Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “denial of service”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Feasibility of critical infrastructure protection using network functions for programmable and decoupled ICS policy enforcement over WAN

Industrial control systems (ICS) represent a major component of our critical infrastructure. With the increasing need for more control and monitoring of such systems, ICS have seen an increase in connectivity to wide area networks (WAN) exposing aging equipment to rapidly evolving cybersecurity threats. Furthermore, the ICS data requires a reliability measure from the networks for critical functions for infrastructure monitoring and control. Especially when remote plant sites are involved such as pipelines, energy distribution networks, and transportation, WAN transport impairments most often provide a best effort delivery with no strict reliability guarantees. Network functions can provide a vendor agnostic, programmable critical infrastructure protection with a single maintenance, policy determination, and reliability assurance surface. A network function (NF) can be utilized for policy enforcement over the communication between remote entities and the main control office. This paper presents the research on transparent integration with existing ICS without disrupting communications, resulting in minimal downtime while decoupling the fast paced evolution of defensive security measures from the upgrade cycle of expensive long term hardware. We report our measurements on the resource requirements and overhead in the network for successful NF insertion under a wide variety of network impairments (network packet delay, reordering, and loss). Our paired NF implementation provides a policy enforcement platform extensible to cover myriad cybersecurity-related communication goals, including packet signing for verification, encryption for data privacy, packet filtering and data diode operation (i.e. protecting against eavesdropping, packet injection, and denial-of-service). Furthermore, bundling communication specifications into packet flows allows for tunability in applying policies as coarse- or fine-grained as the needs of the operator. We report on network function resource requirements in the form of required queue depth and network utilization overhead to inform the decision making against hardware cost constraints.

42 ENGINEERING↗

Design and evaluation of a cyber‐physical testbed for improving attack resilience of power systems

Abstract A power system is a complex cyber‐physical system whose security is critical to its function. A major challenge is to model, analyse and visualise the communication backbone of the power systems concerning cyber threats. To achieve this, the design and evaluation of a cyber‐physical power system (CPPS) testbed called Resilient Energy Systems Lab (RESLab) are presented to capture realistic cyber, physical, and protection system features. RESLab is architected to be a fundamental platform for studying and improving the resilience of complex CPPS to cyber threats. The cyber network is emulated using Common Open Research Emulator (CORE), which acts as a gateway for the physical and protection devices to communicate. The physical grid is simulated in the dynamic time frame using Power World Dynamic Studio (PWDS). The protection components are modelled with both PWDS and physical devices including the SEL Real‐Time Automation Controller (RTAC). Distributed Network Protocol 3 (DNP3) is used to monitor and control the grid. Then, the design is exemplified and the tools are validated. This work presents four case studies on cyberattack and defence using RESLab, where we demonstrate false data and command injection using Man‐in‐the‐Middle and Denial of Service attacks and validate them on a large‐scale synthetic electric grid.

Sahu, Abhijeet↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

Cross-Layered Distributed Data-Driven Framework for Enhanced Smart Grid Cyber-Physical Security

Smart Grid (SG) research and development has drawn much attention from academia, industry and government due to the great impact it will have on society, economics and the environment. Securing the SG is a considerably significant challenge due the increased dependency on communication networks to assist in physical process control, exposing them to various cyber-threats. In addition to attacks that change measurement values using False Data Injection (FDI) techniques, attacks on the communication network may disrupt the power system's real-time operation by intercepting messages, or by flooding the communication channels with unnecessary data. Addressing these attacks requires a cross-layer approach. In this paper a cross-layered strategy is presented, called Cross-Layer Ensemble CorrDet with Adaptive Statistics(CECD-AS), which integrates the detection of faulty SG measurement data as well as inconsistent network inter-arrival times and transmission delays for more reliable and accurate anomaly detection and attack interpretation. Numerical results show that CECD-AS can detect multiple False Data Injections, Denial of Service (DoS) and Man In The Middle (MITM) attacks with a high F1-score compared to current approaches that only use SG measurement data for detection such as the traditional physics-based State Estimation, Ensemble CorrDet with Adaptive Statistics strategy and other machine learning classification-based detection schemes.

cyber-physical security↗

Virtual Agents-Based Attack-Resilient Distributed Control for Islanded AC Microgrid

