Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “distributed energy resources cybersecurity framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

70 records · Page 4

1.3.3.402 - Cybersecurity Value-at-Risk Framework

The Cybersecurity Value-at-Risk Framework tool will guide users through an assessment and detailed analysis of a hydropower plant's operations. The tool will then provide results and data to inform effective cybersecurity investment decision-making and planning. The results will help managers understand the risk probability of cyberattacks on their facilities and how best to use resources to mitigate those risks.

cybersecurity↗

Proactive Intrusion Detection and Mitigation System

SAND2023-05661O The proactive intrusion detection and mitigation system (PIDMS) provides grid-edge situational awareness for cybersecurity defense by capturing real-time distributed energy resource (DER) network traffic and performance data with a novel approach that improves the detection and prevention of cyber-physical attacks. The PIDMS addresses the grid-edge security gap with real-time analysis of both network traffic and photovoltaic performance data to deliver a novel, cyber-physical intrusion detection system (IDS) approach that increases the accuracy and effectiveness of detection and mitigation. This hybrid IDS analysis enables dual monitoring that increases the workload of the adversary; both cyber and physical data would have to be simultaneously spoofed to evade detection. Furthermore, monitoring and analyzing cyber data are insufficient in some cases. For example, in an insider threat aimed at disrupting inverter grid-support functions where proper credentials and authentication are achieved, only the altered PV performance would indicate abnormal behavior. All in all, the PIDMS provides novel capabilities for: • Distributed, real-time cyber-physical detection and mitigation analysis • Cybersecurity defense for grid-edge systems • Analysis framework that can provide situational awareness across the transmission, distribution, and DER systems The PIDMS sensor is designed to collect cyber-physical data, process the data using machine-learning algorithms, detect abnormal events, and deploy mitigations. With these goals, the main functional PIDMS objectives are: • Capability to collect cyber-physical data • Onboard storage of cyber-physical data • Peer-to-peer communication • Computationally efficient machine-learning algorithms • Online cyber-physical data analysis • Alerting/visualization capabilities • Mitigation deployment capability with bump-in-the-wire (BITW) implementation Each of these functional objectives enable PIDMS to perform effective cyber-physical intrusion detection and mitigation. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jones, Christian↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Guide for Distributed Wind Presentation

This presentation communicates information about the MIRACL project Resilience Metrics report and Resilience Framework report. It was created for the 2021 MIRACL advisory board meeting. Distributed wind sits at the intersection of grid-connected, off-grid and behind-the-meter cyber-physical electrical energy systems. The unique physical properties and communications requirements for distributed wind systems mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity. This presentation is intended to be a starting point for distributed wind stakeholders including manufacturers, installers and integrators, and operators (facility, aggregator, or utility). A holistic threat perspective is used to describe the adversaries, threats, and potential impacts of cyberattacks, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We present the recommendations for cybersecurity, both in terms of needs of the system and roles that specific stakeholders should fulfill. Distributed wind systems can come in a variety of architectures and applications, so there is no one-size-fits-all approach to cybersecurity. However, this document contains the relevant information for stakeholders to identify the cybersecurity needs of their system, refer to relevant standards, and apply best practices in a manner most consistent with their security and operational goals.

17 WIND ENERGY↗

Cybersecurity Value-at-Risk Framework

As more variable renewable energy sources are added to the grid, the role of hydropower as a reliable baseline and firming resource is growing more critical. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation methodology↗

Cybersecurity Value-at-Risk Framework: Preprint

As more variable renewable energy sources are added to the grid, the critical role of hydropower as a reliable baseline and firming resource is rapidly growing. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation↗

Automation for Distributed Energy Resources Risk Manager Using OSCAL

The risk management framework (RMF) provides a well-organized and thorough approach to diagnose information technology (IT) system threats, to gather required materials to comply with industry standards, and to document a plan for achieving authority to operate (ATO). ATO is given by the operating authority with the awareness of vulnerabilities that arise when operating the IT system. The primary goal of the National Renewable Energy Laboratory’s (NREL’s) distributed energy resource (DER) RM application is to provide a user-friendly interface and in-depth guidance for generating the authorization package for the authorizing official to review. In other words, the application satisfies steps 1 through 7 of the RMF process with a focus on DERs.

cybersecurity↗

Informing Cybersecurity Decisions With the Value-at-Risk Framework

Security at every site is critical to making hydropower a strong contributor to the country's grid, but with ongoing development and expanding capabilities, the diversity of the existing hydropower fleet makes across-the-board investment decisions difficult. The threat of cyberattacks naturally increases as the interconnection of Information Technology and Operational Technology networks broadens. Hydropower plants require custom analyses that are specific to the unique challenges and characteristics of any given facility. Facilities, however, often do not have the necessary resources for managers to make informed decisions on investments based on assessed capabilities and risks.

