Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber-attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Resilience Through Data-Driven, Intelligent Designed Control: A Formal Methods Approach

The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.

97 MATHEMATICS AND COMPUTING↗

Time Synchronization Techniques in the Modern Smart Grid: A Comprehensive Survey

In modern smart grids, accurate and synchronized time signals are essential for effective monitoring, protection, and control. Various time synchronization methods exist, each tailored to specific application needs. Widely adopted solutions, such as GPS, however, are vulnerable to challenges such as signal loss and cyber-attacks, underscoring the need for reliable backup or supplementary solutions. This paper examines the timing requirements across different power grid applications and provides a comprehensive review of available time synchronization mechanisms. Through a comparative analysis of timing methods based on accuracy, flexibility, reliability, and security, this study offers insights to guide the selection of optimal solutions for seamless grid integration.

comparison↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

A dataset of cyber-induced mechanical faults on buildings with network and buildings data

We have collected data of cyber-induced mechanical faults on buildings using a simulation platform. A DOE reference building model was used for running the simulation under a Rogue device attack and collected the network data as well as the physical buildings data to better understand the impacts of cyber attacks on the building and help identify the source of the mechanical fault with the network data. Alfalfa is the tool used for simulating the DOE reference buildings and acts as an interface to the model for querying the status and providing input externally. The Building Automation System (BAS) is the centralized controller providing control commands to other BACnet devices on the network based on the building status received from Alfalfa. The BACnet devices like damper will listen for the control commands from BAS on the BACnet network and implement it. The attacker is the malicious actor on the network creating disruptions by placing cyber-attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Threat Assessment for the Air Traffic Management System: A Network Controls Approach

Air transportation networks are being disrupted with increasing frequency by failures in their cyber- (computing, communication, control) systems. Whether these cyber- failures arise due to deliberate attacks or incidental errors, they can have far-reaching impact on the performance of the air traffic control and management systems. For instance, a computer failure in the Washington DC Air Route Traffic Control Center (ZDC) on August 15, 2015, caused nearly complete closure of the Centers airspace for several hours. This closure had a propagative impact across the United States National Airspace System, causing changed congestion patterns and requiring placement of a suite of traffic management initiatives to address the capacity reduction and congestion. A snapshot of traffic on that day clearly shows the closure of the ZDC airspace and the resulting congestion at its boundary, which required augmented traffic management at multiple locations. Cyber- events also have important ramifications for private stakeholders, particularly the airlines. During the last few months, computer-system issues have caused several airlines fleets to be grounded for significant periods of time: these include United Airlines (twice), LOT Polish Airlines, and American Airlines. Delays and regional stoppages due to cyber- events are even more common, and may have myriad causes (e.g., failure of the Department of Homeland Security systems needed for security check of passengers, see [3]). The growing frequency of cyber- disruptions in the air transportation system reflects a much broader trend in the modern society: cyber- failures and threats are becoming increasingly pervasive, varied, and impactful. In consequence, an intense effort is underway to develop secure and resilient cyber- systems that can protect against, detect, and remove threats, see e.g. and its many citations. The outcomes of this wide effort on cyber- security are applicable to the air transportation infrastructure, and indeed security solutions are being implemented in the current system. While these security solutions are important, they only provide a piecemeal solution. Particular computers or communication channels are protected from particular attacks, without a holistic view of the air transportation infrastructure. On the other hand, the above-listed incidents highlight that a holistic approach is needed, for several reasons. First, the air transportation infrastructure is a large scale cyber-physical system with multiple stakeholders and diverse legacy assets. It is impractical to protect every cyber- asset from known and unknown disruptions, and instead a strategic view of security is needed. Second, disruptions to the cyber- system can incur complex propagative impacts across the air transportation network, including its physical and human assets. Also, these implications of cyber- events are exacerbated or modulated by other disruptions and operational specifics, e.g. severe weather, operator fatigue or error, etc. These characteristics motivate a holistic and strategic perspective on protecting the air transportation infrastructure from cyber- events. The analysis of cyber- threats to the air traffic system is also inextricably tied to the integration of new autonomy into the airspace. The replacement of human operators with cyber functions leaves the network open to new cyber threats, which must be modeled and managed. Paradoxically, the mitigation of cyber events in the airspace will also likely require additional autonomy, given the fast time scale and myriad pathways of cyber-attacks which must be managed. The assessment of new vulnerabilities upon integration of new autonomy is also a key motivation for a holistic perspective on cyber threats.

