Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Attack detection and localization with adaptive thresholding

According to some embodiments, a system, method, and non-transitory computer readable medium are provided comprising a plurality of real-time monitoring nodes to receive streams of monitoring node signal values over time that represent a current operation of the cyber physical system; and a threat detection computer platform, coupled to the plurality of real-time monitoring nodes, to: receive the monitoring node signal values; compute an anomaly score; compare the anomaly score with an adaptive threshold; and detect that one of a particular monitoring node and a system is outside a decision boundary based on the comparison, and classify that particular monitoring node or system as anomalous. Numerous other aspects are provided.

Abbaszadeh, Masoud↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Detecting Masquerade Attacks in Controller Area Networks Using Graph Machine Learning

Modern vehicles rely on a myriad of electronic control units (ECUs) interconnected via controller area networks (CANs) for critical operations. Despite their ubiquitous use and reliability, CANs are susceptible to sophisticated cyberattacks, particularly masquerade attacks, which inject false data that mimic legitimate messages at the expected frequency. These attacks pose severe risks such as unintended acceleration, brake deactivation, and rogue steering. Traditional intrusion detection systems (IDS) often struggle to detect these subtle intrusions due to their seamless integration into normal traffic. This paper introduces a novel framework for detecting masquerade attacks in the CAN bus using graph machine learning (ML). We hypothesize that the integration of shallow graph embeddings with time series features derived from CAN frames enhances the detection of masquerade attacks. We show that by representing CAN bus frames as message sequence graphs (MSGs) and enriching each node with contextual statistical attributes from time series, we can enhance detection capabilities across various attack patterns compared to using graph-based features only. Our method ensures a comprehensive and dynamic analysis of CAN frame interactions, improving robustness and efficiency. Extensive experiments on the ROAD dataset validate the effectiveness of our approach, demonstrating statistically significant improvements in the detection rates of masquerade attacks compared to a baseline that uses graph-based features only as confirmed by Mann-Whitney U and Kolmogorov-Smirnov tests (p < 0.05) .

Marfo, William [Univ. of Texas, El Paso, TX (Unite↗

Cybersecurity Center for Offshore Wind Energy (Final Project Report)

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models with SCADA infrastructure, and deployed a scaled physical turbine and associated sensors. High-resolution operational and side-channel data streams were collected and used to refine machine-learning (ML)-based attack detection systems and to extend the WindCRAFT framework to multi-turbine threat scenarios. The project demonstrated a realistic, scalable environment for evaluating cyber threats, validated attack detection approaches using enriched datasets, and identified new multi-turbine and inter-turbine communication attack vectors. The resulting testbed, models, and security mechanisms provide a foundation for ongoing R&D and deployment of cyber-resilient offshore wind energy systems.

17 WIND ENERGY↗

Protection Against Graph-Based False Data Injection Attacks on Power Systems

Graph signal processing (GSP) has emerged as a powerful tool for practical network applications, including power system monitoring. By representing power system voltages as smooth graph signals, recent research has focused on developing GSP-based methods for state estimation, attack detection, and topology identification. Included, efficient methods have been developed for detecting false data injection (FDI) attacks, which until now were perceived as non-smooth with respect to the graph Laplacian matrix. Consequently, these methods may not be effective against smooth FDI attacks. In this paper, we propose a graph FDI (GFDI) attack that minimizes the Laplacian-based graph total variation (TV) under practical constraints. In addition, we develop a low-complexity algorithm that solves the non-convex GDFI attack optimization problem using ell_1-norm relaxation, the projected gradient descent (PGD) algorithm, and the alternating direction method of multipliers (ADMM). We then propose a protection scheme that identifies the minimal set of measurements necessary to constrain the GFDI output to high graph TV, thereby enabling its detection by existing GSP-based detectors. Our numerical simulations on the IEEE-57 bus test case reveal the potential threat posed by well-designed GSP-based FDI attacks. Moreover, we demonstrate that integrating the proposed protection design with GSP-based detection can lead to significant hardware cost savings compared to previous designs of protection methods against FDI attacks.

