Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Oak Ridge National Laboratory EAGLE-I TM : Modeling Electric Utility County Customers for Situational Awareness

During natural hazard events (hurricanes, wildfires, earthquakes, etc.) and recent man-made events (e.g., cyber attacks), the exchange of near real-time, spatially refined data within the response community is critical. The EAGLE-I$^{TM}$ platform is one tool that facilitates this data for decision makers within the energy sector. While much information can be collected and integrated into the system directly, other pertinent data must be augmented by other derived data products to enhance the information and allow for a consistent evaluation of on-the-ground conditions. One such data set that requires the addition of other derived data is the electric utility customer outage data that is aggregated to the county level within the EAGLE-I application. Without a county customer data set, outages can only be compared on total counts, which gives greater importance to higher population outages. Including an electric utility customer data set at the county level allows for these outage counts to be converted to percent outages and brings a consistent classification of outages and equal importance to all outages. To achieve this, several available data sets were combined and spatial disaggregation techniques were employed to model customer estimates at the county scale. This paper presents the approach to produce this data for the United States and lessons learned from working with these disparate data sets. Data validation is provided, where possible, and limitations of the model and possible improvements are discussed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilience Through Data-Driven, Intelligent Designed Control: A Formal Methods Approach

The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.

97 MATHEMATICS AND COMPUTING↗

Nominal and adversarial synthetic PMU data for standard IEEE test systems

GridSTAGE (Spatio-Temporal Adversarial scenario GEneration) is a framework for the simulation of adversarial scenarios and the generation of multivariate spatio-temporal data in cyber-physical systems. GridSTAGE is developed based on Matlab and leverages Power System Toolbox (PST) where the evolution of the power network is governed by nonlinear differential equations. Using GridSTAGE, one can create several event scenarios that correspond to several operating states of the power network by enabling or disabling any of the following: faults, AGC control, PSS control, exciter control, load changes, generation changes, and different types of cyber-attacks. Standard IEEE bus system data is used to define the power system environment. GridSTAGE emulates the data from PMU and SCADA sensors. The rate of frequency and location of the sensors can be adjusted as well. Detailed instructions on generating data scenarios with different system topologies, attack characteristics, load characteristics, sensor configuration, control parameters are available in the Github repository - https://github.com/pnnl/GridSTAGE. There is no existing adversarial data-generation framework that can incorporate several attack characteristics and yield adversarial PMU data. The GridSTAGE framework currently supports simulation of False Data Injection attacks (such as a ramp, step, random, trapezoidal, multiplicative, replay, freezing) and Denial of Service attacks (such as time-delay, packet-loss) on PMU data. Furthermore, it supports generating spatio-temporal time-series data corresponding to several random load changes across the network or corresponding to several generation changes. A Koopman mode decomposition (KMD) based algorithm to detect and identify the false data attacks in real-time is proposed in https://ieeexplore.ieee.org/document/9303022. Machine learning-based predictive models are developed to capture the dynamics of the underlying power system with a high level of accuracy under various operating conditions for IEEE 68 bus system. The corresponding machine learning models are available at https://github.com/pnnl/grid_prediction.

99 GENERAL AND MISCELLANEOUS↗

Feature Classification for Control System Devices

Control systems are used to automate industrial processes, smart grids, and smart cities. Unfortunately, cyber attacks on control systems are on the rise. Additionally, control systems lack the plethora of tools available for commodity systems for forensic investigation. An important step towards the proper forensic investigation is to analyze device memory. To assist in identifying features of device memory, we present a machine learning-based technique that integrates ontology information for feature classification in a control system device’s memory.

ahmed mithu, M Rayhan↗

Time Synchronization Techniques in the Modern Smart Grid: A Comprehensive Survey

In modern smart grids, accurate and synchronized time signals are essential for effective monitoring, protection, and control. Various time synchronization methods exist, each tailored to specific application needs. Widely adopted solutions, such as GPS, however, are vulnerable to challenges such as signal loss and cyber-attacks, underscoring the need for reliable backup or supplementary solutions. This paper examines the timing requirements across different power grid applications and provides a comprehensive review of available time synchronization mechanisms. Through a comparative analysis of timing methods based on accuracy, flexibility, reliability, and security, this study offers insights to guide the selection of optimal solutions for seamless grid integration.

comparison↗

Cyber-Resilient Frequency Control of Power Grids with Energy Storage Systems

The integration of synchronous generators and energy storage systems operated through communication networks introduces new challenges and vulnerabilities to the electric grid, where cyber attacks can corrupt sensor measurements or control inputs and interrupt functions such as frequency regulation. This paper proposes a defense methodology for the design of resilient operating constraints imposed on each generation and storage unit in order to prevent any attack sequence from driving the system's frequency to unsafe conditions. The resilient operating constraints are found by using ellipsoidal approximations of the reachable set of the power system, leading to a convex optimization problem with linear matrix inequalities. Numerical results in a single-area power system with synchronous generation and energy storage demonstrate how the resilient constraints provide security guarantees against any type of attack affecting frequency measurements or controller setpoints.

