Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Moving Target Defense”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

31 records · Page 2

Sequential Perturbation-based FDIA Detection using DERs for Unbalanced Distribution System

The power distribution system with its reliance on automated monitoring and control infrastructure makes it a complicated cyber-physical system and vulnerable to various cyber-attacks. This paper proposes a moving target defense inspired false data injection attack (FDIA) detection mechanism for an unbalanced distribution system. In the proposed grid diagnosis service framework, the distribution system operator judiciously manipulates power outputs of a subset of inverter-based distribution energy resources (DERs) to create secret low magnitude voltage perturbations which are inconsequential to the normal operation of the grid. A mixed-integer-linear-programming algorithm is developed to select the optimal set of DERs that can create a voltage perturbation signal of the required magnitude at each sensor location at a minimum cost. Then, a sequential detector is applied that detects for the FDIA as measurements are received from individual sensors. The performance of the proposed perturbation-based FDIA detection framework is demonstrated via simulation of the IEEE 123 bus test system.

Attack Detection↗

Enabling Cybersecurity, Situational Awareness and Resilience in Distribution Grids with High Penetration of Photovoltaics (CARE-PV) (Final Report)

Since legacy distribution systems have very limited visibility beyond the substation, high penetration of PV at the grid edge presents some unique operational challenges. One approach to address these challenges is to use information from advanced metering infrastructure (AMI) and µPMUs. However, exploiting this information is impacted by a number of factors, including multi-timescale measurements, volume of data generated, communication network impairments (e.g., information loss and latency) and susceptibility to cyber-attacks. Therefore, one of the critical tasks involved in the management of a distribution grid is to develop complete situational awareness by integrating cyber-security mechanisms with state estimation strategies and leveraging this situational awareness to assure energy services at strategic locations while exploiting AMI/PV inverter/ µPMU data. This CARE-PV project addresses the fundamental challenges in situational awareness and resilience to cyber and physical vectors by exploiting the synergy between innovative modeling, estimation, data analytics, testing and validation using smart PV inverters designed at K-State and facilities at NREL. Specifically, the project involved the development, testing and validation of the following novel enabling technologies: (Thrust 1) Resilience to cyber vectors that impact data integrity was addressed via a two-level defense strategy that combines cyber intrusion detection using self-learning, cooperative smart PV inverters, and a novel moving target defense framework to combat data integrity attacks. (Thrust 2) Resilience to cyber-physical vectors that impact situational awareness by limiting data availability was addressed via novel centralized and decentralized, sparsity-based static and dynamic state estimation approaches that enhance observability even when the underlying system is unobservable. (Thrust 3) Leveraging a unique probabilistic sensitivity analysis approach accompanied by one-of-a-kind dominant influencer set computation, the vulnerability of critical infrastructure at strategic locations was evaluated so that proactive PV-based control strategies can be used to support operations under normal/outage scenarios. These CARE-PV project innovations were demonstrated on both small-scale IEEE and larger utility-scale testbeds (Thrust 4). Feedback from Industry Advisory Board members was used to formulate a commercialization pathway for a subset of CARE-PV technologies. These CARE-PV technologies will ultimately lead to reliable and secure, large-scale integration of renewable energy and mitigate the risk of energy disruption resulting from cyber incidents and other emerging threats within the energy environment.

14 SOLAR ENERGY↗

TRIM: AI Guided Random Number Generation for Resource-Constrained IoT Systems

Random numbers often serve as the backbone for many security solutions in diverse domains such as cryptography, side channel leakage prevention, and moving target defense. However, generating true random numbers requires a physical source of entropy (e.g. hardware, quantum, environmental phenomenon) making it difficult to realize at a large scale and at a low cost. On the flip side, pseudorandom number generators (easy to implement) following a specific distribution (e.g. Gaussian) can be easily compromised given a sufficient amount of traces. In this work, we have developed a machine learning-guided generative approach that can be used to create portable, resource-efficient, and cost-effective random number generators with high throughput and true randomness characteristics. We implement the proposed approach as a highly parameterized framework and perform extensive evaluation for different settings. The framework was able to learn from true random sources such as irrational numbers and environmental audio noise and imitate those sources towards generating new good quality random numbers on demand. We have generated more than 1 billion bits and observed robust performance in terms of true randomness metrics obtained from NIST SP 800-22 and FIPS 140-1 randomness test suites achieving a throughput of up to 142.85 Mbps. Compared to the state-of-the-art (SOTA) technique, the iso-cost setup of our framework can achieve more than 500 Mbps in a distributed setting. We have evaluated the efficacy of running the true randomness imitation AI models on target edge devices such as Raspberry Pi 4 (Model B), Nvidia Jetson Nano, Nvidia Jetson Orin Nano and Nvidia Jetson Xavier. We have also looked at the security of the TRIM framework itself against different adversarial threat models.