Due to its dependence on a communication network, distributed secondary control of microgrids is susceptible to denial-of-service (DoS) attacks in channel shutdown mode, which may negatively impact the network connectivity and thus deteriorate the coordination and power sharing among distributed generators (DGs). Honeypot is a common method for cyber deception by introducing fake targets. However, in the context of microgrid, the misleading information spread by honeypots will also impact the system performance. This paper proposes an attack-resilient distributed control for AC microgrids utilizing virtual agents (VAs) to counteract both DoS edge and node attacks. The VAs are designed to not impact the system’s steady state during normal operation but to share information among neighboring real agents and serve as dummy targets for DoS attacks. The control with VAs is implemented by a primal-dual gradient based distributed algorithm to efficiently obtain a practical solution for voltage/frequency regulation and power sharing. The simulation results on a 4-DG test system and a modified IEEE 34-bus system show that 1) VAs do not impact the normal functionality of the test system, and 2) deploying VAs can enhance the resilience of the microgrid control against DoS edge and node attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Autonomous Cyber Defense Against Dynamic Multi-strategy Infrastructural DDoS Attacks

Dynamic Infrastructural Distributed Denial of Service (I-DDoS) attacks constantly change attack vectors to congest core backhaul links and disrupt critical network availability while evading end-system defenses. To effectively counter these highly dynamic attacks, defense mechanisms need to exhibit adaptive decision strategies for real-time mitigation. This paper presents a novel Autonomous DDoS Defense framework that employs model-based reinforcement agents. The framework continuously learns attack strategies, predicts attack actions, and dynamically determines the optimal composition of defense tactics such as filtering, limiting, and rerouting for flow diversion. Our contributions include extending the underlying formulation of the Markov Decision Process (MDP) to address simultaneous DDoS attack and defense behavior, and accounting for environmental uncertainties. We also propose a fine-grained action mitigation approach robust to classification inaccuracies in Intrusion Detection Systems (IDS). Additionally, our reinforcement learning model demonstrates resilience against evasion and deceptive attacks. Evaluation experiments using real-world and simulated DDoS traces demonstrate that our autonomous defense framework ensures the delivery of approximately 96 - 98% of benign traffic despite the diverse range of attack strategies.

Dutta, Ashutosh↗

Moving Target Defense Routing for SDN-enabled Smart Grid

The increasing attack surface area in the smart grid communication networks is making the grid more susceptible to cyber attacks that can lead to instability of the grid and even blackouts. While there are multiple types of cyber attacks that can impact the grid, Denial of Service (DoS) attacks are relatively easier to inject as they require lesser knowledge about the system as compared to data integrity attacks. Various research works showcase methods to prevent or mitigate the impacts of DoS attacks in the smart grid but the research still lacks in demonstrating the feasibility and efficacy of the solutions in a real-world environment. In this paper, we propose a Moving Target Defense (MTD)-enabled Software Defined Network (SDN) for the Smart Grid communication implemented on a Hardwarein- the-Loop (HIL) Testbed. We showcase the implementation of the proposed architecture of MTD-enabled SDN using Mininet 2.3.0 which enables communication between the physical grid and the control center. The results show the advantages of using MTD based on SDN for the wide-area network (WAN) with much lower packet drop percentages in the case of MTD-based routing in the SDN WAN. Index Terms—SDN,

97 MATHEMATICS AND COMPUTING↗

A Typology of Quantum-Classical Faults

This paper introduces an extended taxonomy of faults specific to hybrid quantum-classical systems, addressing the unique challenges that arise from integrating quantum accelerators into high-performance computing (HPC) infrastructures. Building on the foundational fault classification by Avizienis et al., we incorporate fault types unique to quantum computing-such as qubit decoherence, spontaneous gate errors, and photon loss-alongside traditional and human-induced faults including development errors, operational mistakes, and malicious attacks. Our taxonomy classifies faults by their origin (natural vs. human-made), intent (accidental, deliberate non-malicious, or malicious), system boundaries (internal vs. external), and persistence (transient to permanent). We also explore how different architectural integration patterns-ranging from tight coupling to loose on-premise and cloud-based configurations-shape the manifestation and propagation of faults. These scenarios are analyzed in terms of timing mismatches, interface inconsistencies, and security threats such as data tampering and denial-of-service attacks. Through this fault-centric lens, we aim to support the co-design of dependable quantum-classical systems and highlight the critical role that integration strategies play in ensuring reproducibility, resilience, and security across hybrid computing platforms.

