Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

An Interior-Point Solver for Optimal Power Flow Problem Considering Distributed FACTS Devices

In this paper, we propose an AC optimal power flow (ACOPF) model considering distributed flexible AC transmission system (D-FACTS) devices, in which the reactance of D-FACTS equipped lines are introduced as decision variables. This is motivated by increasing interests in using D-FACTS devices to address system operational and cyber-security concerns. First, D-FACTS devices can be incorporated in real-time operations for economic benefits such as managing power congestions and reducing system losses. Second, D-FACTS devices can be utilized by moving target defense (MTD), an emerging concept against cyber-attacks, to prevent attackers from knowing true system configurations. Therefore, system operators can use the proposed ACOPF model to achieve economic benefits and provide the setpoints of D-FACTS devices for MTD at the same time. In addition, we rigorously derive the gradient and Hessian matrices of the objective function and constraints, which are further used to build an interior-point solver of the proposed ACOPF. Numerical results on the IEEE 118-bus transmission system show the validity of the proposed ACOPF model as well as the efficacy of the interior-point solver in minimizing system losses and generation costs.

Liu, Bo↗

Cyber-Physical Security and Resiliency Analysis Testbed for Critical Microgrids with IEEE 2030.5: Preprint

IEEE 2030.5, also known as the Common Smart Inverter Standard (CSIP) is a protocol that specifies the interface between the end user and the smart grid. This standard was proposed recently, and provides many functions which if implemented incorrectly might lead to vulnerabilities. This paper proposes a cyber-physical microgrid testbed using OpenDSS and IEEE 2030.5 that can be used to study the performance of the CSIP protocol various scenarios. For critical microgrid installations, it is essential that the critical loads are served in spite of multiple contingencies. A resiliency analysis is performed for a military microgrid to study its performance and the results are analyzed.

CVSS↗

Reconfigurable Network Slicing Orchestration in Network Function Virtualization Compatible Operational Technology Environment

The ongoing transition to Industry 4.0, which is characterized by increased inter-connectivity of cyber-physical systems, requires having time-sensitive, high throughput, and secure transfer of critical data in industrial sites. In this context, network slicing emerges as a critical tool to ensure timely data delivery by provisioning the network resources to cater to specific applications’ requirements and mitigating potential cyber attacks. To address these challenges, this paper aims to tackle two key questions essential for the successful implementation of network slicing in industrial environments. First, it investigates architectural considerations for developing a network infrastructure capable of supporting network slicing functionalities effectively. The proposed approach significantly improves deployment efficiency over traditional manual configurations. Second, it delves into the automated orchestration process, elucidating the steps and components involved in transitioning from a static network management approach to dynamically leverage network function virtualization schemes for creating network slices in ad-hoc manner. The system demonstrates high throughput suitable for production-level solutions and maintains exceptionally low latency, making it ideal for ultra-reliable low-latency communications. Even with increased network demands, the system remains stable, with effective Quality of Service (QoS) management, ensuring reliable performance under varying conditions. The proposed architecture outlines the necessary components, services, and communication protocols required for a production-level orchestrator for network segmentation in SCADA environments.

Rodiles Delgado, Brian G.↗

Pulsar Based Timing for Grid Synchronization

Existing synchronization systems in the power grid, such as the global positioning system, are susceptible to temporary or permanent failures due to various unpredictable and uncontrollable factors such as cyber-attack and electromagnetic interferences, thus affecting the accuracy and reliability of generated timing signal. In this article, a pulsar astronomy-based timing system is proposed to provide an alternative synchronization signal. Further, this clock will offer significant security improvements to power grid applications, such as a wide-area monitoring system, which depends on a precise timing signal. The hardware and software frameworks are described in detail. First, a high-speed sampling hardware platform is designed to collect signals from radio telescopes. Then a periodic pulse extraction method with three steps is proposed to process the pulsar signal, including polyphase filterbanks, incoherent de-dispersion, and sliding window folding. Lastly, three experiments are conducted to verify the effectiveness of the frameworks. The generated pulsar timing pulse is presented, and the factors affecting its accuracy are also discussed. The analysis results demonstrate that the pulsar signals can provide high-accurate timing pulses for grid synchronization.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING↗

Framework for Analysis and Quantification of Wide-Area Control Resilience for Power Systems

Wide-area control helps damp the inter-area oscillations in modern power systems. However, compared to traditional local control, it is more vulnerable to cyber attacks due to its dependence on remote real-time-communicated measurements. In this paper, a formal mathematical framework for analyzing resilience of various wide-area controllers under adversarial scenarios is proposed. A novel resilience index based on the $\H_2$ norm of the post-attack closed-loop system is defined. Computation of such an index is, in general, challenging due to the combinatorial nature of the attack profiles and the bilinear nature of the problem. To address these difficulties, a gradient-based path-following-like solution is developed in this paper to solve a relaxed version of the original non-convex problem. Case studies on IEEE 39-bus system are performed to demonstrate the usage of the proposed framework.