cybersecurity↗

Battery Energy Storage Systems Report

Battery energy storage systems (BESS) are a critical component of grid reliability and resilience today, providing rapid response capabilities while enabling grid modernization and capacity expansion across the United States. As utilities, communities, and customers prepare to deploy significant BESS capacity over the next several years, the United States has an opportunity to build security into battery system design and deployments. This report provides a framework for assessing the current dominance of foreign-manufactured components in the supply chains for BESS, inverter-based resources, and transformers. It offers high-impact, actionable solutions to service partners, industry, and government to address supply chain risks for currently installed, in design, and future deployments.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Risk Assessment Framework for Cyber-Physical Security in Distribution Grids with Grid-Edge DERs

Integration of inverter-based distributed energy resources (DERs) is reshaping the landscape of distribution grids to fulfill the socioeconomic, environmental, and sustainability goals. Addressing the technological challenges of DER grid integration requires an adaptive communication layer for efficient DER management and control. This transition has given rise to a cyberphysical system (CPS) architecture within the distribution system, causing new vulnerabilities for cyberphysical attacks. To better address potential threats, this paper presents a comprehensive risk assessment framework for cyberphysical security in distribution grids with grid-edge DERs. The framework incorporates a detailed CPS model accounting for dynamic DER characteristics within the distribution grid. It identifies vulnerabilities in DER communication systems, models attack scenarios, and addresses communication latency crucial for inverter control timescales. Subsequently, the quantification of attack impacts employs an attack probability model including both the vulnerability and criticality of cyber components. The proposed risk assessment framework was validated through testing on the modified IEEE 13-node and 123-node test feeders.

cyberattack↗

Autonomous Tools for Attack Surface Reduction (Final Report)

The electric power grid is a complex critical infrastructure that forms the lifeline of modern society, and its secure and reliable operation is of paramount importance to national security and economic wellbeing. However, recent findings documented in authoritative sources indicate the threat of cyber-based attacks growing in numbers and sophistication. However, securing the grid against stealthy cyberattacks is a challenging task due to legacy nature of the infrastructure coupled with dynamic nature of threat landscape and ever-growing sophistication of the adversaries. Additionally, the grid’s attack surface continues to grow with the increased dependence on digital communications and control that now extends to each consumer through smart meters and distributed energy resources. Unfortunately, this expansive surface increases the grid’s vulnerability and further exposes critical control systems in both substations and control centers. To respond to this emerging need, we had successfully assembled an interdisciplinary team with academic- industry partnership to successfully conduct research, development, evaluation, demonstration, and commercialization of attack surface reduction tools, whose goal was to significantly reduce the cyber attack surface in the North American power grid. Our proposed project was a synergistic collaborative effort leveraging the synergistic expertise of the team members across power systems, cyber security and CPS security, testbeds, field deployments and demonstration, and successful commercialization. The following are the specific tasks that have been successfully completed two phases (2016-2020). Phase I: Task 1: Developed and implemented a robust Project Management and Data Management Plan, coupled with a well thought out Risk Mitigation Plan. Task 2.1: Developed a comprehensive framework that continually assesses and autonomously reduces the attack surface for the power grid control environment spanning across substations, control center and the SCADA network to significantly reduce the risks of cyber attacks. Task 2.2: Developed attack surface analysis techniques, metrics, and tools that assess the attack surface at multiple levels including the control center, substations, and the SCADA network. Task 2.3: Developed attack surface reduction techniques and tools that dynamically reduce attack surface and hence increase attacker’s cost without interfering in the critical functions of the system. Task 2.4: Prototyped, implemented, and quantitatively evaluated/validated the techniques and tools on a realistic industrial CPS security testbed environment by leveraging the unique resources of the team. Task 3: Developed Commercialization plan to transition the developed tools into power system industry stakeholders for a broader adoption by leveraging the expertise of our industrial members. Phase II: Task 4: Successfully completed field demonstration, verification, and evaluation of the effectiveness of the attack surface analysis and reduction techniques on a realistic utility testbed environment. This also involved the development of realistic scenarios, sound metrics, data sets, evaluation criteria, and documentation. Technology integration & Field demonstration: The project had significantly advanced the state-of-the-art research and practice in improving the cybersecurity of our nation’s power grid infrastructure against cyber threats. In particular, the proposed, designed, and deployed attack surface analysis and reduction algorithms and tools have contributed to significantly reducing the exposure and risk of the devices, substations, and the integrated SCADA/EMS/ DMS grid environment to cyber threat. Strong demonstration and evaluation techniques have verified the feasibility of the developed techniques on realistic cyber-physical testbeds and utility partner's real grid environment, and collaborative research and evaluation of attack surface reduction techniques (for wide-are monitoring and control) within a vendor (GE) EMS platform. The Attack Host Analyzer (AHA) tool that was developed through this project was made available through GitHub.