Morgenstern, Gal↗

Cyber-Resilient Automatic Generation Control for Systems of AC Microgrids

In this paper we propose a co-design of the secondary frequency regulation in systems of AC microgrids and its cyber security solutions. We term the secondary frequency regulator a Micro-Automatic Generation Control (μ AGC) for highlighting its same functionality as the AGC in bulk power systems. We identify sensory challenges and cyber threats facing the μ AGC. To address the sensory challenges, we introduce a new microgrid model by exploiting the rank-one deficiency property of microgrid dynamics. This model is used to pose an optimal μ AGC control problem that is easily implemented, because it does not require fast frequency measurements. An end-to-end cyber security solution to the False Data Injection (FDI) attack detection and mitigation is developed for the proposed μ AGC. The front-end barrier of applying off-the-shelf algorithms for cyber attack detection is removed by introducing a data-driven modeling approach. Finally, we propose an observer-based corrective control for an islanded microgrid and a collaborative mitigation scheme in systems of AC microgrids. We demonstrate a collaborative role of systems of microgrids during cyber attacks. Furthermore, the performance of the proposed cyber-resilient μ AGC is tested in a system of two networked microgrids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Real-Time Testbed for Studying Cyberattacks and Defense in DER-integrated Smart Inverter Systems

In this paper, we propose a Hardware-in-the-Loop (HIL) simulation testbed suitable for the implementation and testing of realistic cyberattacks on grid-tied smart inverter systems integrated with Distributed Energy Resources (DER) that use the Distributed Network Protocol-3 (DNP3) protocol for communications between grid components. Specifically, our testbed combines a Real-Time Digital Simulator (RTDS) NovaCor device, outfitted with GNETx2 network interface cards, a gridtied DER topology implemented via the RTDS software package RSCAD, and a custom virtual network that emulates a man in the middle attacker. The Man-in-the-Middle (MITM) attacker captures DNP3 traffic and falsifies telemetry data in DNP3 packets to trigger unwarranted commands from a DNP3 controller that exploit smart inverter grid support functions. We choose DNP3 and implement grid support functions according to the IEEE Std. 1547-2018 mandated for the interconnection and interoperability of DER power systems with associated power components. Furthermore, we develop a protocol payload agnostic attack detection framework that leverages the round-trip time (RTT) anomalies between DNP3 requests and responses and can detect the presence of attacks without having to analyze the payload’s contents, while balancing trade-offs between false alarm counts, missed detections, and time to detection. To facilitate further research, we publicly release benign and attack network traffic exchanged between various sensors, controllers, and actuators in our grid-tied inverter testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Adaptive Cyber-Physical Resilience for Building Control Systems

The main goal of the project is to develop an AI-based process layer cybersecurity suite for detection, isolation and mitigation of cyber-attack effects on operation of building energy management systems (BEMS). The following constituent key technologies were developed under the program towards fulfilling the program objectives: (1) developed a high fidelity BEMS testbed for generation of training data and validation of developed technologies; (2) developed a physics informed ML based attack detection and localization module (ADL) capable of detecting high impact stealthy attacks (HISA - attacks causing 30% energy utilization but no immediate visible impact otherwise) with 98% accuracy; (3) developed a methodology to determine ’representative days’ to limit the data required for training; (4) developed a virtual sensing system that can reconstruct affected sensors with 10% error for the same HISA set; (5) developed a resilient model predictive control system that can continue operation of the BEMS without jeopardizing stability for the HISA set; and (6) integrated and deployed all the constituent modules and demonstrated the efficacy of the technology in real-time in a hardware in loop simulation.

42 ENGINEERING↗

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.

Asmar Awad, Rima [ORNL] (ORCID:0000000233407742)↗

Maximum-impact Adversary Design for Network-based Control System: A Case Study on Grid-interactive Efficient Buildings

The Internet of Things (IoT) technology has dramatically improved the efficiency of today's building operation and management. By connecting controllable devices into a communication network, control signals can be easily passed to the devices, and operating status can be acquired from measurable ends with minimal effort. However, this all-connected configuration could also expose the network-based control system (NBCS) to malicious actions, such as cyberattacks. One of the common NBCSs is the building automation system. With the promotion of grid-interactive efficient buildings (GEBs), there has been increasing attention on securing the buildings from the network perspective. This research proposes a maximum-impact adversary design framework so that the adversary can provide the most adversarial impact on the controlled system while remaining stealthy. The proposed framework is numerically demonstrated on a network-based building energy and control system. The building energy system is built in a Modelica-based simulation environment and controlled by the state-of-the-art ASHRAE Guideline 36 control sequences. The control commands at the supervisory level, generated from the Guideline 36 controller, are assumed to be sent to local devices through communication networks using the BACnet protocol. Simulation results show that the proposed maximum-impact adversary on such a system can stealthily affect the building system's performance to its maximum extent. It is anticipated that results can be used by researchers and practitioners in the building automation industry to design efficient and robust cyber-attack detection algorithms, especially for stealthy attacks.

Chu, Mengyuan↗

HIDES (Hybrid Intrusion Detection for Energy Systems) [SWR-19-65]

Hybrid Intrusion Detection for Energy Systems (HIDES) is a conglomerate detector that incorporates three major components: (1) Signature-based detection that involves information technology (IT) related anomaly detection rules, (2) Behavior-based detection that utilizes specially crafted rulesets for detecting abnormal behavior regarding the power system's supervisory control and data acquisition (SCADA) communication streams, and (3) Learning-based detection that combines SCADA communication with phasor measurements to identify otherwise non-detectible attack vectors. The software itself interconnects intrusion detection engine (IDE) enabling communications between the generated OT and IT alerts with phasor measurements for the learning-based detection system. The resulting detection system can detect a wide array of IT, OT, and physical attacks in a real-time setting.