24 POWER TRANSMISSION AND DISTRIBUTION↗

An Advanced Cyber-Physical System Security Testbed for Substation Automation

A Cyber-Physical System (CPS) testbed serves as a powerful platform for testing and validating cyber intrusion detection and mitigation strategies in substations. This study presents the design and development of a CPS testbed that can effectively assess the real-time dynamics of a substation. Cyber attacks exploiting IEC 61850-based SV and GOOSE protocols are demonstrated using the testbed, along with an analysis on attack detection. Realistic timing measurements are obtained, and the time frames for deploying detection and mitigation strategies are evaluated.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Privacy-preserving Information Security for the Energy Grid of Things

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. Further, as information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacy-preserving, trust-augmented secure scheme for a smart grid implementation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Ground Data System Applications for Space Operations

The increasing prevalence and sophistication of cyber attacks has prompted the Multimission Ground Systems and Services (MGSS) Program Office at Jet Propulsion Laboratory (JPL) to initiate the Common Access Manager (CAM) effort to protect software applications used in Ground Data Systems (GDSs) at JPL and other NASA Centers. The CAM software provides centralized services and software components used by GDS subsystems to meet access control requirements and ensure data integrity, confidentiality, and availability. In this paper we describe the CAM software; examples of its integration with spacecraft commanding software applications and an information management service; and measurements of its performance and reliability.

Security↗

Analyzing Cyber Security Threats on Cyber-Physical Systems Using Model-Based Systems Engineering

The spectre of cyber attacks on aerospace systems can no longer be ignored given that many of the components and vulnerabilities that have been successfully exploited by the adversary on other infrastructures are the same as those deployed and used within the aerospace environment. An important consideration with respect to the mission/safety critical infrastructure supporting space operations is that an appropriate defensive response to an attack invariably involves the need for high precision and accuracy, because an incorrect response can trigger unacceptable losses involving lives and/or significant financial damage. A highly precise defensive response, considering the typical complexity of aerospace environments, requires a detailed and well-founded understanding of the underlying system where the goal of the defensive response is to preserve critical mission objectives in the presence of adversarial activity. In this paper, a structured approach for modeling aerospace systems is described. The approach includes physical elements, network topology, software applications, system functions, and usage scenarios. We leverage Model-Based Systems Engineering methodology by utilizing the Object Management Group's Systems Modeling Language to represent the system being analyzed and also utilize model transformations to change relevant aspects of the model into specialized analyses. A novel visualization approach is utilized to visualize the entire model as a three-dimensional graph, allowing easier interaction with subject matter experts. The model provides a unifying structure for analyzing the impact of a particular attack or a particular type of attack. Two different example analysis types are demonstrated in this paper: a graph-based propagation analysis based on edge labels, and a graph-based propagation analysis based on node labels.

MBSE↗

Detection, Localization, and Tracking of Unauthorized UAS and Jammers

Small unmanned aircraft systems (UASs) are expected to take major roles in future smart cities, for example, by delivering goods and merchandise, potentially serving as mobile hot spots for broadband wireless access, and maintaining surveillance and security. Although they can be used for the betterment of the society, they can also be used by malicious entities to conduct physical and cyber attacks to infrastructure, private/public property, and people. Even for legitimate use-cases of small UASs, air traffic management (ATM) for UASs becomes of critical importance for maintaining safe and collusion-free operation. Therefore, various ways to detect, track, and interdict potentially unauthorized drones carries critical importance for surveillance and ATM applications. In this paper, we will review techniques that rely on ambient radio frequency signals (emitted from UASs), radars, acoustic sensors, and computer vision techniques for detection of malicious UASs. We will present some early experimental and simulation results on radar-based range estimation of UASs, and receding horizon tracking of UASs. Subsequently, we will overview common techniques that are considered for interdiction of UASs.

surveillance↗

Cyber Physical Security (CPS) Extension to Air Traffic Management (ATM) Testbed

The Air Traffic Management (ATM) Testbed is being developed at NASA to enable benefit, impact, safety and cost assessments for accelerating the deployment of Concept and Technologies (C&T) in the National Airspace System (NAS). Today, C&T introduction into the NAS takes decades. The primary reason for this is an inability to assess the operational impact of the interaction between the proposed C&T and operationally deployed systems (Realistic Technologies) in terms of NAS-wide safety, traffic flow efficiency, roles and workload of controllers and traffic managers, and impact on airline fleet operations. Transition of C&T to operations requires mathematical modeling and simulation, Human-in-the-Loop (HITL) testing and shadow-mode evaluation driven by operational data. Whereas interaction with the operational system during testing and stages of deployment is not permissible due to safety concerns, it is certainly possible to create a simulation environment that closely mimics the NAS using the same operational systems/hardware for enabling such assessments. This presentation focuses on a proposed Cyber Physical Security extension to the ATM Testbed for creating a modeling and simulation architecture to study how well the Air Traffic Management system will perform and analyze effectiveness of mitigating security measures against particular cyber-attack scenarios.