24 POWER TRANSMISSION AND DISTRIBUTION↗

FY 2021 Isolated Grids and Grid-Connected Turbine Reference Systems; Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL)

For individuals, businesses, and communities focused on building resilient electrical grid infrastructure, wind energy can provide an affordable, accessible, and compatible distributed energy resource option that also enhances the capabilities of local grid operations. The Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project is a multi-year distributed wind research effort, driven through a partnership between four Department of Energy National Laboratories and industry to develop and improve the planning, design, and operation of wind-centered microgrids to complement solar, energy storage, and other distributed energy resources for grid-tied and isolated operation (U.S. Department of Energy, 2021). This report documents the application of methods developed through the initial three years of the MIRACL project to two real-world distributed wind reference systems. Specifically, the methods demonstrated in this report include 1) a market valuation framework to comprehensively value the services distributed wind can provide and 2) a resilience framework that enables stakeholders to characterize distribution system resilience and compare grid investment decisions from a resilience perspective. Additional methods mentioned in this report include distributed hybrid system design methods for grid resilience, advanced control co-simulation platforms, and power hardware-in-the-loop (PHIL) models. Preliminary results from these additional methods are presented in this report and will be demonstrated and/or applied to the reference systems in the coming year. The purpose of applying these methods to reference systems is to drive technology transfer of the theories, methodologies, and technologies developed under the MIRACL project and increase the number of referenceable case studies available to stakeholders interested in additional value-added capabilities of wind systems beyond bulk energy supply (i.e. kilowatt-hours).

17 WIND ENERGY↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Real-Time Testbed for Studying Cyberattacks and Defense in DER-integrated Smart Inverter Systems

In this paper, we propose a Hardware-in-the-Loop (HIL) simulation testbed suitable for the implementation and testing of realistic cyberattacks on grid-tied smart inverter systems integrated with Distributed Energy Resources (DER) that use the Distributed Network Protocol-3 (DNP3) protocol for communications between grid components. Specifically, our testbed combines a Real-Time Digital Simulator (RTDS) NovaCor device, outfitted with GNETx2 network interface cards, a gridtied DER topology implemented via the RTDS software package RSCAD, and a custom virtual network that emulates a man in the middle attacker. The Man-in-the-Middle (MITM) attacker captures DNP3 traffic and falsifies telemetry data in DNP3 packets to trigger unwarranted commands from a DNP3 controller that exploit smart inverter grid support functions. We choose DNP3 and implement grid support functions according to the IEEE Std. 1547-2018 mandated for the interconnection and interoperability of DER power systems with associated power components. Furthermore, we develop a protocol payload agnostic attack detection framework that leverages the round-trip time (RTT) anomalies between DNP3 requests and responses and can detect the presence of attacks without having to analyze the payload’s contents, while balancing trade-offs between false alarm counts, missed detections, and time to detection. To facilitate further research, we publicly release benign and attack network traffic exchanged between various sensors, controllers, and actuators in our grid-tied inverter testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Virtual Power Plant Architecture and Resilient Design

Virtual Power Plants (VPPs) represent a fundamental shift in electric grid operations, aggregating distributed energy resources (DERs) such as solar panels and battery storage to deliver utility-scale grid services traditionally provided by centralized power plants. This report examines the unique architectural, operational, and digital assurance considerations that distinguish VPPs from conventional utility infrastructure as they scale from pilot projects to mainstream deployment across the United States. While VPPs offer significant opportunities for grid modernization and enhanced flexibility, their distributed, multi-stakeholder architecture introduces distinct security challenges that differ fundamentally from traditional generation facilities. The analysis identifies risks in VPP operations, including device-level security gaps, platform vulnerabilities, and communication protocol weaknesses that create expanded attack surfaces compared to centralized power plants. Through examination of real-world incidents and emerging threat patterns, the report demonstrates how some VPPs' reliance on consumer-owned devices, public internet infrastructure, and complex vendor ecosystems require new approaches to digital assurance and operational security. The findings provide practical guidance for utilities, regulators, and aggregators to implement robust security frameworks and operational best practices essential for maintaining grid reliability as VPP deployment accelerates under the Federal Energy Regulatory Commission (FERC) Order 2222 and related regulatory initiatives.

24 - POWER TRANSMISSION AND DISTRIBUTION↗