Cybersecurity↗

Detection of Stealthy False Data Injection Attacks in Unobservable Distribution Networks

In this paper, a composite scheme is proposed for detecting stealthy data manipulation attacks on distribution system which is unobservable with standard least squares based state estimators. This technique has three stages where the process of data imputation, voltage phasor estimation and the bad data detection are carried out in a systematic manner. The proposed approach is then integrated with moving target defense strategies which perturbs the network parameters to reveal stealthy false data injection attacks. The proposed approach is tested is validated on a three-phase, unbalanced 37-node distribution system and its results are presented. It is shown that the proposed approach has the ability to accurately detect the presence of FDI attacks using limited measurements (i.e., the test system is unobservable).

Rajasekaran, James K.↗

An Interior-Point Solver for Optimal Power Flow Problem Considering Distributed FACTS Devices

In this paper, we propose an AC optimal power flow (ACOPF) model considering distributed flexible AC transmission system (D-FACTS) devices, in which the reactance of D-FACTS equipped lines are introduced as decision variables. This is motivated by increasing interests in using D-FACTS devices to address system operational and cyber-security concerns. First, D-FACTS devices can be incorporated in real-time operations for economic benefits such as managing power congestions and reducing system losses. Second, D-FACTS devices can be utilized by moving target defense (MTD), an emerging concept against cyber-attacks, to prevent attackers from knowing true system configurations. Therefore, system operators can use the proposed ACOPF model to achieve economic benefits and provide the setpoints of D-FACTS devices for MTD at the same time. In addition, we rigorously derive the gradient and Hessian matrices of the objective function and constraints, which are further used to build an interior-point solver of the proposed ACOPF. Numerical results on the IEEE 118-bus transmission system show the validity of the proposed ACOPF model as well as the efficacy of the interior-point solver in minimizing system losses and generation costs.

Liu, Bo↗

Reinforcement Learning Approach to Cybersecurity in Space (RELACSS)

Securing satellite groundstations against cyber-attacks is vital to national security missions. However, these cyber threats are constantly evolving. As vulnerabilities are discovered and patched, new vulnerabilities are discovered and exploited. In order to automate the process of discovering existing vulnerabilities and the means to exploit them, a reinforcement learning framework is presented in this report. We demonstrate that this framework can learn to successfully navigate an unknown network and detect nodes of interest despite the presence of a moving target defense. The agent then exfiltrates a file of interest from the node as quickly as possible. This framework also incorporates a defensive software agent that learns to impede the attacking agents progress. This setup allows for the agents to work against each other and improve their abilities. We anticipate that this capability will help uncover unforeseen vulnerabilities and the means to mitigate them. The modular nature of the framework enables users to swap out learning algorithms and modify the reward functions in order to adapt the learning tasks to various use cases and environments. Several algorithms, viz., tabular Q learning, deep Q networks, proximal policy optimization, advantage actor-critic, generative adversarial imitation learning, are explored for the agents and the results highlighted. The agent learns to solve the tasks in a light-weight abstract environment. Once the agent learns to perform sufficiently well, it can be deployed in a minimega virtual machine environment (or a real network) with wrappers that map abstract actions to software commands. The agent also uses a local representation of the actions called a ‘slot-mechanism’. This allows the agent to learn in a certain network and generalize it to different networks. The defensive agent learns to predict the actions taken by an offensive agent and uses that information to anticipate the threat. This information can then either be used to raise an alarm or to take actions to thwart the attack. We believe that with the appropriate reward design, a representative environment, and action set, this framework can be generalized to tackle other cybersecurity tasks. By sufficiently training these agents, we can anticipate vulnerabilities leading to robust future designs. We can also deploy automated defensive agents that can help secure satellite groundstation and their vital national security missions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Perturbation-Based Diagnosis of False Data Injection Attack Using Distributed Energy Resources