Marinovici, Laurentiu D.↗

Employing Interacting Qubits for Distributed Microgrid Control

To empower flexible and scalable operations, distributed control of multi-inverter microgrids, based on classical communication networks among distributed energy resources, has attracted considerable attention as it can guarantee synchronization and provide suitable remedies to the problem of improper power sharing. Notwithstanding this, resilience of the current schemes on classical communication makes microgrids vulnerable to cyber attacks. Inspired by recent revolutionary breakthroughs in quantum communication, in this paper, we devise a novel synchronization mechanism. We extend the synchronization framework utilized in distributed control algorithms to networks of quantum systems by generating pinning terms and coupling mechanism for the new synchronization rule via exploiting proper quantum jump operators and observables, and show that the quantum system will converge to a time-variant target state. Our devised quantum distributed controller (QDC) gives rise to a novel quantum communication scheme for distributed control of microgrids and enables microgrids to exploit the state-of-the-art quantum communication frameworks as communication infrastructure. Finally, test results on two representative AC and DC networked microgrids validate the efficacy and universality of the quantum distributed control.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Anomaly Detection and Mitigation for Wide-Area Damping Control using Machine Learning

In an interconnected multi-area power system, wide-area measurement based damping controllers are used to damp out inter-area oscillations, which jeopardize grid stability and constrain the power flows below to their transmission capacity. The effect of wide-area damping control (WADC) significantly depends on both power and cyber systems. At the cyber system layer, an adversary can inflict the WADC process by compromising either measurement signals, control signals or both. Stealthy and coordinated cyber-attacks may bypass the conventional cybersecurity measures to disrupt the seamless operation of WADC. This paper proposes an anomaly detection (AD) algorithm using supervised Machine Learning and a model-based logic for mitigation. The proposed AD algorithm considers measurement signals (input of WADC) and control signals (output of WADC) as input to evaluate the type of activity such as normal, perturbation (small or large signal faults), attack and perturbation-and-attack. Upon anomaly detection, the mitigation module tunes the WADC signal and sets the control status mode as either wide-area mode or local mode. The proposed anomaly detection and mitigation (ADM) module works inline with the WADC at the control center for attack detection on both measurement and control signals and eliminates the need for ADMs at the geographically distributed actuators. Here, we consider coordinated and primitive data-integrity attack vectors such as pulse, ramp, relay-trip and replay attacks. The performance of the proposed ADM algorithms was evaluated under these attack vector scenarios on a testbed environment for 2-area 4-machine power system. The ADM module shows effective performance with 96:5% accuracy to detect anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Multi-Source Data Aggregation and Real-Time Anomaly Classification and Localization in Power Distribution Systems

This paper proposes a real-time anomaly location and classification framework for power distribution systems to simultaneously determine the type of anomaly (i.e., short-circuit fault, cyber attack, DER switching) and its location. The proposed framework employs the data aggregation module to collect the measurement data from multiple field devices operating at different sampling rates, such as protection relays and D-PMUs. The output of the data aggregation is then fed into a multi-task learning-based long-based short-term memory (MTL-LSTM) to classify the type of anomaly and the location in two separate tasks. The proposed MTL-LSTM approach can be utilized in real-time operation in order to distinguish between normal and several anomalous operations and locate the anomaly. The proposed framework is tested on a modified IEEE 33-bus test feeder benchmark that integrates solar generation and energy storage. Furthermore, the results show that the proposed framework can locate and classify anomalies for several operation conditions with more than 96% accuracy. Further experiments highlight the impact of aggregating multiple sources of data on the performance of the proposed model.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilient Control of Networked Microgrids Using Vertical Federated Reinforcement Learning: Designs and Real-Time Test-Bed Validations

