Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Design Considerations for Distributed Energy Resource Honeypots and Canaries

There are now over 2.5 million Distributed Energy Resource (DER) installations connected to the U.S. power system. These installations represent a major portion of American electricity critical infrastructure and a cyberattack on these assets in aggregate would significantly affect grid operations. Virtualized Operational Technology (OT) equipment has been shown to provide practitioners with situational awareness and better understanding of adversary tactics, techniques, and procedures (TTPs). Deploying synthetic DER devices as honeypots and canaries would open new avenues of operational defense, threat intelligence gathering, and empower DER owners and operators with new cyber-defense mechanisms against the growing intensity and sophistication of cyberattacks on OT systems. Well-designed DER canary field deployments would deceive adversaries and provide early-warning notifications of adversary presence and malicious activities on OT networks. In this report, we present progress to design a high-fidelity DER honeypot/canary prototype in a late-start Laboratory Directed Research and Development (LDRD) project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Identification and Testing of Electric Vehicle Fast Charger Cybersecurity Mitigations

Fast-charging infrastructure for electric vehicles (EVs) is needed to enable and achieve the national goals of transitioning the vehicle fleet toward more electrification. Idaho National Laboratory, Oak Ridge National Laboratory, and the National Renewable Energy Laboratory (NREL) have jointly worked to identify, evaluate, and mitigate potential cyber-related consequences associated with fast charger systems. NREL contributed by considering cyberattack scenarios and consequences associated with integrating distributed energy resources (DERs) at fast-charging stations. The dynamic nature of fast-charger load profiles would encourage site operators to incorporate solar for energy cost reduction and energy storage for peak demand cost management at future charging facilities with multiple fast chargers at a site. These energy resources would be monitored and coordinated via a site energy management controller with data exchange between devices and local power metering infrastructure; thus, networking between devices and the design of the system becomes important in the overall cybersecurity posture. In addition, component vendors and system operators might have remote interfaces to any of these systems. It is therefore important to understand the breadth of the cyberattack surface and potential strategies to mitigate impacts. This project has focused on components and protocols expected to be found within a local charging site that includes multiple chargers and DER resources. Our methods and results are summarized in this final report.

42 ENGINEERING↗

Cybersecurity for Electric Vehicle Charging Infrastructure

As the U.S. electrifies the transportation sector, cyberattacks targeting vehicle charging could impact several critical infrastructure sectors including power systems, manufacturing, medical services, and agriculture. This is a growing area of concern as charging stations increase power delivery capabilities and must communicate to authorize charging, sequence the charging process, and manage load (grid operators, vehicles, OEM vendors, charging network operators, etc.). The research challenges are numerous and complicated because there are many end users, stakeholders, and software and equipment vendors interests involved. Poorly implemented electric vehicle supply equipment (EVSE), electric vehicle (EV), or grid operator communication systems could be a significant risk to EV adoption because the political, social, and financial impact of cyberattacks — or public perception of such — would ripple across the industry and produce lasting effects. Unfortunately, there is currently no comprehensive EVSE cybersecurity approach and limited best practices have been adopted by the EV/EVSE industry. There is an incomplete industry understanding of the attack surface, interconnected assets, and unsecured inter faces. Comprehensive cybersecurity recommendations founded on sound research are necessary to secure EV charging infrastructure. This project provided the power, security, and automotive industry with a strong technical basis for securing this infrastructure by developing threat models, determining technology gaps, and identifying or developing effective countermeasures. Specifically, the team created a cybersecurity threat model and performed a technical risk assessment of EVSE assets across multiple manufacturers and vendors, so that automotive, charging, and utility stakeholders could better protect customers, vehicles, and power systems in the face of new cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilient Energy Delivery and Control Systems (REDCS) (Final Technical Report)

US critical infrastructure is increasingly the target of cyberattacks, where disturbances could cause considerable damage and disruption. To help provide a new layer of cyber-physical protection for one key energy delivery system, natural gas pipelines, GE Vernova Advanced Research along with partners Florida State University and Intel Corporation created an innovative technology called "Resilient Energy Delivery and Control Systems" (REDCS). This cybersecurity package helps detect anomalies caused by cyberattacks, isolate the subsystem being impacted by the attack, and provide functions that can allow for resiliency – giving better situational awareness to the operators and cybersecurity specialists or in the future perform closed loop control for continued operation while compromised.

