Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Experimental Setup for Grid Control Device Software Updates in Supply Chain Cyber-Security

Supply chain cyberattacks that exploit insecure third-party software are a growing concern for the security of the electric power grid. These attacks seek to deploy malicious software in grid control devices during the fabrication, shipment, installation, and maintenance stages, or as part of routine software updates. Malicious software on grid control devices may inject bad data or execute bad commands, which can cause blackouts and damage power equipment. This paper describes an experimental setup to simulate the software update process of a commercial power relay as part of a hardware-in-the-loop simulation for grid supply chain cyber-security assessment. The laboratory setup was successfully utilized to study three supply chain cyber-security use cases.

Keller, Joseph↗

Advancing Cyber-Attack Detection in Power Systems: A Comparative Study of Machine Learning and Graph Neural Network Approaches

This paper explores the detection and localization of cyber-attacks on power systems, focusing on comparing conventional machine learning (ML) and deep learning methods, and graph neural network (GNN)-based techniques. We assess the detection accuracy of these approaches and their potential to pinpoint the locations of specific buses under attack. Given the demonstrated success of GNNs in other time series anomaly detection applications, we aim to evaluate their performance within the context of power systems cyber-attack. Utilizing the IEEE 68-bus system, we simulated four types of attacks to test the selected approaches. Our results indicate that GNN-based methods outperform conventional machine learning and deep learning models in detection. Additionally, GNNs show promise in accurately localizing attacks for simple scenarios, although they still face challenges in more complex cases.

artificial intelligence↗

Achieving Runtime State Verification Assurance in Critical Cyber-Physical Infrastructures

Industrial Cyber-Physical Systems (ICPS) are an essential backbone of national critical infrastructures. They help monitor and control crucial cyber-enabled services such as energy generation. Commonly ICPS monitors the physical process through Supervisory Control and Data Acquisition (SCADA) systems. The SCADA ecosystem takes critical real-time and future system operational decisions based on the runtime state behavior of field sensors. Traditional SCADA systems use legacy and insecure communication protocols such as the Modbus protocol that lack adequate security mechanisms to provide robust runtime state behavior assurance of constrained field sensors. Therefore, constrained field sensors are commonly vulnerable to standard semantic attacks that gradually change the behavior state of infected devices. This paper discusses process integrity assurance techniques necessary to enhance the security of behavior-based protocols such as the Modbus protocol. The Runtime State Verification (RSV) protocol proposed in this paper aims to address semantic attacks in the SCADA ecosystem by integrating behavior-based Mandatory Results Automata (MRA) and a Hyperledger Fabric (HLF) network. The RSV protocol provides high process integrity assurance through enhanced behavior-based MRA suitable for the constrained field devices. A proof of concept of the RSV protocol has been evaluated in an emulated water-tube boiler. Preliminary evaluations of the RSV protocol aimed to measure the efficiency of the proposed protocol by monitoring an Combustion Efficiency (CE) process necessary to preserve optimal combustion, thus minimizing costs and future maintenance of water-tube boilers. We analyze the overall network overhead and latency of the proposed RSV protocol by evaluating the HLF network performance and comparing the proposed RSV protocol with the state-ofart BloSPAI protocol. Through the preliminary evaluations of the proposed RSV protocol, this paper demonstrates that the proposed RSV protocol overcomes the shortcomings and network overhead of the BloSPAI protocol by integrating behavior-based authentication through novel MRAs and HLF networks.

Rivera, Abel Gomez↗

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING↗

Game-Theoretic Strategies for Cyber-Physical Infrastructures Under Component Disruptions

In this work, networked infrastructures of recursively defined systems composed of discrete cyber and physical components are considered. The components of basic systems at the finest levels can be disrupted by cyber or physical means, and can be reinforced to survive at certain costs. A problem of ensuring the infrastructure performance is formulated as a game between a provider and an attacker, who probabilistically choose components to reinforce and attack, respectively. The disruptions of this infrastructure are characterized using the aggregate failure correlation function that specifies the conditional failure probability of the infrastructure given the failure of an individual system at that level. The survival probabilities of basic systems satisfy simple product-form, first-order differential equations expressed in terms of the multiplier functions. The utility functions of the provider and attacker are composed of the reward and cost terms, both expressed in terms of the component reinforcement and attack probabilities. The Nash equilibrium of this game is characterized, along with the sensitivity functions of the survival probabilities of basic systems that highlight their dependence individually on the cost-benefit terms, the correlation functions, and the multiplier functions. These results are illustrated using simplified models of a distributed cloud servers infrastructure, a 5G data network infrastructure, a high performance computing federation, and a smart energy grid infrastructure.

