Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “power system security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

Multi-Objective PMU Allocation for Resilient Power System Monitoring

Phasor measurement units (PMUs) enable better system monitoring and security enhancement in smart grids. In order to enhance power system resilience against outages and blackouts caused by extreme weather events or man-made attacks, it remains a major challenge to determine the optimal number and location of PMUs. In this paper, a multi-objective resilient PMU placement (MORPP) problem is formulated, and solved by a modified Teaching-Learning-Based optimization (MO-TLBO) algorithm. Three objectives are considered in the MORPP problem, minimizing the number of PMUs, maximizing the system observability, and minimizing the voltage stability index. The effectiveness of the proposed method is validated through testing on IEEE 14-bus, 30-bus, and 118-bus test systems. The advantage of the MO-TLBO-based MORPP is demonstrated through the comparison with other methods in the literature, in terms of iteration number, optimality and time of convergence.

Multi-Objective Optimization↗

Security assessment and impact analysis of cyberattacks in integrated T&D power systems

In this paper, we examine the impact of cyberattacks in an integrated transmission and distribution (T&D) power grid model with distributed energy resource (DER) integration. We adopt the OCTAVE Allegro methodology to identify critical system assets, enumerate potential threats, analyze and prioritize risks for threat scenarios. Based on the analysis, attack strategies and exploitation scenarios are identified which could lead to system compromise. Specifically, we investigate the impact of data integrity attacks in inverted-based solar PV controllers, control signal blocking attacks in protective switches and breakers, and coordinated monitoring and switching time-delay attacks. Index Terms—Cyberattacks, security assessment, impact analysis, case studies, integrated power systems.

14 SOLAR ENERGY↗

Inferring adversarial behaviour in cyber‐physical power systems using a Bayesian attack graph approach

Abstract Highly connected smart power systems are subject to increasing vulnerabilities and adversarial threats. Defenders need to proactively identify and defend new high‐risk access paths of cyber intruders that target grid resilience. However, cyber‐physical risk analysis and defense in power systems often requires making assumptions on adversary behaviour, and these assumptions can be wrong. Thus, this work examines the problem of inferring adversary behaviour in power systems to improve risk‐based defense and detection. To achieve this, a Bayesian approach for inference of the Cyber‐Adversarial Power System (Bayes‐CAPS) is proposed that uses Bayesian networks (BNs) to define and solve the inference problem of adversarial movement in the grid infrastructure towards targets of physical impact. Specifically, BNs are used to compute conditional probabilities to queries, such as the probability of observing an event given a set of alerts. Bayes‐CAPS builds initial Bayesian attack graphs for realistic power system cyber‐physical models. These models are adaptable using collected data from the system under study. Then, Bayes‐CAPS computes the posterior probabilities of the occurrence of a security breach event in power systems. Experiments are conducted that evaluate algorithms based on time complexity, accuracy and impact of evidence for different scales and densities of network. The performance is evaluated and compared for five realistic cyber‐physical power system models of increasing size and complexities ranging from 8 to 300 substations based on computation and accuracy impacts.

Sahu, Abhijeet↗

Universal Utility Data Exchange (UUDEX) - Workflow Design - Rev 1

This workflow design document describes the process of establishing a Universal Utility Data Exchange (UUDEX) Connection between two or more UUDEX Endpoints. The existing processes required to establish a data link using Inter Control Center Communications Protocol (ICCP) are very time consuming, from both the perspectives of effort and calendar time. The intent of UUDEX is to provide a more streamlined alternative. The UUDEX Workflow is also used to establish UUDEX Connections to exchange data other than that found in traditional ICCP data exchanges such as exchanges of power system model files, security events and mitigations, disturbance reports, and market data.

97 MATHEMATICS AND COMPUTING↗

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Advanced Measurements for Resilient Integration of Inverter-Based Resources: PROGRESS MATRIX Year-1 Report

As nearly every aspect of the electric power grid undergoes rapid change, measurement technologies that support grid operation and planning must evolve as well. Recent large-scale deployments of inverter-based resources (IBRs) have brought to the forefront the critical need for new measurement technologies. Though these IBRs are vital to achieving the nation’s clean energy goals, their rapid deployment has in some cases led to negative impacts on the reliability and security of the bulk power system (BPS). Advanced power system measurements, including synchronized phasor and waveform measurements, are key to making IBR integration secure and reliable. To this end, the Department of Energy (DOE) initiated a project in 2022 to develop advanced measurement capabilities and analytics that will accelerate adoption of IBRs while improving the reliability and resilience of the BPS. This report discusses a portion of the findings from the project’s first year, which focused on surveying existing measurement capabilities of partner utilities and comparing these capabilities with the requirements of applications that support IBR integration. This report also discusses how these findings will guide the development and demonstration of a set of applications in the project’s second year.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Historic Context, Character-Defining Elements, And Photographic Record For A 26.45-Mile Segment Of The 138-Kilovolt Power Transmission System, Areas 3, 5, 6, And 23, Nevada National Security Site, Nye County, Nevada