03 NATURAL GAS↗

Cybersecurity Considerations for Grid-Connected Batteries with Hardware Demonstrations

The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.

25 ENERGY STORAGE↗

Investigating the Vulnerabilities of the Direct Transfer Trip Scheme for Network Protector Units in the Secondary Networks of Electric Power Distribution Grids

Network protector units (NPUs) are crucial parts of the protection of secondary networks to effectively isolate faults occurring on the primary feeders. When a fault occurs on the primary feeder, there is a path of the fault current going through the service transformers that causes a negative flow of current on the NPU connected to the faulted feeder. Conventionally, NPUs rely on the direction of current with respect to the voltage to detect faults and make a correct trip decision. However, the conventional NPU logic does not allow the reverse power flow caused by distributed energy resources installed on secondary networks. The communication-assisted direct transfer trip logic for NPUs can be used to address this challenge. However, the communication-assisted scheme is exposed to some vulnerabilities arising from the disruption or corruption of the communicated data that can endanger the reliable operation of NPUs. This paper evaluates the impact of the malfunction of the communication system on the operation of communication-assisted NPU logic. To this end, the impact of packet modification and denial-of-service cyberattacks on the communication-assisted scheme are evaluated. The evaluation was performed using a hardware-in-the-loop (HIL) co-simulation testbed that includes both real-time power system and communication network digital simulators. This paper evaluates the impact of the cyberattacks for different fault scenarios and provides a list of recommendations to improve the reliability of communication-assisted NPU protection.

direct transfer trip↗

Cybersecurity Resiliency of Marine Renewable Energy Systems-Part 1: Identifying Cybersecurity Vulnerabilities and Determining Risk

Technology innovation, market demand, and the potential impacts of a changing climate are driving the marine renewable energy (MRE) industry to develop market-ready systems to provide low-carbon electricity for emerging, off-grid markets. The advanced operational and information technology devices used in MRE systems create a pathway for a cyber threat actor to gain unauthorized access to data or disrupt operation. To improve the resiliency of MRE systems as a predictable, affordable, and reliable source of energy from oceans and rivers, guidance was developed for an end users' organization that describes a framework for identifying and managing cybersecurity risk. The development of the cybersecurity guidance is based on standards described in the Risk Management Framework and Cybersecurity Framework developed by the National Institute of Standards and Technology (NIST). This paper is the first of a two-part series that describes an approach to determine the cybersecurity risk for MRE systems based on assessing potential cyber threats, identifying vulnerabilities (people, processes, and technology, including physical and operational environment), and evaluating the consequences a cyberattack would have on operation of the MRE system and impact on end users' mission and business objectives. MRE developers and stakeholders can use this approach to assess their current cybersecurity risk posture to incorporate appropriate cybersecurity controls to reduce the consequences and impacts from a cyberattack on MRE systems. This approach can be refined further as MRE systems are deployed and operational configurations are available.

97 MATHEMATICS AND COMPUTING↗

The CYBER security – Competency Health and Maturity Progression (CYBER-CHAMP) model: Extending the National Initiative for Cybersecurity Education (NICE) Framework Across Organizational Security