42 ENGINEERING↗

A Cyber-Physical Anomaly Detection for Wide-Area Protection Using Machine Learning

Wide-area protection scheme (WAPS) provides system-wide protection by detecting and mitigating small and large-scale disturbances that are difficult to resolve using local protection schemes. As this protection scheme is evolving from a substation-based distributed remedial action scheme (DRAS) to the control center-based centralized RAS (CRAS), it presents severe challenges to their cybersecurity because of its heavy reliance on an insecure grid communication, and its compromise would lead to system failure. This article presents an architecture and methodology for developing a cyber-physical anomaly detection system (CPADS) that utilizes synchrophasor measurements and properties of network packets to detect data integrity and communication failure attacks on measurement and control signals in CRAS. The proposed machine leaning-based methodology applies a rules-based approach to select relevant input features, utilizes variational mode decomposition (VMD) and decision tree (DT) algorithms to develop multiple classification models, and performs final event identification using a rules-based decision logic. Here, we have evaluated the proposed methodology of CPADS using the IEEE 39 bus system for several performance measures (accuracy, recall, precision, and F-measure) in a cyber-physical testbed environment. Furthermore, our experimental results reveal that the proposed algorithm (VMD-DT) of CPADS outperforms the existing machine learning classifiers during noisy and noise-free measurements while incurring an acceptable processing overhead.

24 POWER TRANSMISSION AND DISTRIBUTION↗

FEMP Cyber Security Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools.

Gourisetti, Sri Nikhil Gupta↗

FEMP Cyber Security Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. This is an upgrade of the tools available from the earlier version in DOE CODE ID: #41457

Gourisetti, Sri Nikhil Gupta↗

Cyber Informed Engineering Cie Analysis Tool

Main Benefits: • Collaborate on assessment via the web and access and share assessments on your mobile device. • Helps you maximize your cybersecurity investment and resources • Saves you significant time and money by eliminating the requirement to research each government and industry standard in order to understand your cybersecurity posture • Contains easy to follow, step by step instructions to guide you through the process of identifying the cybersecurity posture of your organization • Provides a place to begin with cybersecurity improvement and a way to prioritize your tasks and budgets. • Covers all major cyber relevant topic areas for a comprehensive assessment of your organization’s cybersecurity posture. • Dives deep into the details of each topic area. • Contributes to the organization's risk management and decision-making process • Highlights vulnerabilities and gaps in your organization's IT and control systems. • Raises awareness and facilitates discussion on cybersecurity within your organization • Educates the controls system community on cyber security.

Hansen, Barry [Idaho National Laboratory (INL), Id↗

CIEPAT (Cyber-Informed Engineering Photovoltaic Analysis Tool) [SWR-25-171]

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

Etigowni, Sriharsha [National Laboratory of the Ro↗

CIECAT (Cyber-Informed Engineering Commercial Buildings Analysis Tool) [SWR-25-172]

The Cyber-Informed Engineering Commercial Buildings Analysis Tool (CIECAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Commercial Buildings by incorporating Cyber-Informed Engineering (CIE) principles into the Commercial Buildings.

Etigowni, Sriharsha [National Laboratory of the Ro↗

Cyber-CHAMP Task Analysis Survey Tool

Cyber-CHAMP Task analysis survey tool is a web-hosted code platform for an individual to select their every day tasking, based on industry documentation and standards, and produce an education and training mapping to provide them the proper associated cyber competency level(s).

Stailey, ShaneD.↗

Cyber Resilience as a Deterrence Strategy

This paper was written by the Cyber Deterrence and Resilience Strategic Initiative in partnership with the Resilience Energy Systems Strategic Initiative. Resilience and deterrence are both part of a comprehensive cyber strategy where tactics may overlap across defense, resilience, deterrence, and other strategic spaces. This paper explores how building resiliency in cyberspace can not only serve to strengthen the defender's posture and capabilities in a general sense but also deter adversaries from attacking.

97 MATHEMATICS AND COMPUTING↗

Time Series Dimension Reduction for Surrogate Models of Port Scanning Cyber Emulations

Surrogate model development is a key resource in the scientific modeling community for providing computational expedience when simulating complex systems without loss of great fidelity. The initial step to development of a surrogate model is identification of the primary governing components of the system. Principal component analysis (PCA) is a widely used data science technique that provides inspection of such driving factors, when the objective for modeling is to capture the greatest sources of variance inherent to a dataset. Although an efficient linear dimension reduction tool, PCA makes the fundamental assumption that the data is continuous and normally distributed. Thus, it provides ideal performance when these conditions are met. In the case for which cyber emulations provide realizations of a port scanning scenario, the data to be modeled follows a discrete time series function comprised of monotonically increasing piece-wise constant steps. The sources of variance are related to the timing and magnitude of these steps. Therefore, we consider using XPCA, an extension to PCA for continuous and discrete random variates. This report provides the documentation of the trade-offs between the PCA and XPCA linear dimension reduction algorithms, for the intended purpose to identify key components of greatest variance in our time series data. These components will ultimately provide the basis for future surrogate models of port scanning cyber emulations.