The subject of this report is the 138-kilovolt (kV) power transmission line on the Nevada National Security Site (NNSS) (see Figure 1). The NNSS, formerly the Nevada Test Site (NTS), was the main continental nuclear test site for the United States between 1951 and 1992. Known as the battleground of the Cold War, the NNSS hosted a total of 928 nuclear tests during that period. It also served as the location of numerous scientific advancements in the fields of rocketry, big-hole drilling, nuclear waste management, and defense. From its construction in the 1960s through the present day, the 138 kV line has provided electrical power to the numerous buildings, facilities, experiments, and tests on the NNSS. The Department of Energy (DOE), in consultation with the Nevada State Historic Preservation Officer (SHPO), has determined that it may contribute to the character and significance of the Mercury Historic District (MHD) on the NNSS, as well as other historic districts that have not been recorded or evaluated yet. The purpose of this report is to fulfill two of the stipulations in the Memorandum of Agreement DEGM58-22NA25553 between the U.S. Department of Energy and the Nevada State Historic Preservation Officer Regarding Installation of a 138-kilovolt Transmission Line from the Mercury Switching Station to the U1a Facility and the Removal of the Historic 138-kilovolt Transmission Line from the Mercury Switching Station to the U1a Facility in Areas 1, 3, 5, 6, and 23 of the Nevada National Security Site (MOA). The MOA was executed as part of the DOE’s obligations under Section 106 of the National Historic Preservation Act (NHPA) to mitigate the adverse effects of two undertakings on historic properties. In particular, this report fulfills MOA Stipulations III.C.1-3, which state that the Department of Energy (DOE) will prepare the following: A historic context for the 138 kV transmission line and identification of the line’s characterdefining elements; High-quality digital images of the 26.45-mile segment of the 138 kV transmission line that is subject to the two undertakings for which the MOA was executed; and Photograph catalogs and map keys showing photograph viewpoints and directions.

54 ENVIRONMENTAL SCIENCES↗

Implementation Aspects of Smart Grids Cyber-Security Cross-Layered Framework for Critical Infrastructure Operation

Communication networks in power systems are a major part of the smart grid paradigm. It enables and facilitates the automation of power grid operation as well as self-healing in contingencies. Such dependencies on communication networks, though, create a roam for cyber-threats. An adversary can launch an attack on the communication network, which in turn reflects on power grid operation. Attacks could be in the form of false data injection into system measurements, flooding the communication channels with unnecessary data, or intercepting messages. Using machine learning-based processing on data gathered from communication networks and the power grid is a promising solution for detecting cyber threats. In this paper, a co-simulation of cyber-security for cross-layer strategy is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection as well as identification of anomalies in the operation of the power grid. The framework is implemented on the IEEE 118-bus system. The system is constructed in Mininet to simulate a communication network and obtain data for analysis. A distributed three controller software-defined networking (SDN) framework is proposed that utilizes the Open Network Operating System (ONOS) cluster. According to the findings of our suggested architecture, it outperforms a single SDN controller framework by a factor of more than ten times the throughput. This provides for a higher flow of data throughout the network while decreasing congestion caused by a single controller’s processing restrictions. Furthermore, our CECD-AS approach outperforms state-of-the-art physics and machine learning-based techniques in terms of attack classification. The performance of the framework is investigated under various types of communication attacks.

cross-layered↗

CPES-QSM: A Quantitative Method Towards the Secure Operation of Cyber-Physical Energy Systems

