming from the PJM market. Our simulation results demonstrate that the proposed approach performs well in detecting data integrity attacks within the allocated time frame and also minimizes the system's transient instability during the participation of hydropower and BESS in the regulation market.

battery energy storage system↗

Anomaly Detection and Mitigation for Dynamic Frequency Regulation in Hydropower-Battery Systems: Preprint

Hydropower operators and energy storage providers are increasingly interested in participating in frequency regulation services, driven by the incentives offered by independent system operators, such as the Pennsylvania-New Jersey-Maryland Interconnection (PJM), in a competitive electricity market. This transition, however, unfolds against the backdrop of a modernizing and rapidly digitizing power grid, exposing the integrated legacy infrastructure and vulnerable communication networks to a multitude of cybersecurity threats. These evolving threats not only endanger grid operations but also have the potential to trigger cascading disruptions across the broader grid network and influence regulation markets. This work presents an approach for developing an anomaly detection and mitigation system to address cybersecurity challenges during the participation of a hydropower-integrated battery energy storage system (BESS) in a frequency regulation market. The applied anomaly detector utilizes machine learning algorithms to provide detailed classification of cyber-physical events and provide a comprehensive situation awareness to grid operators. Later, the applied mitigation system triggers predefined corrective actions to minimize the impact of data integrity attacks on the regulation market and system stability. We evaluated the proposed approach on a fully active BESS topology using the slow regulation signal (Reg A) coming from the PJM market. Our simulation results reveal that the proposed approach performs well in detecting data integrity attacks within the allocated time frame and also minimizes the system's instability and economic loss during the participation of hydropower and BESS in the regulation market.

battery energy storage system↗

Attack-Resilient Weighted $\ell_{1}$ Observer with Prior Pruning

Security related questions for Cyber Physical Systems (CPS) have attracted much research attention in searching for novel methods for attack-resilient control and/or estimation. Specifically, false data injection attacks (FDIAs) have been shown to be capable of bypassing bad data detection (BDD), while arbitrarily compromising the integrity of state estimators and robust controller even with very sparse measurements corruption. Moreover, based on the inherent sparsity of pragmatic attack signals, ℓ1 -minimization scheme has been used extensively to improve the design of attack-resilient estimators. For this, the theoretical maximum for the percentage of compromised nodes that can be accommodated has been shown to be 50%. In order to guarantee correct state recoveries for larger percentage of attacked nodes, researchers have begun to incorporate prior information into the underlying resilient observer design framework. For the most pragmatic cases, this prior information is often obtained through some data-driven machine learning process. Existing results have shown strong positive correlation between the tolerated attack percentages and the precision of the prior information. In this paper, we present a pruning method to improve the precision of the prior information, given corresponding stochastic uncertainty characteristics of the underlying machine learning model. Then a weighted ℓ1 -minimization is proposed based on the pruned prior. The theoretical and simulation results show that the pruning method significantly improves the observer performance for much larger attack percentages, even when moderately accurate machine learning model used.

Resilient observer, Cyber-physical systems, prunin↗

Strengthening Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Based Infrastructure

In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.

Huang, Peng-Hao↗

Time-Based CAN Intrusion Detection Benchmark

Modern vehicles are complex cyber-physical systems made of hundreds of electronic control units (ECUs) that communicate over controller area networks (CANs). This inherited complexity has expanded the CAN attack surface by the injection of malicious messages that vary their time-based characteristics. To detect these malicious messages, time-based intrusion detection systems (IDS) have been proposed. However, time-based IDS are usually trained and tested on low-fidelity datasets with unrealistic labeled attacks. This makes difficult the task of evaluating, comparing, and validating IDS. Here we detail and benchmark four time-based IDS in a dataset with real and advanced attacks. We found that methods with strong assumptions regarding the distribution of inter-arrival times have lower performance than distribution agnostic based methods. In particular, distribution agnostic based methods outperform distribution based methods at least on $55\%$ in area under the precision-recall (AUC-PR) curve. Our results expand the body of knowledge of CAN time-based IDS by providing details of these methods and reporting their results when tested on datasets with real and advanced attacks. We describe limitations, open challenges, and how lessons learnt from this research can inform the design of deployable time-based IDS in modern vehicles.