Modern smart grid relies on various sensor measurements for its operational control. In a successful false data injection attack, the attacker manipulates the measurements from the grid sensors such that undetected errors are introduced into the estimates of the system parameters leading to catastrophic situations. This paper proposes a novel perturbation based false data injection attack detection mechanism that utilizes inverter based distributed energy resources (DERs) to create low magnitude perturbation signal in the distribution system voltage that is inconsequential to the normal grid operation. Two voltage sensitivity analysis based algorithms are designed to identify the optimal set of DERs that can create the voltage perturbation signal of desired magnitude. An analytical method of voltage sensitivity analysis is used to compute the magnitude of voltage perturbation signal at each node in a computationally efficient manner. Then, a detection mechanism is developed that checks for the presence of the perturbation sequence in each sensor measurement. A sensor measurement is deemed authentic if the voltage perturbation signal is present in the data. In case of sensor malfunction or cyber-attack, the perturbation signal will not be present in the measurement data. Performance of the proposed attack detection mechanism is validated via simulation of the IEEE 69 bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Plant endomembranes and cytoskeleton: moving targets in immunity

Pathogens attack plant cells to divert resources toward pathogen proliferation. To resist pathogens, plant cells rely on multilayered signaling pathways that hinge upon the secretory pathway for the synthesis and trafficking of pathogen sensors and defense molecules. In recent years, significant strides have been made in the understanding of the functional relationship between pathogen response and membrane traffic. Furthermore, we discuss how the plant cytoskeleton and endomembranes are targeted by pathogen effectors and highlight an emerging role of membrane contact sites in biotic stress responses.

59 BASIC BIOLOGICAL SCIENCES↗

Assessment of the High Flux Isotope Reactor Cybersecurity Initiative

Recent cyber-attacks on industrial control systems, and inadvertent exposure of nuclear plant systems to cyber-exploits underscore the need for plant operators to adopt and deploy cyber-security defense solutions made for industrial control systems. Of increasing concern is the fact that international cyber hackers are beginning to target critical infrastructure, and because these more modern controls systems depend on advanced use of digital systems, they are more vulnerable than ever before to cyber-attacks. Traditional cyber defense strategies and products that have been available for decades are tailored for use on IT or corporate networks but can cause interruptions and catastrophic damage when deployed on industrial control system networks. The Department of Energy (DOE) Office of Nuclear Energy established the Gateway for Accelerated Innovation in Nuclear (GAIN) program to provide private companies pursuing innovative nuclear energy technologies with access to the technical support necessary to move toward commercialization. One of these GAIN small business vouchers was awarded to Dragos, Inc. to enable collaboration with Oak Ridge National Laboratory (ORNL) to evaluate the Dragos Platform on a production nuclear reactor test bed, hence laying the path for future commercial adoption. The vision was to provide a guide for industrial operators on implementing an industrial monitoring solution and to show how these solutions can be deployed without causing safety and reliability issues. This report documents the results of the collaboration between ORNL and Dragos, Inc.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

A critical review of cyber-physical security for building automation systems

Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.

97 MATHEMATICS AND COMPUTING↗

Optimization of Geometric Perturbations on a Rod Moving Through a High Explosive Target

After completing a study to ensure the simulation results were converged, several high resolution 3D Smoothed Particle Hydrodynamic (SPH) simulations of copper rods impacting a high explosive (LX14) target were performed. This was then formulated into an optimization problem: I wanted to find the optimum shape and location of a perturbation on the rod that would maximize its erosion after it left the target. The shape of the perturbation was modeled as a 2D Gaussian bump and parameterized by its location along the rod axis (z 0 ) and amplitude (A). The final mass of the coherent part of the rod as it leaves the target was used as a metric to represent the erosion of the rod, and the optimization was formulated to maximize this metric with respect to the aforementioned design variables. Due to the expensive nature of the high-fidelity 3D SPH simulations, a surrogate model needed to be chosen so that many function calls to the optimizer would be feasible. Thus, a strategic full factorial sampling plan was chosen to build a dataset, which consisted of 24 high-fidelity simulations. Two surrogate models, a third order polynomial regression model and a Gaussian Process Model, were analyzed using a 14%/86% test/train holdout technique. The root mean square and R2 score of the test set was used to determine the best model, and the third order polynomial regression model was chosen as the surrogate model. Finally, the Nelder-Mead Simplex and Basin-hopping optimization algorithms were implemented, and it was found that the two algorithms gave slightly different optimum values. Nelder-Mead gave an optimum point of [z* 0 ;A*] = [9:9;0:4] and Basin-Hopping gave an optimum value of x* = [z* 0 ;A*] = [9:2;0:1].

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