Complex Networks↗

Cyber Physical Security (CPS) Extension to Air Traffic Management (ATM) Testbed

The Air Traffic Management (ATM) Testbed is being developed at NASA to enable benefit, impact, safety and cost assessments for accelerating the deployment of Concept and Technologies (C&T) in the National Airspace System (NAS). Today, C&T introduction into the NAS takes decades. The primary reason for this is an inability to assess the operational impact of the interaction between the proposed C&T and operationally deployed systems (Realistic Technologies) in terms of NAS-wide safety, traffic flow efficiency, roles and workload of controllers and traffic managers, and impact on airline fleet operations. Transition of C&T to operations requires mathematical modeling and simulation, Human-in-the-Loop (HITL) testing and shadow-mode evaluation driven by operational data. Whereas interaction with the operational system during testing and stages of deployment is not permissible due to safety concerns, it is certainly possible to create a simulation environment that closely mimics the NAS using the same operational systems/hardware for enabling such assessments. This presentation focuses on a proposed Cyber Physical Security extension to the ATM Testbed for creating a modeling and simulation architecture to study how well the Air Traffic Management system will perform and analyze effectiveness of mitigating security measures against particular cyber-attack scenarios.

Datta, Koushik↗

A Survey of Cyber Threat

Multiple companies are competing to develop human-crewed and unmanned aerial vehicles to provide flight in urban environments. With the growth of aerial systems and future airborne vehicle networks and the need to enable secure data exchange and service interactions within Urban Air Mobility (UAM) environments, cybersecurity has come to the forefront as a topic, highlighting the need to protect these networks from cyber-attacks. This paper will identify potential threats, vulnerabilities, and weaknesses of UAM environments, that could lead to system compromises and disruptions.

Cyber Security↗

NASA’s Secured Airspace for Urban Air Mobility (UAM)

The Urban Air Mobility (UAM) architecture is leveraged from the Unmanned Traffic Management (UTM) concept of operations. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within that environment. As a recognized need, various views of UAM flight information are provided to the public and public safety entities. To accomplish this, among other goals, the Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). This concept of UAM proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical take-off and landing (VTOL) or short take-off and landing (STOL) aircraft to overcome increasing surface congestion. To garner the support of UAM and to realize its potential, an assurance of cybersecurity is critical for public acceptance. Understanding the various components communicating with one-another cybersecurity, like in other industries, has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. With the planned growth and reach of UAM systems, it’s clear that the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. Consequently, as these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well. While learning is always the goal, the overall intent of this workshop is to make recommendations on the following: (1) how future UAM environments can be protected against cyber-attacks, and (2) what mechanisms should be put in place to detect attacks against UAM environments.

UAM↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

OT Operational Anomaly Detection (OAD) T&D + DER

The growth of utility-scale renewable energy resources, distributed energy resources (DER), and transportation electrification has increased uncertainty and cybersecurity risks in power grids. The Purdue Enterprise Reference Architecture model which is widely adopted by the utility industry is now insufficient to protect the power grid against cyber-attacks. There is a need to identify what cybersecurity model is effective on Energy Management System (EMS), Advanced Distribution Management System (ADMS), and DER Management System (DERMS) to address the fundamental cybersecurity challenges in the age of increasing renewable energy and DER share as well as consumer participation in the electric energy industry. The next generation of cybersecurity model for OT network should be able to detect inside attackers, mitigate the cybersecurity risks arising from the new grid participants including DER aggregators, electric vehicle owners, and behind-the-meter consumers outside the utility company, and develop the strategy to trust consumer measurement data. This panel will discuss the challenges and pathways for the development of an ensemble cybersecurity model based on predictive state estimation to detect cybersecurity anomalies in OT network including EMS, ADMS, and DERMS.

cybersecurity↗

Development of A Hardware-In-the-Loop (HIL) Testbed for Cyber-Physical Security in Smart Buildings

As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the building's intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIT) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.

Li, Guowen↗

Maximum-impact Adversary Design for Network-based Control System: A Case Study on Grid-interactive Efficient Buildings

The Internet of Things (IoT) technology has dramatically improved the efficiency of today's building operation and management. By connecting controllable devices into a communication network, control signals can be easily passed to the devices, and operating status can be acquired from measurable ends with minimal effort. However, this all-connected configuration could also expose the network-based control system (NBCS) to malicious actions, such as cyberattacks. One of the common NBCSs is the building automation system. With the promotion of grid-interactive efficient buildings (GEBs), there has been increasing attention on securing the buildings from the network perspective. This research proposes a maximum-impact adversary design framework so that the adversary can provide the most adversarial impact on the controlled system while remaining stealthy. The proposed framework is numerically demonstrated on a network-based building energy and control system. The building energy system is built in a Modelica-based simulation environment and controlled by the state-of-the-art ASHRAE Guideline 36 control sequences. The control commands at the supervisory level, generated from the Guideline 36 controller, are assumed to be sent to local devices through communication networks using the BACnet protocol. Simulation results show that the proposed maximum-impact adversary on such a system can stealthily affect the building system's performance to its maximum extent. It is anticipated that results can be used by researchers and practitioners in the building automation industry to design efficient and robust cyber-attack detection algorithms, especially for stealthy attacks.

