Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cyber-Attack Methods, Why They Work on Us, and What to Do

Basic cyber-attack methods are well documented, and even automated with user-friendly GUIs (Graphical User Interfaces). Entire suites of attack tools are legal, conveniently packaged, and freely downloadable to anyone; more polished versions are sold with vendor support. Our team ran some of these against a selected set of projects within our organization to understand what the attacks do so that we can design and validate defenses against them. Some existing defenses were effective against the attacks, some less so. On average, every machine had twelve easily identifiable vulnerabilities, two of them "critical". Roughly 5% of passwords in use were easily crack-able. We identified a clear set of recommendations for each project, and some common patterns that emerged among them all.

cybersecurity↗

Data-driven cyber-attack detection for photovoltaic systems: A transfer learning approach

With increasing exposure to software-based sensing and control, power systems are facing higher risks of cyber/physical attacks. Here, to ensure system stability and minimize the potential economic losses, it is imperative to monitor the operating states and detect those attacks at the early stage. In this paper, a transfer learning method is proposed to detect cyber-attacks in photovoltaic (PV) systems with much less training data. First of all, two PV systems with a different number of PV inverters and power ratings are analyzed and their attack models are studied. Next, an attack detection Convolutional Neural Network (CNN) model was trained with rich amount of data from PV #1. Then, transfer learning was proposed to transfer the well-trained features from PV #1 to PV #2. Lastly, the attack detection model on PV #2 was trained based on the transferred CNN model. The experiment results show that the proposed transfer learning method achieves better accuracy and a faster convergence rate with a much less training dataset than conventional deep learning.

14 SOLAR ENERGY↗

Robust Distribution State Estimation for Reliable Locational Marginal Pricing under Cyber-Attacks

Here this paper examines the impact of false data injection (FDI) cyber-attacks on distribution system state estimation (DSSE) and the resulting distribution locational marginal price (DLMP) in power markets. Two robust high-breakdown regression estimators, namely S- and MM- estimators, are implemented to provide resistance against FDI attacks targeting measurements and grid topology, creating leverage points. The introduced estimators are compared to the weighted least squares (WLS) with a bad data detection and rejection module (BDD) and the robust Huber M-estimator. The proposed estimators are shown to be effective and compare favorably to both existing Huber M- and the WLS with BDD in the presence of topology FDI attacks. Both the S- and MM-estimators provide good performance in the case of clean and corrupted measurements. Their performance is comparable in this case to the Huber M- and the WLS, followed by a BDD module. The simulation considered a modified distribution IEEE 13 and 34-bus systems where the impact of FDI attack scenarios is shown on the state and the DLMP pricing in the presence of distributed Generation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Online Dynamic Cyber-Attack Diagnosis in Power Electronics Systems Based on Few-Shot Learning

With increasing exposure to software-based sensing and control, power electronics systems are facing higher risks of cyber-physical attacks. To ensure system stability and minimize potential economic losses, it is critical to monitor the operating states and detect those attacks at the early stage. However, anomaly detection and diagnosis of attacks are still challenging, especially when labeled anomaly data is difficult or even infeasible to obtain. To overcome this problem, we propose a Few-Shot Learning (FSL) based approach for cyber-attack diagnosis leveraging the waveform data. To the best of our knowledge, this work is the first attempt at leveraging FSL for cyber-attack diagnosis in power electronics systems. Extensive experimental results demonstrate that our proposed approach can achieve comparable diagnosis accuracy with the state-of-the-art data-driven methods using less than 0.04% of the training samples.

Li, Qi↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Detection of Cyber Attacks in Grid-tied PV Systems Using Dynamic Watermarking

This paper presents of an active detection scheme for detecting cyber attacks on sensors controlling a grid-tied PV systems. Several cyber vulnerabilities in Grid tied PV Systems are discussed. The defense mechanism introduces a private (secret) watermarking signal into the control inputs of the grid-tied inverter system. This will enable the detection of any malicious manipulation of sensor measurements. Based on the measured data, two statistical tests are conducted to identify anomalies in the system using the presence of the watermarking signal. It shown that when a sensor data is compromised and/or replaced by a pre-recorded healthy signal, both test 1 and 2 exhibit high values indicating a possible malicious activity. The robustness of the proposed algorithm is tested and validated with several attack scenarios on a grid tied PV system. Select results from an experimental setup are discussed.

