Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber for Manufacturing [slides]

Protecting sensitive information is the number one national security challenge facing the United States. The US Manufacturing Industrial Base (MIB) information supply chain is extremely vulnerable to cyber attack from nation-state adversaries, criminal enterprises and insiders.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Physics-Informed Deep Neural Network Method for Limited Observability State Estimation

The precise knowledge regarding the state of the power grid is important in order to ensure optimal and reliable grid operation. Specifically, knowing the state of the distribution grid becomes increasingly important as more renewable energy sources are connected directly into the distribution network, increasing the fluctuations of the injected power. In this paper, we consider the case when the distribution grid becomes partially observable, due to for example cyber attacks, and the state estimation problem is under-determined. We present a new methodology that leverages a deep neural network (DNN) to estimate the grid state. The standard DNN training method is modified to explicitly incorporate the physical information of the grid topology and line/shunt admittance. We show that our method leads to a superior accuracy of the estimation when compared to the case when no physical information is provided. Finally, we compare the performance of our method to the standard state estimation approach, which is based on the weighted least squares with pseudo-measurements, and show that our method performs significantly better with respect to the estimation accuracy.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Supporting Cyber Security of Power Distribution Systems by Detecting Differences Between Real-time Micro-Synchrophasor Measurements and Cyber-Reported SCADA (Final Report)

As modern power grids tend towards greater levels of automation and communication, the challenges of identifying and mitigating vulnerabilities to cyber-attacks are ones that are increasingly demanding attention. Today’s power system has evolved to form the foundational bedrock of modern society, and an attack on this infrastructure could prove disastrous. In this project we were tasked to investigate the use of distribution synchrophasors as an independent isolated sensor network with which we can corroborate, or flag potentially spoofed,Supervisory Control And Data Acquisition (SCADA) data. We adapted an approach to marry the underlying physical properties of power systems with the network communications used by power systems in order to offer insights unattainable by either data stream isolation. While the concept of intrusion detection systems (IDS) is well understood for monitoring network traffic and traditional IT computing systems, the approach discussed in this report is motivated by several key notions: first, current SCADA communications alone presents an incomplete view of the grid. Second, the power grid, and the equipment controlling it, is grounded by laws of physics. Given this, we leverage high-frequency physical grid measurements to understand the physical condition of the grid, and combine this with SCADA. While high-frequency physical grid measurements and SCADA communication over Internet Protocol (IP) networks are fundamentally disparate information sources, when collectively examined through appropriate lenses, they offer a much more nuanced depiction of the grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Recommendations for Distributed Energy Resource Access Control

Cybersecurity for internet - connected Distributed Energy Resources (DER) is essential for the safe and reliable operation of the US power system. Many facets of DER cybersecurity are currently being investigated within different standards development organizations, research communities, and industry committees to address this critical need. This report covers DER access control guidance compiled by the Access Controls Subgroup of the SunSpec/Sandia DER Cybersecurity Workgroup. The goal of the group was to create a consensus - based technical framework to minimize the risk of unauthorized access to DER systems. The subgroup set out to define a strict control environment where users are authorized to access DER monitoring and control features through three steps: (a) user is identified using a proof-of-identity, (b) the user is authenticated by a managed database, (c) and the user is authorized for a specific level of access. DER access control also provides accountability and nonrepudiation within the power system control environment that can be used for forensic analysis and attribution in the event of a cyber-attack. This paper covers foundational requirements for a DER access control environment as well as offering a collection of possible policy, model, and mechanism implementation approaches for IEEE 1547-mandated communication protocols.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Detecting Electrical Anomalies via Overlapping Measurements

As cyber-attacks against critical infrastructure become more frequent, it is increasingly important to be able to rapidly identify and respond to these threats. Therefore, we are investigating using multiple independent systems with overlapping electrical measurements to more rapidly identify anomalies. While prior research has explored the benefits of fusing measurements, the possibility of overlapping measurements from an existing electrical system has not been investigated. To that end, we explore the potential benefits of combining overlapping measurements both to improve the speed/accuracy of anomaly detection and to provide additional validation of collected measurements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Emerging Trends and Systemic Issues Influencing Today’s U.S. Electric Grid

With increasing shifts from vertically integrated to horizontally structured operations and from centralized to distributed electric power delivery, today’s electric power grid (the “grid”) operators and designers face the challenge of creating an architecture that accommodates a host of diverse requirements. The grid’s modes of operation must address concerns of reliability and stability, new deployments of renewable energy sources, threats from cyber-attacks and natural disasters, and increasingly distributed system operations. Grid modernization calls for a reliable, affordable, sustainable, agile, secure, and resilient grid. However, the modernization of the U.S. power grid is hampered by mounting complexity and diverging objectives from owners and operators and is consequently risky and fraught with potential missteps. Flawed architecture, design, and implementation will lead to stranded investments and lost opportunities. A principled approach to minimize risk and develop a robust grid of the future is to begin with a sound architecture for the grid to inform the design process. Architecture development starts with the context of influencing factors that provide constraints as well as driving goals. This report provides the context of emerging trends and cross-cutting systemic issues in the U.S. electric power grid and serves as a vital input for grid architecture development.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Operational Technology Behavioral Analytics (OTBA) (Final Technical Report DE-FE0031640)