Blevins, Deborah↗

Designing an Intrusion Detection for an Adjustable Speed Drive System Controlling a Critical Process

In this article, we address the cyber-security problem of industrial control systems (ICSs) when their sensor measurements may be compromised due to an attacker who has intercepted those measurements via a network. We introduce a general-purpose method “Dynamic Watermarking (DW)” to detect potential cyber-intrusions on speed sensor measurements within industrial control systems, which deploy an adjustable speed drive (ASD) to control a critical process. The DW method is injecting a random private low-amplitude signal with a zero mean Gaussian distribution, “watermark”, into one of the input phase voltages powering the ASD system. The watermark signal propagates through the system including pulse width modulation (PWM) power conversion stage and motor, then ultimately appears in the speed sensor measurements. By deploying two statistical DW tests with two proper thresholds, the system can detect potential cyber-intrusions or unobservable cyber-attacks such as replay attacks and false data injection attacks (FDIA). The DW method tested on a laboratory-scale ASD system experimentally to protect the system against cyber-intrusions. This system, powered by a commercial PWM drive operating at 208 V, 3-phase, and 3.7 kW, served as our experimental platform.

42 ENGINEERING↗

Failure detection and fault management techniques for flush airdata sensing systems

A high-angle-of-attack flush airdata sensing system was installed and flight tested on the F-18 High Alpha Research Vehicle at NASA-Dryden. This system uses a matrix of pressure orifices arranged in concentric circles on the nose of the vehicle to determine angles of attack, angles of sideslip, dynamic pressure, and static pressure as well as other airdata parameters. Results presented use an arrangement of 11 symmetrically distributed ports on the aircraft nose. Experience with this sensing system data indicates that the primary concern for real-time implementation is the detection and management of overall system and individual pressure sensor failures. The multiple port sensing system is more tolerant to small disturbances in the measured pressure data than conventional probe-based intrusive airdata systems. However, under adverse circumstances, large undetected failures in individual pressure ports can result in algorithm divergence and catastrophic failure of the entire system. How system and individual port failures may be detected using chi sq. analysis is shown. Once identified, the effects of failures are eliminated using weighted least squares.

Whitmore, Stephen A.↗

A Review of Cyber-Physical Security for Photovoltaic Systems

In this paper, the challenges and a future vision of the cyber-physical security of photovoltaic (PV) systems are discussed from a firmware, network, PV converter controls, and grid security perspective. The vulnerabilities of PV systems are investigated under a variety of cyber-attacks, ranging from data integrity attacks to software-based attacks. A success rate metric is designed to evaluate the impact and facilitate decision making. Model-based and data-driven methods for threat detection and mitigation are summarized. In addition, the blockchain technology that addresses cyber-attacks in software and cyber networks is described. Simulation and experimental results that show the impact of cyber-attacks at the converter (device) and grid (system) levels are presented. Finally, potential research opportunities are discussed for next-generation, cyber-secure power electronics systems. These opportunities include multi-scale controllability, self-/event-triggering control, artificial intelligence/machine learning, hot patching, and online security. As of today, this study will be one of the few comprehensive studies in this emerging and fast-growing area.

14 SOLAR ENERGY↗

Device-Centric Firmware Malware Detection for Smart Inverters using Deep Transfer Learning

Since future power grids are inverter-dominant grids and inverters are getting smarter by incorporating remote access and seamless firmware update, it is anticipated that malware attackers will directly target smart inverters. However, malware threats targeting smart inverters have been less studied yet. This paper explores potential malware attacks targeting smart inverters and proposes a deep transfer-learning (DTL)-based malware detection framework for smart inverters. The proposed DTL method can significantly reduce development time and efforts for an artificial intelligence-based malware detection algorithm while improving detection accuracy. The experimental result shows that the proposed method achieves 98% of firmware malware detection accuracy. Furthermore, this approach will be transformative to other smart grid devices enabling seamless firmware update.

artificial intelligence↗

Autonomous reconfigurable virtual sensing system for cyber-attack neutralization

An industrial asset may be associated with a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time representing current operation of the industrial asset. An abnormality detection computer may determine that at least one abnormal monitoring node is currently being attacked or experiencing a fault. A virtual sensing estimator may continuously execute an adaptive learning process to create or update virtual sensor models for the monitoring nodes. Responsive to an indication that a monitoring node is currently being attacked or experiencing a fault, the virtual sensing estimator may be dynamically reconfigured to estimate a series of virtual node values for the abnormal monitoring node or nodes based on information from normal monitoring nodes and appropriate virtual sensor models. The series of monitoring node values from the abnormal monitoring node or nodes may then be replaced with the virtual node values.

97 MATHEMATICS AND COMPUTING↗