Ibrahim, Hasan↗

Deception-Based Cyber Attacks on Hierarchical Control Systems using Domain-Aware Koopman Learning

Industrial control systems are subject to cyber attacks that produce physical consequences. These attacks can be both hard to detect and protracted. Here, we focus on deception-based sensor bias attacks made against a hierarchical control system where the attacker attempts to be stealthy. We develop a a data-driven, optimization-based attacker model and use the Koopman operator to represent the system dynamics in a domain-aware and computationally efficient manner. Using this model, we compute several different attacks against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. Finally, we discuss some computational considerations and identify avenues for future research.

koopman operator, Cyber-Physical Security, machine↗

Cyber-Attack Detection and Accommodation for the Energy Delivery System

The goals of this project were to create a software system with a suite of key algorithms for cyber-attack detection and accommodation providing domain layer protection for critical power generation assets. Example assets included gas and steam turbines, heat recovery steam generators, and electrical generators. The aggressive algorithm goals were aimed at reducing the false positive rates in threat detection to <1% using learnings from many evolving disciplines (power turbine and generator physics, power system modeling, modern control theory, system identification, machine learning, deep learning, mathematics and data science). Additional goals for the algorithms involved localizing threats on-the-fly to know in which monitoring node the effects of attacks are present, and then providing accommodation to keep the system running uninterrupted much of the time in the presence of the attack. Accommodation had a performance goal of providing resiliency when up to 50% of monitoring nodes are in an attack state.

cybersecurity, cyber-physical↗

Cyber-Attack Detection for Photovoltaic Farms Based on Power-Electronics-Enabled Harmonic State Space Modeling

Here in this paper, a physics-data-based detection method is proposed to detect a variety of cyber-attacks in Photovoltaic (PV) farms using the power electronics-enabled harmonic state space (HSS) models, which, to our knowledge, is original. At the device level, HSS-based detection is developed to monitor harmonic vectors of individual PV converter with minimum sensor measurements, thus improving accuracy and robustness compared to Kalman Filter-based detection. At the system level that involves multiple PV converters, a clustering approach is developed to investigate attack propagation and accurately locate attack sources within a PV farm. The proposed approach is one of the first attempts to address PV security through interaction between the device and system, maximizing the accuracy and robustness at different levels. To verify the feasibility, a comprehensive attacks model is built, including single attack, coordinated attacks, and replay attacks. Besides, the impacts of irradiance changes are taken into consideration in the test scenarios. With the real-time data acquisition and hardware-in-the-loop testbed, comprehensive test results are provided to verify the feasibility of the proposed detection methodology.

42 ENGINEERING↗

Coslett Intern Poster: Faster Cyber Attack Response Using STIG

This is a poster for the 2023 intern poster session demonstrating the most effective way to use STIG, a publicly available graph tool, for more efficient cybersecurity. Responses to cyber attacks can be implemented sooner if those shared are more generally applicable.

99 GENERAL AND MISCELLANEOUS↗

Cooperative Systems in Presence of Cyber-Attacks: A Unified Framework for Resilient Control and Attack Identification

Here, this paper considers a cooperative control problem in presence of unknown attacks. The attacker aims at destabilizing the consensus dynamics by intercepting the system’s communication network and corrupting its local state feedback. We first revisit the virtual network based resilient control proposed in our previous work and provide a new interpretation and insights into its implementation. Based on these insights, a novel distributed algorithm is presented to detect and identify the compromised communication links. It is shown that it is not possible for the adversary to launch a harmful and stealthy attack by only manipulating the physical states being exchanged via the network. In addition, a new virtual network is proposed which makes it more difficult for the adversary to launch a stealthy attack even though it is also able to manipulate information being exchanged via the virtual network. A numerical example demonstrates that the proposed control framework achieves simultaneously resilient operation and real-time attack identification.