This final report provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company Services, Inc. at Alabama Power Company’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

20 FOSSIL-FUELED POWER PLANTS↗

WPTO Comprehensive References [Poster]

Protecting hydroelectric plants from incidents that adversely impact their cyber-physical systems presents unique challenges due to the plants’ widely dispersed geographic locations and varied configurations as well as the relative nascent nature of the cyberattacks targeting these facilities. To help hydroelectric plants better respond to and mitigate cybersecurity incidents, this Department of Energy Water Power Technologies Office Cyber Comprehensive Reference list is to be used at a hydroelectric plant to quickly go to appropriate sources during the response and recovery of a cyber incident. In addition to this product, there are three other products meant to be distributed to a hydroelectric plant to assist in their cyber incident response and recovery. The first, a report on the processes of building a R&R flip book based on a large set of existing guidance. The second, a handy flip book meant to be distributed to hydroelectric plants to assist them during a cybersecurity incident occurring on a hydroelectic plant. And the third is a correlated alignment of the steps an hydroelectric plant operator would take for both a cyber incident as well as an emergency response process if the event rises to a cyber incident affecting the safe and reliable operations of a hydroelectric plant.

13 HYDRO ENERGY↗

Smart Microgrids

The Nation’s electrical power depends on one bulk power grid to support security and economic prosperity. According to the Department of Homeland Security’s Homeland Threat Assessment of 2020, the largest cyber threat to homeland security is potential disruption to critical infrastructure, including power grids. Critical infrastructure includes the physical and cyber systems which generate, transmit, and distribute electricity with an impact on economic security, public health, or safety. The surety of the Nation’s power grid is vital for providing essential services and would put the population at risk if disrupted. Power outages can have catastrophic consequences for critical organizations such as hospitals and military installations. Additionally, the current fossil-fuel dependent power grid is extremely fragile and vulnerable to overloads, storms that destroy power lines, and cyber-attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CRADA Number NFE-20-08292 with Quantum Lock Technologies LLC (CRADA Final Report)

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022).

97 MATHEMATICS AND COMPUTING↗

Wheelbyte Incident Response [Slides]

Wheelbyte faced some challenges regarding cyber attacks. The company reported possible exfiltration of company and customer data, along with the sudden death of an employee.

97 MATHEMATICS AND COMPUTING↗

Advancing Electric System Resilience with Distributed Energy Resources: A Review of State Policies

Severe weather, cyber-attacks, geomagnetic disturbances, and other hazards and threats have caused or have the potential to cause substantial levels of damage to electricity infrastructure and the global economy. Growth in distributed energy resources (DERs) and increasing attention to the resilience of the electric grid - its ability to "anticipate, absorb, adapt to, and/or rapidly recover" from disruptions, according to the Federal Energy Regulatory Commission (FERC, 2018) - have created an opportunity for energy stakeholders to develop and deploy "resilient DERs," resources in the distribution grid that improve the ability of a customer, critical facility, and/or the distribution system in general to anticipate, absorb, adapt to, and/or rapidly recover from disruptions. This paper explores how existing state regulations intersect with resilience and highlights opportunities where state regulators can employ DERs to advance resilience.

14 SOLAR ENERGY↗

Adaptive Cyber-Physical Resilience for Building Control Systems

The main goal of the project is to develop an AI-based process layer cybersecurity suite for detection, isolation and mitigation of cyber-attack effects on operation of building energy management systems (BEMS). The following constituent key technologies were developed under the program towards fulfilling the program objectives: (1) developed a high fidelity BEMS testbed for generation of training data and validation of developed technologies; (2) developed a physics informed ML based attack detection and localization module (ADL) capable of detecting high impact stealthy attacks (HISA - attacks causing 30% energy utilization but no immediate visible impact otherwise) with 98% accuracy; (3) developed a methodology to determine ’representative days’ to limit the data required for training; (4) developed a virtual sensing system that can reconstruct affected sensors with 10% error for the same HISA set; (5) developed a resilient model predictive control system that can continue operation of the BEMS without jeopardizing stability for the HISA set; and (6) integrated and deployed all the constituent modules and demonstrated the efficacy of the technology in real-time in a hardware in loop simulation.

42 ENGINEERING↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Quantum Lock Technologies: Innovation Crossroads Final CRADA Report

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022). Below is a photograph of myself at an energy substation where we plan to eventually apply our technology.

42 ENGINEERING↗

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