Problem Statement: There is a pervasive talent deficit in the cybersecurity industry that prevents employers from being able to fill their open positions efficiently. A holistic approach to security is required to ensure organizations have adequate prevention and response capabilities in case of a cyberattack. Specifically, industrial control systems (ICS’s) and their operational technology (OT) components have become a constant target for cyberattacks. Research Questions: It is proposed that the NICE Framework should be extended in the following areas: 1) Include guidance regarding the job roles and competencies for both IT and OT professionals. 2) Offer step-by-step solutions, based on the work role mappings from the NICE Framework, to increase cybersecurity through employee training and education. 3) Provide a streamlined, lifecycle approach to building a cybersecurity program. Contribution: The CYBER security – Competency Health and Maturity Progression (CYBER-CHAMP©) model provides a customized solution for businesses to understand their education gaps in organizational security and target areas for improvement. Rationale: The Framework for Improving Critical Infrastructure Cybersecurity v1.1 addresses ICS but does not offer a measurement of cybersecurity maturity or clear methods to ascertain an organization’s current risk profile. In Phases 1 and 5 of the model, measurements are provided to help an organization build their current and target risk profiles. The NICE framework provides a structure for planning an IT cybersecurity workforce, but the OT aspects of cybersecurity are only briefly discussed. The model uses Phases 2-3 to examine the competencies of an organization’s workforce, which includes both IT and OT roles. Current frameworks do not offer next steps to increase an organization’s cybersecurity. During Phase 4, employees’ roles are mapped to training, education, and/or certifications from common vendors. Investigative Approach: The model provides measurements and metrics for both an organization’s status and continual improvement. This improvement methodology includes guidance for creating an overall strategic plan for security improvement via products designed to increase an organization’s operational readiness through workforce competency health. Lessons Learned: Depending on who was participating, there were contradicting answers given in Phase 1 due to different security cultures in the organization. This revelation has influenced the steps listed in the User’s Guide, where Phase 1’s first recommended step is to assemble a team that champions the facilitation and implementation of the model in the organization. During Phase 2, the discovery was made that organizations may be missing roles that are necessary to perform critical cybersecurity functions. By understanding the functional roles and competencies needed, they can contract or hire cybersecurity help to fill these gaps. Implications: Using the model, organizations can discuss quantitative measures for improvement as a business case for advancing their security program. Future research can validate and extend the present theory and model to a variety of environments. It is of interest to investigate additional security roles and knowledge domains that are used to build standardized cybersecurity curriculum.

97 MATHEMATICS AND COMPUTING↗

Attacking the IEC-61131 Logic Engine in Programmable Logic Controllers in Industrial Control Systems

In industrial control systems (ICS), programmable logic controllers (PLCs) directly monitor and control a physical process such as nuclear power plants, gas pipelines, and water treatment. They are equipped with a control logic written in IEC-61131 languages (e.g., ladder logic and structured text) that defines how a PLC should control a physical process. A PLC's control logic is a usual target of a cyberattack to sabotage a physical process. For instance, Stuxnet targets a control logic of a Siemens S7-300 PLC to damage a nuclear facility's centrifuges. The existing attacks in the literature generally focus only on injecting malicious control logic into a PLC. This paper presents a new dimension of control logic attacks that target the control logic engine (responsible for running a control logic) of a PLC. It demonstrates that a cyberattack can disable the control logic engine successfully by exploiting inherent PLC features such as program mode and starting/stopping engine. We develop two novel case studies on control logic engine attacks by employing the MITRE ATT\&CK knowledge base on the real-world PLCs used in industry settings, i.e., 1) Schweitzer Engineering Laboratory (SEL)'s Real-Time Automation Controller (SEL-3505 RTAC) equipped with security features such as encrypted traffic and device-level access control, and 2) traditional PLCs, i.e., Schneider Electric's Modicon M221, Allen-Bradley's MicroLogix 1400 and 1100 that do not have security features. The case studies present the internals of the logic engine attacks and facilitate the ICS research community and industry to understand the attack vectors on the control logic engine. We evaluate the effectiveness of the control engine attacks on a power substation, a 4-floor elevator, and a conveyor belt to demonstrate their real-world impact of halting a physical process.