Datta, Koushik↗

IS BLOCKCHAIN A SUITABLE TECHNOLOGY FOR ENSURING THE INTEGRITY OF DATA SHARED BY LIGHTING AND OTHER BUILDING SYSTEMS?

Increasing amounts of data are available from lighting and other building systems. In commercial buildings, these data can be used to improve system and energy performance, detect and diagnose faults, and facilitate maintenance. Building data are not only of interest to owners and operators of the building systems, however. Owners and operators of similar buildings, manufacturers of building systems, utilities, and city agencies also have interesting use cases. Energy data can, for example, be used to verify the performance of energy-conservation measures, issue renewableenergy certificates, and financially settle grid services. Increased data sharing, however, significantly expands the cyber-attack surface, creating new challenges. In this work, blockchain is explored as an option for ensuring the integrity of data that are shared by lighting and other building systems. Blockchain fundamentals and variants are briefly reviewed, and value propositions relevant to building systems are discussed. A recently developed blockchain applicability framework (BAF) that builds upon and addresses the limitations of previous applicability models is also briefly reviewed. The BAF is used to assess the suitability of blockchain over other technologies or approaches for building-data applications, using emerging connected lighting systems as an example use case.

blockchain, connected lighting system, data integr↗

Control-Theory-Informed Feature Selection for Detecting Malicious Tampering in Additive Layer Manufacturing Processes

Additive layer manufacturing (ALM) is rapidly becoming an appealing solution to the low-volume manufacturing of metal, polymer, or composite parts. However, ALM’s reliance on digital part specifications, microcontrollers, and modern networking makes these devices vulnerable to malicious tampering by cyber attackers, which can negatively affect part performance and even result in catastrophic failure. We present a hybrid analytic approach to feature discovery using control theoretic techniques and linear modelling on input-output data collected from a representative controller system. Employing this approach, we design, train, and test an anomaly detection system. The preliminary results show that the proposed approach effectively discovers useful input-output relationships for anomaly detection in a simulated ALM process. Application to larger and more complex systems are discussed.

Dawson, Joel↗

Guided Resilience Self Assessment Application

Reliable electricity access is vital for everything from hospitals to national security. When grid disturbances occur, it is crucial to minimize the amount of time it takes to recover. Grid resiliency considers both the preparation for and recovery from high-impact low-frequency disturbances (HILF) such as weather events and cyber attacks. The Department of Energy (DOE) Wind Energy Technologies Office (WETO) funds the multi-laboratory Microgrids, Infrastructure Resilience, and Advanced Control Launchpad (MIRACL) project to investigate technologies to support and grow distributed wind. Researchers at Idaho National Laboratory (INL) contribute to resilience and cybersecurity efforts for the project, and have produced a resilience framework to evaluate system resilience based on individual system specifications. In order to make this framework easy for anyone to apply, I have coded a web application that allows users to input their power system qualities, goals, and perceived risks and then receive suggestions on how to improve their grid resiliency. The web application follows the seven steps in the planning stage of the framework process, allowing the user to input information about their grid and select from common goals, metrics, and hazards, as well as add their own. The application currently provides information about how to complete each step, requiring minimal prior knowledge of the framework. Future work for this application will include allowing the user to submit line drawings of their system and incorporate modeling tools so that the hazard simulations of applying the framework is completed for the user.

97 MATHEMATICS AND COMPUTING↗

Protecting Smart Buildings with STIG

This is a submission for the 2022 Intern Poster Session. The abstract of the poster is: Smart buildings are getting more common, and so are hackers that target them. The physical systems in our businesses and homes are now vulnerable to cyber attacks. Using STIG, an INL program that turns cybersecurity data into graphs, buildings can be better protected.

99 GENERAL AND MISCELLANEOUS↗

OPERATIONAL TECHNOLOGY BEHAVIORAL ANALYTICS (OTBA) – A DATA-CENTRIC APPROACH FOR REDUCING CYBERSECURITY RISK

This paper provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company at Alabama Power’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

Black, Clifton↗

Variable Resource Resilience: How Systems Experience Increased Resilience from Variable and Hybrid Resources

Variable resources like wind and solar are often seen as detriments to system resilience rather than benefits because they may not be available with the capacities or services required during a high-impact low-frequency (HILF) event, whether that is a physical threat, natural disaster, or cyber attack. However, resilience goals and metrics are inadequate for electric energy delivery systems with inverter-based resources. Examination of this topic reveals that renewable resources are well suited to combat many resilience hazards due to local resource availability. Metrics that demonstrate the resilience value of variable resources are presented and categorized for resource (wind, solar, storage, hybrid) and installation type (bulk utility scale, behind-the-meter, front-of-the-meter, isolated). Distributed and hybrid systems can further enhance resilience benefits my maximizing resource potential for a locality. A case study demonstrating quantitative resilience benefits from wind alone is provided for St. Mary's, AK, which concludes that hundreds of thousands of dollars are saved by the addition of a wind turbine in the face of realistic fuel shortage and extreme winter weather scenarios.

17 WIND ENERGY↗