Power systems are evolving into cyber-physical energy systems (CPES) mainly due to the integration of modern communication and Internet-of-Things (IoT) devices. CPES security evaluation is challenging since the physical and cyber layers are often not considered holistically. Existing literature focuses on only optimizing the operation of either the physical or cyber layer while ignoring the interactions between them. This paper proposes a metric, the Cyber-Physical Energy System Quantitative Security Metric (CPES-QSM), that quantifies the interaction between the cyber and physical layers across three domains: electrical, cyber-risk, and network topology. A method for incorporating the proposed cyber-metric into operational decisions is also proposed by formulating a cyber-constrained AC optimal power flow (C-ACOPF) that considers the status of all the CPES layers. The C-ACOPF considers the vulnerabilities of physical and cyber networks by incorporating factors such as voltage stability, contingencies, graph-theory, and IoT cyber risks, while using a multi-criteria decision-making technique. We note that simulation studies are conducted using standard IEEE test systems to evaluate the effectiveness of the proposed metric and the C-ACOPF formulation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

An Analysis of the Effects of Renewable Energy Intermittency on the 2030 Korean Electricity Market

Republic of Korea has unique geographical characteristics similar to those of an island, resulting in an isolated power system. For this reason, securing sufficient operating reserves for the system’s stability and reliability in the face of the intermittency of increasing variable renewable energy (VRE) is paramount, and this will pave the way to achieving the nation’s decarbonization target and carbon neutrality. However, the current reserve-operation method in Republic of Korea does not take into account energy-system conditions, such as the intermittency of the VRE. Therefore, this paper presents an analysis of the impact of changes in reserve-operation methods on the electricity market in the future Republic of Korean power system, with the increased levels of VRE that are currently envisioned. Specifically, three reserve-operation methods, including Korea’s current reserve-power-operation standards, were applied to the two power-system plans announced by the Korean government to analyze the annual generator operation and costs. The analysis results show that securing reserves proportional to the VRE would exert negative effects, such as increased power-generation costs and the curtailment of nuclear and VRE generation. These results can contribute to the estimation of operational reserves needed for high levels of VRE and to the design of new the Korean reserve market, to be introduced in 2025.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilience in an Age of Increasing Electrification

The purpose of this paper is to outline considerations of global electrification trends that include the resultant system-wide and nation-wide impacts. How we incorporate resilience into the electrification plans that transition a nation from conventional energy sources to secure clean energy sources can impact the success of those transitions. Electrification of energy systems has the potential to impact power system planning, emissions, and security; however, little research has been done on comprehensive solutions for incorporating resilience into the electrification process. Research has been conducted on aspects of the energy system and electrification, but not holistically across disciplines and related to the interdependencies of different components of the grid system. This gap in research provides an opportunity for more analysis and a collection of best practices to incorporate resilience into electrification plans. Although clean energy is the goal of an increasing number of nations worldwide, there are many considerations in designing clean energy transitions and increased electrification. Resilience must be factored into clean energy transitions from planning, market design, and policies to modernized grid structures and new, location-specific dispersed energy and energy storage technologies.

clean energy↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Developing an AI-Powered Zero-Trust Cybersecurity Framework for Malware Prevention in Nuclear Power Plants

This study presents the development of an AI-powered Zero-Trust cybersecurity framework for malware prevention in nuclear power plants. The framework aims to enhance the security of critical systems within nuclear power plants by adopting the principles of Zero-Trust and leveraging artificial intelligence (AI) technologies. By assuming no implicit trust in any user or device and continuously authenticating and authorizing access, the framework ensures a robust defense against malware attacks. The integration of AI allows for the detection and prevention of malware through behavioral analytics, endpoint protection, network segmentation, and continuous monitoring. The paper discusses the key considerations, steps, and technologies involved in developing this framework, emphasizing the importance of regular updates, training, compliance, and auditing. The proposed framework serves as a comprehensive approach to safeguarding nuclear power plants from sophisticated malware threats and protecting the integrity and safety of critical infrastructure.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

GLIMPSE of Future Power Grid Models

Power grid is one of the critical national infrastructures with social, economics, and national security impacts. Particularly, power distribution systems represent part of the infrastructure between power distribution substations and customers such as residential, commercial, and industrial. To address various grid modernization challenges, state-of-the-art algorithms and methodologies have been developed to deploy, operate, and expand a secure and resilient power grid. At the same time, there is a need to develop capabilities to assist power grid stakeholders to quickly get insight into the design and structure of the grid. Data visualization is a key approach to comprehend and understand complex systems such as the power grid. We present GLIMPSE Grid Layout Interface for Model Preview and System Exploration), a graph-based semantic-aware application to visualize and update distribution power grid models. The GLIMPSE can be used with standard IEEE models to search and highlight power grid objects such as generators, loads, overhead lines, etc. Additionally, it supports updating attributes and model export to integrate with GridLAB-D simulations.

Cybersecurity, power grid, visualization↗

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