Ali qasim, Syed↗

Cybersecurity for Electric Vehicle Fast-Charging Infrastructure: Preprint

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

47 OTHER INSTRUMENTATION↗

Cybersecurity for Fast Charging EV Infrastructure

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

ADVANCED PROPULSION SYSTEMS,POWER TRANSMISSION AND↗

EVSE Cybersecurity and Resilience

Consequence-driven Cybersecurity Analysis for Extreme Fast Charging Electric Vehicle Infrastructure Electric vehicle (EV) development and associated charging infrastructure are expected to advance rapidly. Thirty percent of all global vehicle sales may be EVs and hybrid EVs by 2025, and they will rely on increasingly sophisticated strategies for grid integration. Next-generation EV charging infrastructure is expected to include interconnected renewable resources, such as photovoltaic (PV) arrays and battery storage systems, along with grid-edge devices. Although distributed energy resources (DERs) are useful in several ways, such as peak shaving at high demand times and backup supply for added resilience, the integration of vehicle charging and DERs could create more avenues for cyberattack. Physical and/or remote access to EV charging station components, including charge ports, power electronics, controllers, and local generation (e.g., PV and energy storage) could be paths to cause power fluctuations, leading to altered operations at the charging station, escalated privileges to administrative systems, exfiltration of financial information (including personally identifiable information), and reduced grid stability. One compromised EV supply equipment component can open the door to a variety of exploitable vulnerabilities. Cloud computing and mobile application control have the potential to expand the threat surface to non-repudiation and firmware integrity challenges. Vendor clouds have access to hundreds of chargers, and if compromised, can scale the attack surface exponentially. The high power and voltage levels of xFC infrastructure (e.g., 400 kW at 1000- V DC) increase the hazards and ability to impact the grid and vehicles more than lower-power charging systems. Legacy communications systems and protocols could also put EV infrastructure at risk of cyberattacks requiring a robust patch management process. Communications networks link EVs and chargers to several stakeholders - including charging station operators, grid operators, vendors/manufacturers, and aggregators - who have both physical and network access to share information for control, monitoring, and analytics. Information in these networks that is vulnerable to compromise includes the state of charge, charging duration, payment information, electricity price, and load control. Analyzing and prioritizing these interconnections risks could help address cybersecurity related to data leakage and manipulation.

charging↗

Cybersecurity concerns for the energy sector in the maritime domain

The world has seen a number of high-profile maritime disasters in recent months and years, and has felt the impact of them. At the same time, the world has also seen a number of high-profile cyberattacks. It has felt their impact, as well. And, likely no sector has been more affected by the maritime and cyber incidents than the energy sector, as fuel prices often spike or trough, and access to energy resources can become an instant source of concern, tension, or even conflict. As energy sectors—in all their forms—continue to rely on the maritime domain or even increase that reliance, they must be mindful that traditional maritime threats—like piracy, theft, and weather events—are not the only threats they face today. Maritime cybersecurity concerns are among the most potentially disruptive to energy-sector interests and, yet, are among the least understood and least addressed. This paper identifies nine areas in which the energy sector faces harmful cyber vulnerabilities in the maritime domain, to provide enough insight and examples to allow for action to be taken to reduce the risk of harm from these different vulnerabilities. The paper develops the example of offshore wind energy to model how to assess cyber considerations more fully. Ultimately, it concludes with a series of recommendations that offer policymakers, energy-sector actors, and security and law-enforcement professionals steps to minimize the exposure of the maritime energy sector to harmful cyberattacks.