97 MATHEMATICS AND COMPUTING↗

Resilient Design of Continuous-time Distributed Optimization Algorithm in the Presence of Cyber-attacks

This paper presents a continuous-time resilient distributed optimization algorithm based on competitive interaction design method on connected graphs in the presence of adversaries. Here, the competitive interaction method allows us to design a network that protects the multi-agent systems from adversaries without requiring high network connectivity. In addition, the proposed algorithm does not require the global information about the number of adversaries. First, we show that the proposed distributed algorithm solves the resilient distributed optimization problem with no attack on the communication links. Second, we show that the proposed continuous-time distributed optimization algorithm on connected graphs converges to the small neighborhood of the optimal solution in the presence of cyber-attacks onto the communication channel. Simulations are presented to illustrate our theoretical results.

97 MATHEMATICS AND COMPUTING↗

Cyber-Attack Identification of Synchrophasor Data Via VMD and Multifusion SVM

A large amount of synchrophasor data in the wide area measurement system (WAMS) needs to be collected and transmitted to the phasor data concentrator, thereby increasing the possibility of being attacked by hackers. The attacked data are therefore hidden into the normal synchrophasor data so that the synchrophasor data based application will be affected. To remedy this problem, an identification framework is proposed to detect the data cyber-attack in WAMS utilizing variational mode decomposition (VMD) and multifusion support vector machine (MSVM). First, VMD is used to transform the attacked data into multiple modal components. Thereafter, a novel MSVM is employed to classify the deterministic features using the proposed linear combined multikernel (LCM). Further, this LCM can fuse multiple types of features, including the time, frequency, and statistical domains of the synchrophasor data. Utilizing the actual data from FNET/GridEye, different experiments are conducted under multiple attack strengths and types. The results demonstrate that the identification framework has higher precision and robustness compared with other conventional classifiers.

97 MATHEMATICS AND COMPUTING↗

Cyber Attack Sequences Generation for Electric Power Grid

Security assessment of cyber-physical energy systems (CPESs) such as the electric power grid is a critical operation to maintain availability, reliability, and quality of service in the presence of persistent threats from malicious cyber actors. Existing security assessment approaches such as penetration testing and red teaming rely on subject matter expert experience and forensic cyber analysis of historical events to perform realistic, threat-informed assessments of CPES defense. CPESs have a large attack surface because of the heterogeneity and complexity of underlying topology, devices, measurements, and vulnerabilities. The aforementioned approaches lead to partial coverage of the attack surface with a large set of unknown but possible exploits. There is a need to automate the CPES attack surface discovery and contextualize it for relevant, highly probable, real-world attack scenarios. We propose a methodology and framework to facilitate the discovery of the CPES attack surface. We present a multilayer attack graph with ranked attack sequences to describe CPES failure scenarios. We present a work-in-progress framework that lists key components to automate the attack modeling and sequence generation. We demonstrate the published National Electric Sector Cybersecurity Organization Resource CPES failure scenario to highlight the trustworthiness of generated attack sequences.

Dutta, Ashutosh↗

Two-Stage Optimization Framework for Detecting and Correcting Parameter Cyber-Attacks in Power System State Estimation

One major tool of Energy Management Systems for monitoring the status of the power grid is State Estimation. Since the results of state estimation are used within the energy management system, the security of the state estimation process is most important. The focus research in this area is on detecting False Data Injection attacks on measurements. While this is important, State Estimation also rely on database that are used to describe the relationship between measurements and systems' states. This paper presents a two-stage programming framework to detect and correct attacks in the parameters of the measurement model used by the state estimation process in the Energy Management System. In the first stage, an estimate of the line parameters ratios are obtained. In the second stage, the estimated ratios from stage I are used in a Bi-Level model for obtaining a final estimate of the measurements' model parameters. Hence, the presented framework does not only unify the detection and correction in a single optimization run, but also provide a monitoring scheme for the SE database that is typically considered static. In addition, in the two stages, linear programming framework is preserved. For validation, the IEEE 118 bus system is used for implementation. The results of this paper illustrate the effectiveness of the proposed model for detecting attacks in the database used in the state estimation process.

state estimation, two-stage optimization, cyber-ph↗