Rivera, Joshua↗

Evaluating lightweight unsupervised online IDS for masquerade attacks in CAN

Vehicular controller area networks (CANs) are susceptible to masquerade attacks by malicious adversaries. In masquerade attacks, adversaries silence a targeted ID and then send malicious frames with forged content at the expected timing of benign frames. As masquerade attacks could seriously harm vehicle functionality and are the stealthiest attacks to detect in CAN, recent work has devoted attention to compare frameworks for detecting masquerade attacks in CAN. However, most existing works report offline evaluations using CAN logs already collected using simulations that do not comply with the domain’s real-time constraints. Here we contribute to advance the state of the art by presenting a comparative evaluation of four different non-deep learning (DL)-based unsupervised online intrusion detection systems (IDS) for masquerade attacks in CAN. Our approach differs from existing comparative evaluations in that we analyze the effect of controlling streaming data conditions in a sliding window setting. In doing so, we use realistic masquerade attacks being replayed from the ROAD dataset. We show that although evaluated IDS are not effective at detecting every attack type, the method that relies on detecting changes in the hierarchical structure of clusters of time series produces the best results at the expense of higher computational overhead. We discuss limitations, open challenges, and how the evaluated methods can be used for practical unsupervised online CAN IDS for masquerade attacks.

Anomaly detection↗

Secure and Resilient Operations Using Open-Source Distributed Systems Platform (OpenDSP)

The goal of this project is to identify and address cybersecurity gaps by developing a multi-layer multi-channel cyber-physical defense and survival mechanism for operating distribution networks with high penetration of solar / inverter-based resource (IBR) / distributed energy resource (DER). The proposed security enhancements are built upon the distributed framework and solution architecture for both information technology (IT) and operational technology (OT) systems. The technical solutions consist of two composite functionalities and six layers: proactive defense (vulnerability assessment, communication protection, and attack detection, as layers 1-3), and adaptive self-healing (attack-resilient control, adaptive recovery, and resilient survival, as layers 4-6). These layers, built on and extended from DHS CISA Cyber Framework, establish an integrated and robust cybersecurity framework for operating large-scale distribution networks.

14 SOLAR ENERGY↗

NASA’s Secured Airspace for Urban Air Mobility (UAM)

The Urban Air Mobility (UAM) architecture is leveraged from the Unmanned Traffic Management (UTM) concept of operations. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within that environment. As a recognized need, various views of UAM flight information are provided to the public and public safety entities. To accomplish this, among other goals, the Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). This concept of UAM proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical take-off and landing (VTOL) or short take-off and landing (STOL) aircraft to overcome increasing surface congestion. To garner the support of UAM and to realize its potential, an assurance of cybersecurity is critical for public acceptance. Understanding the various components communicating with one-another cybersecurity, like in other industries, has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. With the planned growth and reach of UAM systems, it’s clear that the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. Consequently, as these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well. While learning is always the goal, the overall intent of this workshop is to make recommendations on the following: (1) how future UAM environments can be protected against cyber-attacks, and (2) what mechanisms should be put in place to detect attacks against UAM environments.

UAM↗

Simulated 5g Network Traffic Dataset

This is a dataset of 5G network traffic for use with machine learning tools to benchmark attack detection capabilities for multiple different models. The dataset contains simulated normal and attack 5G network traffic. There is no software in this dataset, only simulated network traffic data.

Anderson, MatthewW↗

Beyond Binary: Automated PLC Memory Forensics through RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and the evolution of industrial control systems (ICS) to adopt Internet-based technologies enhanced productivity, but have inadvertently increased their vulnerability to cyber-based malicious attacks. When an ICS system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies to safeguard against future instances. Memory forensics is critical in the analysis process to ascertain what occurred. To date, approaches to analyze the persistent memory in ICS devices are limited, and almost nonexistent for volatile memory. This paper proposes an automated methodology, COMA, for PLC memory dump analysis using computer vision and deep learning techniques. Specifically, COMA converts the sequences of bytes in a PLC memory dump to RGB pixels and creates a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. COMA then uses the trained model to automatically segment new memory images and extract forensic artifacts. We evaluate COMA on a Schneider Electric Modicon M221 PLC involving two cyber-based attack scenarios: (i) code injection and (ii) code modification. The empirical results show that COMA can successfully detect attack artifacts in memory dumps in both scenarios.

Asmar Awad, Rima↗