Giusto, Edorado [University of Naples Federico II,↗

Time Sequence Machine Learning-Based Data Intrusion Detection for Smart Voltage Source Converter-Enabled Power Grid

Smart inverters of distributed energy resources can enable cloud computing, condition monitoring, result visualization, remote control, and peer-to-peer energy trading in advanced power systems. However, the advent of data injection attacks in the communication architecture can alter measurement characteristics of power grids and have devastating consequences. In this article, we propose a time sequence machine learning-based anomaly detection methodology for detecting cyber intrusion into control signal setpoints and dc voltage signal measurement bias of the voltage source converter (VSC) in wind generators. We first investigated the effects of four types of denial of service, tampering signal, and stealthy-type data intrusion attacks on smart VSCs and overall wind farms. We then proposed a novel time sequence machine learning-based intrusion detection framework that can be implemented to detect different cyberattacks in the VSCs. The performance of the proposed framework has been compared with that of autoencoder and clustering-based intrusion detection framework. The proposed framework was validated by using the IEEE 39 bus power system in the presence of four wind farms in different locations. Using several metrics for intrusion detection performance, we validated the effectiveness of the proposed framework.

42 ENGINEERING↗

Cybersecurity Challenges in Low-Inertia Power-Electronics-Dominated Grids

Here, the low inertia characteristics of the power electronics dominated grid (PEDG) introduces challenges while restoring voltage and frequency to their nominal values. These stability challenges create new cybersecurity vulnerabilities that are not thoroughly discussed in the literature. Cyber events such as false data injection (FDI), denial of service (DoS), man-in-the-middle attacks, stealthy attacks, and advanced persistent threats target PEDG to disrupt grid stability or gain financial benefits. The low inertia of PEDG (< 2s) compared to traditional grids (~10s) exacerbates these vulnerabilities. In response to stealthy attacks on state variables that supervisory layers cannot detect until significant harm occurs, the low inertia characteristics of PEDG offer substantial stealthy attack surfaces. To counteract such threats, PEDG must be equipped with ultra-fast real-time anomaly detection system and trajectory prediction mechanism to achieve effective cyberattack resiliency.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Novel control solutions for DoS attack delay mitigation in grid-connected and standalone inverters

This paper introduces two novel control solutions, which allow localised delay compensation for grid-connected and standalone inverters. As the prediction horizon of the existing controllers are quite small as compared to large communication delays and information unavailability due to denial-of-service (DoS) attacks, the proposed strategy offers a robust delay mitigation range using localized dynamics. Its design philosophy is leveraged via a prediction policy using the inner control loop dynamics. Based on different control objectives in grid-connected and standalone mode, the proposed solutions have been augmented into the control system accordingly. Finally, its robustness under various communication delay and DoS attacks have been tested.

Roig Greidanus, Mateo D.↗

Identification of a Delay Attack in the Secondary Control of Grid-Tied Inverter Systems

This work is developed for the identification of a denial-of-service cyberattack on the secondary controller of inverter systems which is connected to the power grid. The identification is made through the dynamic response of the reactive power (Q) of the system under attack. By observing the dynamic characteristic of Q, it is possible to correlate the attack with the nominal response of the hierarchical controller. The article shows that the occurrence of the attack can be identified through a supervisory control that runs a model in parallel. The article argues that after an early identification of the attack, a local controller can take action to mitigate its effects on the system’s response.

Roig Greidanus, Mateo D.↗

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation

Advanced persistent threats and cyberattacks can impact wide-area monitoring, protection, and control (WAMPAC) system operation. Many cyber-physical system (CPS) testbeds have been developed for attack-defense experimentation and attack-resiliency tools evaluation for WAMPAC, but they are limited to a simulation-and-emulation based environment. This paper presents a quasi-realistic CPS attack-defense testbed-based framework for WAMPAC applications using the industrial substation and control center platforms such as eTerra integrated with the hardware-in-the-loop CPS smart grid testbed available at Iowa State University. The proposed framework includes various combinations of industry-grade substation and control center platforms, communication topologies, real-time digital simulators, and a novel cyber-physical distributed intrusion-and-anomaly detection system (D-IADS) for WAMPAC applications. The D-IADS includes a master at the control center and geographically distributed sensor devices at each substation. Each D-IADS sensor deployed at a substation or control center network monitors ingress and egress traffic, detect intrusions, and dispatch alerts to the D-IADS master. The D-IADS master centrally monitors and analyze the alerts and controls D-IADS sensors. We considered an EMP60 synthetic CPS grid as a case study to demonstrate the framework and proposed D-IADS for WAMPAC applications against cyberattack vectors such as Man-in-the-Middle DNP3 attack, denial-of-service, and data-integrity attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