Improving system-level resiliency of networked microgrids against adversarial cyber-attacks is an important aspect in the current regime of increased inverter-based resources (IBRs). To achieve that, this paper contributes in designing a hierarchical control layer, in conjunction with the existing control layers, resilient to adversarial attack signals. Considering model complexities, unknown dynamical behaviors of IBRs, and privacy issues regarding data sharing in multi-party-owned microgrids, designing such a control layer is non-trivial. Here, to tackle these issues, a novel federated reinforcement learning (Fed-RL) method is proposed. To grasp the interconnected dynamics of networked microgrids, the paper develops Federated Soft Actor-Critic (FedSAC) algorithm following the vertical structure of implementing Fed-RL. Next, utilizing the OpenAI Gym interface, we built a custom set-up in GridLAB-D/HELICS co-simulation platform, named Resilient RL Co-simulation (ResRLCoSIM), to train the RL agents with IEEE 123-bus benchmark comprising 3 interconnected microgrids. Finally, the learned policies in the simulation are transferred to the real-time hardware-in-the-loop (HIL) test-bed developed using the high-fidelity Hypersim platform. Finally, experiments show that the simulator-trained RL controllers achieve desirable performance with the test-bed platform, validating the minimization of the sim-to-real gap.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multi-Segment Decentralized Control Strategies for Renewables-Rich Microgrids in Extreme Conditions

Microgrids provide a promising approach to accommodating various distributed energy resources (DERs), while requiring significant communication infrastructures that may be affected by extreme conditions such as natural disasters and cyber-attacks. In this paper, a fully decentralized control strategy without the need for communication is proposed for islanded microgrids with high renewables penetration. First, special multi-segment power/frequency characteristic curves are designed, so that different DERs can be automatically coordinated in a prioritized manner such as renewables first to maintain power balance while DER frequencies are regulated at their reference values. Second, piecewise linear served load versus frequency models are designed to prioritize loads according to their significance, so that only noncritical loads will be curtailed as needed while critical loads are supplied without any interruptions during power deficiency. The proposed strategy can effectively deal with various normal and extreme system conditions including 100% renewables penetration, loads and renewables variations, power deficiencies requiring load curtailments, disconnection of existing DERs, connection of new DERs as well as network sectionalization and reconfiguration. As a result, the proposed control strategy is validated in the real-time digital simulator (RTDS) model of the IIT Campus Microgrid to demonstrate its effectiveness in enhancing the resiliency of renewables-rich microgrids in extreme conditions.

24 POWER TRANSMISSION AND DISTRIBUTION↗

K-anonymity applied to the energy grid of things distributed energy resource management system

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. As information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacypreserving, trust-augmented secure scheme for a smart grid implementation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Stealthy Cyber Anomaly Detection On Large Noisy Multi-material 3D Printer Datasets Using Probabilistic Models

As Additive Layer Manufacturing (ALM) becomes pervasive in industry, its applications in safety critical component manufacturing are being explored and adopted. However, ALM's reliance on embedded computing renders it vulnerable to tampering through cyber-attacks. Sensor instrumentation of ALM devices allows for rigorous process and security monitoring, but also results in a massive volume of noisy data for each run. As such, in-situ, near-real-time anomaly detection is very challenging. The ideal algorithm for this context is simple, computationally efficient, minimizes false positives, and is accurate enough to resolve small deviations. In this paper, we present a probabilistic-model-based approach to address this challenge. To test our approach, we analyze current measurements from a polymer composite 3D printer during emulated tampering attacks. Our results show that our approach can consistently and efficiently locate small changes in the presence of substantial operational noise.

Yoginath, Srikanth↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗

Peer-to-Peer Energy Management System for Distributed Microgrid Coordination [SWR-21-92]

Resiliency is one of the key challenges in today's power system. Natural disasters and cyber-attacks both can limit communications between microgrids and the central management system. Thus, having a Distributed Microgrid Coordination (DMC) algorithm can improve the system resiliency, which enables the microgrids to operate without communication with the central management system. Peer-to-Peer Energy Management System for Distributed Microgrid Coordination adopts a primal-dual approach, where each microgrid controller keeps a local estimate of the dual variables. The estimate is updated with local measurements and peer-to-peer communication, leading to a fully distributed algorithm. While the DMC is developed for microgrid coordination, it can be used for general distributed control purpose.

Li, Yashen↗

Reinforcement Learning for Distribution Grid Optimization (PyCIGAR) v0.1

PyCIGAR is a python software package that merges off-the-shelf reinforcement learning libraries (RLLib and Ray) with electric power distribution system simulation tools (OpenDSS and a custom power flow solver built by LBL). PyCIGAR enables the training of neural networks to optimize the behavior of different components in the electric distribution grid, such as control systems in photovoltaic rooftop solar inverters and electric battery storage systems. The software package has been used to train neural networks to update settings in photovoltaic rooftop solar inverter control systems to mitigate cyber attacks on other solar photovoltaic rooftop devices.

Arnold, Daniel↗

Cyote Research Tool Library

The software is a library of individual proof-of-concept tools to be further developed in research efforts with partner utilities to detect indicators of Cyber Attacks within the Operational Technology Environments.

Wellman, LawrenceR.↗