99 GENERAL AND MISCELLANEOUS↗

Electric Vehicle Supply Equipment Cybersecurity Through Emulation

As the grid evolves, it is paramount to understand the risks that cyberattacks pose before assets are deployed. Leveraging the ARIES Cyber Range, NREL has created a platform to conduct analysis of EV charging protocol cybersecurity to understand the risks and impacts that cyberattacks may pose to critical infrastructure.

bug bounty prize↗

Employing a Hardware-in-the-Loop Approach to Realize a Fully Homomorphic Controller for a Small Modular Advanced High Temperature Reactor

This paper addresses the cybersecurity challenges of advanced nuclear reactors by integrating fully homomorphic encryption (FHE) into their control systems, enabling encrypted processing of control signals without compromising functionality. Advanced nuclear reactors, including Small Modular Reactors (SMRs) and microreactors, aim to achieve autonomous and remote operations, reducing costs and enhancing competitiveness. However, these advancements expand the attack surface for cyberattacks, particularly in autonomous and remote operation scenarios. Cyberattacks can exploit vulnerabilities to manipulate physical processes, causing shutdowns, asset damage, or public harm. Such attacks begin with passive reconnaissance, where adversaries intercept communications or observe behaviors to gather information, which is then leveraged to execute cyber-physical attacks by injecting malicious commands. Nuclear power must adopt cybersecurity protection measures to secure the integrity and availability of their digital control systems. This paper demonstrates the application of FHE to secure operations by enabling encrypted processing of sensitive signals and parameters -- ensuring privacy without exposing data. FHE supports secure mathematical operations on encrypted data without requiring decryption. Using a hardware-in-the-loop (HIL) approach, this paper implements an FHE-integrated controller on a BeagleBone Black (BBB) controlling a simulation of the Small Modular Advanced High Temperature Reactor (SmAHTR). By doing so, the encrypted controller protects the integrity of critical set points and control signals during transmission and processing. Thus, FHE-integrated controllers enhance secure operations of advanced nuclear reactors while maintaining functionality.

control systems↗

Data recovery via covert cognizance for unattended operational resilience

One of the important premises of unattended operation, a highly promoted characteristic of fission batteries and advanced microreactors, is the ability to automate the analysis of sensors data used in support of operational monitoring and control. Here, to meet this vision, this work proposes a new monitoring and data recovery paradigm to ensure resilience against data corruption which may be the result of malicious intrusion into the reactor operational network. This is paramount to ensure 100% availability under contingency scenarios such as cyberattacks. In support of this vision, earlier work has presented the concept of covert cognizance and demonstrated its mathematical ability to identify and embed cognizance parameters under the noise-dominated null space of the sensors data. This work extends this concept and applies it in real-time to demonstrate three key characteristics: zero-impact, zero-observability, and data recovery, where the first characteristic is to ensure no impact on operation, the second is immunity to discovery by pattern recognition techniques, and the third is to allow recovery of corrupt or falsified data. Recognizing that fission batteries are designed to operate under steady state most of the time, we elect to employ a small modular reactor model under transient operational conditions to demonstrate the operational resilience enabled by the covert cognizance paradigm. Specifically, the PI controller is augmented with the covert cognizance modules to develop self-awareness and enable automatic data recovery. The developed modules are expected to be equally applicable to a wide range of advanced reactor technologies relying on full or partial unattended control.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Time Sequence Machine Learning-Based Data Intrusion Detection for Smart Voltage Source Converter-Enabled Power Grid

Smart inverters of distributed energy resources can enable cloud computing, condition monitoring, result visualization, remote control, and peer-to-peer energy trading in advanced power systems. However, the advent of data injection attacks in the communication architecture can alter measurement characteristics of power grids and have devastating consequences. In this article, we propose a time sequence machine learning-based anomaly detection methodology for detecting cyber intrusion into control signal setpoints and dc voltage signal measurement bias of the voltage source converter (VSC) in wind generators. We first investigated the effects of four types of denial of service, tampering signal, and stealthy-type data intrusion attacks on smart VSCs and overall wind farms. We then proposed a novel time sequence machine learning-based intrusion detection framework that can be implemented to detect different cyberattacks in the VSCs. The performance of the proposed framework has been compared with that of autoencoder and clustering-based intrusion detection framework. The proposed framework was validated by using the IEEE 39 bus power system in the presence of four wind farms in different locations. Using several metrics for intrusion detection performance, we validated the effectiveness of the proposed framework.

42 ENGINEERING↗

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION↗