Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “adversarial attack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Automated Membership Inference Attacks: Discovering MIA Signal Computations using LLM Agents

Membership inference attacks (MIAs), which enable adversaries to determine whether specific data points were part of a model's training dataset, have emerged as an important framework to understand, assess, and quantify the potential information leakage associated with machine learning systems. Designing effective MIAs is a challenging task that usually requires extensive manual exploration of model behaviors to identify potential vulnerabilities. In this paper, we introduce AutoMIA -- a novel framework that leverages large language model (LLM) agents to automate the design and implementation of new MIA signal computations. By utilizing LLM agents, we can systematically explore a vast space of potential attack strategies, enabling the discovery of novel strategies. Our experiments demonstrate AutoMIA can successfully discover new MIAs that are specifically tailored to user-configured target model and dataset, resulting in improvements of up to 0.18 in absolute AUC over existing MIAs. This work provides the first demonstration that LLM agents can serve as an effective and scalable paradigm for designing and implementing MIAs with SOTA performance, opening up new avenues for future exploration.

Tran, Toan Viet [Emory University]↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

Cross-Layered Cyber-Physical Power System State Estimation towards a Secure Grid Operation

In the Smart Grid paradigm, this critical infrastructure operation is increasingly exposed to cyber-threats due to the increased dependency on communication networks. An adversary can launch an attack on a power grid operation through False Data Injection into system measurements and/or through attacks on the communication network, such as flooding the communication channels with unnecessary data or intercepting messages. A cross-layered strategy that combines power grid data, communication grid monitoring and Machine Learning based processing is a promising solution for detecting cyberthreats. In this paper, an implementation of an integrated solution of a cross-layer framework is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection of anomalies in the operation of power grid. IEEE 118-bus system is built in Simulink to provide a power grid testing environment and communication network data is emulated using SimComponents. The performance of the framework is investigated under various FDI and communication attacks.

cyber security, network security, cyber-physical s↗

Implementation Aspects of Smart Grids Cyber-Security Cross-Layered Framework for Critical Infrastructure Operation

Communication networks in power systems are a major part of the smart grid paradigm. It enables and facilitates the automation of power grid operation as well as self-healing in contingencies. Such dependencies on communication networks, though, create a roam for cyber-threats. An adversary can launch an attack on the communication network, which in turn reflects on power grid operation. Attacks could be in the form of false data injection into system measurements, flooding the communication channels with unnecessary data, or intercepting messages. Using machine learning-based processing on data gathered from communication networks and the power grid is a promising solution for detecting cyber threats. In this paper, a co-simulation of cyber-security for cross-layer strategy is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection as well as identification of anomalies in the operation of the power grid. The framework is implemented on the IEEE 118-bus system. The system is constructed in Mininet to simulate a communication network and obtain data for analysis. A distributed three controller software-defined networking (SDN) framework is proposed that utilizes the Open Network Operating System (ONOS) cluster. According to the findings of our suggested architecture, it outperforms a single SDN controller framework by a factor of more than ten times the throughput. This provides for a higher flow of data throughout the network while decreasing congestion caused by a single controller’s processing restrictions. Furthermore, our CECD-AS approach outperforms state-of-the-art physics and machine learning-based techniques in terms of attack classification. The performance of the framework is investigated under various types of communication attacks.

cross-layered↗

Resilient Observer Design for Cyber-Physical Systems with Data-Driven Measurement Pruning