97 MATHEMATICS AND COMPUTING↗

Tailored Cyber Strategies for the 21st Century (Summary Report)

On December 9, 2020, Sandia National Laboratories (SNL) convened a diverse set of voices from across the federal government, the United States (U.S.) military, the private sector, and national laboratories to understand current and future trends affecting our national cyber strategy, and to illuminate the role of Federally Funded Research and Development Centers (FFRDCs) in contributing to national cyber strategy objectives.

97 MATHEMATICS AND COMPUTING↗

Evaluating China's Road to Cyber Super Power

This report examines open source, non-classified qualitative analysis to evaluate China’s current cyber maturity. Evidence for this document draws on materials from academia, private cybersecurity companies, and national security research institutions. Private sector threat intelligence firms produce high quality analysis on Chinese APTs tactics, techniques, and procedures (TTPs), and investigation from companies such as FireEye illuminate China’s ability to wield cyber means for its security ends. None of the materials cited in this assessment originate from classified United States or foreign government sources. Any references to United States government sources are sourced entirely to unclassified information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber-Physical Dynamic System (CPDS) Modeling for Frequency Regulation and AGC Services of Distributed Energy Resources

The substantial integration of renewable energy brings significant challenges to balance the system in real time because of the variability and intermittency of renewable power. For the reliable system operation, the frequency regulation service is used to stabilize the system frequency through automatically balancing the system generation and load. On one hand, with the substantially increasing deployment of renewable energy in electricity system, the requirement of frequency regulation (FR) services increases significantly. On the other hand, the current main resource of FR services, the controllable conventional generation, is continuously decreasing in the system generation mix. This means that in the future high renewable penetration power system, additional and alternative reliable FR services providers such as distributed energy storage (DES) resources should be explored. Although the capability of utility-scale energy storage to provide FR services has been demonstrated, the integrated control and dynamic modeling of distributed energy resource (DER) providing frequency regulation grid services has been rarely explored. There are several challenges to adopt DERs to provide reliable grid services as illustrated in FERC 755. First, the distributed installation of DES requires a comprehensive cyber-physical dynamic system (CPDS) modeling to fully consider the impacts of the communication latency variability on its real time FR provision capability. Unlike the conventional generators, there are two-layer communication between DERs and system operators which increase the communication delay. Second, unlike the conventional generators whose dynamic models have been comprehensively studied, the difference among individual DER components' power-dynamic characteristic brings challenges in the accurate dynamic AGC modeling of its power-frequency relationship. Third, the temporal dependent state of charge uncertainty of DERs challenges DERs' power and frequency regulation capacities scheduling in the look-ahead generation scheduling. Therefore, the aggregator should optimize the frequency regulation provision from individual DER in real time. To overcome these challenges, this project proposes a cyber-physical dynamic system (CPDS) model to handle the uncertainty of DERs two-layer communication latency and power dynamics. The variability of DERs' communication delay and dynamic constraints will be comprehensively modeled. The DERs' AGC model with communication delay is designed to validate DESs' frequency regulation services. Like current performance-based frequency regulation evaluation, the delivery of DERs' frequency regulation will be assessed through post-analysis of the actual AGC response with respect to the AGC control signal from system operators. Consequently, the reliability improvement with DERs providing reliable frequency regulation services can be evaluated from a comprehensive perspective considering all the dynamics of communication and power.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Situational Awareness of Grid Anomalies (SAGA) for Visual Analytics—Near-Real-Time Cyber-Physical Resiliency Through Machine Learning

The Situational Awareness of Grid Anomalies (SAGA) project built upon foundational power system tools developed at the National Renewable Energy Laboratory (NREL) integrated with an ever-increasing set of Gridmetrics data extracted from the cable television (CATV) broadband network infrastructure while assimilating other time-series geospatial data and information, such as weather and cyber-physical phenomena, to demonstrate a disruptive technology for power system data analytics relying on existing infrastructure. Three research thrusts supported (1) visual analytics, (2) cyber-physical power system simulation, and (3) anomaly detection. SAGA created technology that leverages, couples, and fortifies two vastly different realms - power and broadband - to increase the resiliency of the power grid in the face of increasing cyberattacks and operational challenges related to integrating DERs. The exploration of potential synergies of broadband-enabled grids resulted in identifying a mutually beneficial symbiosis that can increase the resiliency of both power and broadband services. Broadband networks perform better with reliable power and are good at providing real-time measurements that identify where the grid is under attack, is failing, or is weak. Likewise, sensor-starved distribution grids perform better and can be more reliable when their operation is buttressed with observations of broadband-detected anomalies. Future research can explore broadband's contribution to continuing to improve grid resiliency, reliability, and cost-effective operation.

24 POWER TRANSMISSION AND DISTRIBUTION↗