Chu, Mengyuan↗

Robust and cybersecure coordinated unintentional island detection for microgrids

Unintentional islanding (UI) of a circuit of distributed energy resources (DERs) may leave area electrical power systems (EPS), external to the DER circuit, energized. Thus, UI detection methods have been developed to detect unintentional islanding and trigger a UI response. However, individual UI detection methods have various deficiencies. Thus, a consensus-based UI detection process is disclosed that builds a consensus from multiple UI detection sources, optionally implementing different UI detection methods. The redundancy in this consensus-based UI detection process provides robust, sensitive, selective, and cybersecure UI detection for the entire DER circuit. For example, the consensus-based UI detection process may eliminate or reduce non-detection zones, avoid false positives, thwart cyber-attacks, and/or the like.

Brissette, Alex↗

Does practice make perfect? Lessons learned from full-scale power system incident response exercise

While threats to the energy sector occur daily, few utilities get the opportunity to fully test out their detection and response mechanisms to advanced threats in the real world. With the high demand for reliability, few grid operators would allow execution of simulated cyber-attacks on their live systems. The DOE-funded Liberty Eclipse project offers a unique opportunity for small and large utilities and coops to practice their combined IT/OT responses to a live red team executing attacks against an isolated power system on an island in New York. Both cyber teams and power operations teams must work together to detect and respond to attacks, even restoring the power system against extreme impacts. Lessons learned from these exercises reveal key takeaways for understanding what a real attack against the electric sector will look like, gaps in execution of the best-laid plans when the pressure of a real event is bearing down, and how organizations can better prepare for advanced attacks by optimizing participation in exercises. This presentation will discuss successes and opportunities for improvement both in how utilities can prepare for and respond to events, as well as how full-scale IT/OT exercises can be coordinated.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Software defined networking moving target defense honeypot

Disclosed herein are systems, methods, and storage media for thwarting cyber-attacks and data theft. A computing system receives packets and compares with a configuration resource. The computing system determines that the packet does not match the configuration resource and transmits a packet to a decoy environment via an SDN switch. The decoy environment is configured to generate time-out, service unavailable, or restricted access messages. In some embodiments, the computing system determines the packet does match the configuration and transmits the packet to a production network via an SDN switch. The SDN switch is communicatively connected to the decoy environment through a first channel and communicatively connected to a production environment through a separate second channel. The computing system is further configured to create and transmit to the SDN switch, rules to manage transmitting the packet to either the decoy environment or the production environment.

Lyle, Joshua A.↗

Internship Presentation: Integrating Safety and Cybersecurity: Security-by-Design with SOWT Analysis for Reactor Testing

This study covers leveraging reactor testing facilities that are primarily designed with a focus on safety to enhance cybersecurity testing. By incorporating reactor security-by-design with reactor safety-by-design principles and adopting defense-in-depth strategies that emphasize both safety and security, the research evaluates applicable cyber tools, models, and solutions. This includes simulating specific cyber-attack scenarios using reactor simulators and performing SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis to improve the cybersecurity of reactor systems.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Losing Control of Your Linear Network? Try Resilience Theory

Resilience of cyber-physical networks to unexpected failures is a critical need widely recognized across domains. For instance, power grids, telecommunication networks, transportation infrastructures, and water treatment systems have all been subject to disruptive malfunctions and catastrophic cyberattacks. Following such adverse events, we investigate scenarios where a node of a linear network suffers a loss of control authority over some of its actuators. These actuators are not following the controller's commands and are instead producing undesirable outputs. The repercussions of such a loss of control can propagate and destabilize the whole network despite the malfunction occurring at a single node. To assess system vulnerability, we establish resilience conditions for networks with a subsystem enduring a loss of control authority over some of its actuators. Furthermore, we quantify the destabilizing impact on the overall network when such a malfunction perturbs a nonresilient subsystem. We illustrate our resilience conditions on two academic examples, on an islanded microgrid and on the linearized IEEE 39-bus system.

97 MATHEMATICS AND COMPUTING↗