DER Cybersecurity Detection and Response Suite

SAND2024-08475O The Distributed Energy Resource (DER) Cybersecurity Detection and Response Suite is a solution for distributed energy resource (DER) systems. The DER Security Orchestration, Automation, and Response (SOAR) solution that uses alerts from signature- and behavior-based Intrusion Detection Systems are intended to be deployed as bump-in-the-wire (BITW) devices in front of DER equipment. The fielded application would use multiple intrusion detection systems that report data to SOAR to respond to cyberattacks. The suite consists of two software components: • The proactive intrusion detection and mitigation system (PIDMS) secures grid-edge photovoltaic smart inverters and other equipment in distributed energy resource systems. It is a distributed BITW solution; cyber and physical data are automatically processed using network inspection tools and custom machine learning algorithms to detect abnormal events and correlate cyber-physical events. • The Security Orchestration, Automation, and Response for Distributed Energy Resources (SOAR4DER) application ingests data from several intrusion detection systems to quickly block attacks and revert DER systems to good states. Using a collection of intrusion detection system technologies on a BITW device, it incorporates physical and cyber data to detect abnormal and potential malicious behaviors. Multiple SOAR playbooks then use the intrusion detection system data streams to automatically defend the system. SOAR4DER system testing showed detection and response times under 30 seconds for all adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute-force logins, and machine-in-the-middle attacks. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Johnson, Jay↗

Gap Analysis of Supply Chain Cybersecurity for Distributed Energy Resources

A supply chain is the combination of the ecosystem of resources needed to design, manufacture, and distribute a product. In the context of supply chain cybersecurity, the resources that directly influence this ecosystem include software, data, and/or other digital components. Compromised equipment or software in the supply chain may lead to attacks such as financial loss; denial of service; a breach of confidential or proprietary information from a company, its customers, or its suppliers; ransomware that denies operation of automated equipment for payment; and malicious control actions that could damage equipment and endanger personnel. Currently 60.8% of US energy comes from fossil fuels, 18.9% comes from nuclear energy, and the last 20.1% comes from renewable sources. Federal Energy Regulatory Commission order FERC 2222 and Executive Order 14017 on America's Supply Chains are important milestones for safely expanding generation from renewable energy and achieving the goal of a decarbonized U.S. energy sector by 2035. This report analyzes gaps and opportunities in the supply chain currently available to the renewable energy sector, to help stakeholders formulate a coordinated response.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Secure Data Logging and Processing with Blockchain and Machine Learning (Final Report)

Secure Data Logging and Processing with Blockchain and Machine Learning (ML) research is focused on the development of a platform to securely log and process sensor data in fossil power plants. The platform integrates two emerging technologies, blockchain and ML, and incorporates several innovative mechanisms to ensure the integrity, reliability, and resiliency of power systems. The goal is to protect the power plant from various cyberattacks such as false data injection and denial of service attacks using these technologies. The research goal was enabled by the following Research Project Objectives: 1) Secure authentication and identity verification of sensor nodes, actuators, and other equipment within a network. 2) Development of mechanisms that ensure only data sent by legitimate sensors are accepted and stored in the data repository. 3) Development of data aggregation methodologies using ML / Deep Learning (DL) algorithms to minimize noise / faulty data. 4) Implementation of the blockchain technologies to provide data security using secured IOTA framework & nodes.

20 FOSSIL-FUELED POWER PLANTS↗

National Security Programs - Cyber: MMAREJBLIGE – Modular Multi Agent Grid Emulation for Joined Breakdowns in Linked Generative Emulations - 23-0644

Modular Multi Agent Grid Emulations for Joined Breakdowns in Linked Generative Emulations (MMAREJBLIGE) introduces an agent-based modeling framework into real-time cyber-physical emulation to achieve a context-aware environment that introduces operator/attacker/external-condition variability to improve emulation fidelity and testing rigor. We detail our agent framework design, internal communication via message passing, and time synchronization, as well as the individual components of the system. We include a brief analysis of several scenarios run on a real-time, hardware-in-the-loop, Industrial Control Systems (ICS) test-bed which include normal operation, physical disruption, disruption with mitigation, and disruption with mitigation during a cyber denial-of-service (DOS) attack.

42 ENGINEERING↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