Resilient observer design for Cyber-Physical Systems (CPS) in the presence of adversarial false data injection attacks (FDIA) is an active area of research. The existing state-of-the-art algorithms tend to break down as more and more knowledge of the system is built into the attack model; also as the percentage of attacked nodes increases. From the view of optimization theory, the problem is often cast as a classical error correction problem for which a theoretical limit of has been established as the maximum percentage attacked nodes for which state recovery is guaranteed. Beyond this limit, the performance of -minimization based schemes, for instance, deteriorates rapidly. Similar performance degradation occurs for other types of resilient observers beyond certain percentages of attacked nodes. In order to increase the corresponding percentage of attacked nodes for which state recoveries can be guaranteed, researchers have begun to incorporate prior information into the underlying resilient observer design framework. For the most pragmatic cases, this prior information is often obtained through a data-driven machine learning process. Existing results have shown a strong positive correlation between the maximum attacked percentages that can be tolerated and the accuracy of the data-driven model. Motivated by these results, this chapter examines the case for pruning algorithms designed to improve the Positive Prediction Value (PPV) of the resulting prior information, given stochastic uncertainty characteristics of the underlying machine learning model. Theoretical quantification of the achievable improvement is given. Simulation results show that the pruning algorithm significantly increases the maximum correctable percentage of attacked nodes, even for machine learning model whose prediction power is comparable to the random flip of a coin.

Resilient Observer, Cyber-physical Systems, Data-D↗

Employing a Hardware-in-the-Loop Approach to Realize a Fully Homomorphic Controller for a Small Modular Advanced High Temperature Reactor

This paper addresses the cybersecurity challenges of advanced nuclear reactors by integrating fully homomorphic encryption (FHE) into their control systems, enabling encrypted processing of control signals without compromising functionality. Advanced nuclear reactors, including Small Modular Reactors (SMRs) and microreactors, aim to achieve autonomous and remote operations, reducing costs and enhancing competitiveness. However, these advancements expand the attack surface for cyberattacks, particularly in autonomous and remote operation scenarios. Cyberattacks can exploit vulnerabilities to manipulate physical processes, causing shutdowns, asset damage, or public harm. Such attacks begin with passive reconnaissance, where adversaries intercept communications or observe behaviors to gather information, which is then leveraged to execute cyber-physical attacks by injecting malicious commands. Nuclear power must adopt cybersecurity protection measures to secure the integrity and availability of their digital control systems. This paper demonstrates the application of FHE to secure operations by enabling encrypted processing of sensitive signals and parameters -- ensuring privacy without exposing data. FHE supports secure mathematical operations on encrypted data without requiring decryption. Using a hardware-in-the-loop (HIL) approach, this paper implements an FHE-integrated controller on a BeagleBone Black (BBB) controlling a simulation of the Small Modular Advanced High Temperature Reactor (SmAHTR). By doing so, the encrypted controller protects the integrity of critical set points and control signals during transmission and processing. Thus, FHE-integrated controllers enhance secure operations of advanced nuclear reactors while maintaining functionality.

control systems↗

Cooperative Systems in Presence of Cyber-Attacks: A Unified Framework for Resilient Control and Attack Identification

Here, this paper considers a cooperative control problem in presence of unknown attacks. The attacker aims at destabilizing the consensus dynamics by intercepting the system’s communication network and corrupting its local state feedback. We first revisit the virtual network based resilient control proposed in our previous work and provide a new interpretation and insights into its implementation. Based on these insights, a novel distributed algorithm is presented to detect and identify the compromised communication links. It is shown that it is not possible for the adversary to launch a harmful and stealthy attack by only manipulating the physical states being exchanged via the network. In addition, a new virtual network is proposed which makes it more difficult for the adversary to launch a stealthy attack even though it is also able to manipulate information being exchanged via the virtual network. A numerical example demonstrates that the proposed control framework achieves simultaneously resilient operation and real-time attack identification.

97 MATHEMATICS AND COMPUTING↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

BioSecure Digital Twin: Manufacturing Innovation and Cybersecurity Resilience

U.S. national security, prosperity, economy, and well-being require secure, flexible, and resilient Biopharmaceutical Manufacturing. The COVID-19 pandemic reaffirmed that the biomedical production value-chain is vulnerable to disruption and has been under attack from sophisticated nation-state adversaries. Current cyber defenses are inadequate, and the integrity of critical production systems and processes are inherently vulnerable to cyber-attacks, human error, and supply chain disruptions. The following chapter explores how a BioSecure Digital Twin will improve U.S. manufacturing resilience and preparedness to respond to these hazards by significantly improving monitoring, integrity, security, and agility of our manufacturing infrastructure and systems. The BioSecure Digital Twin combines a scalable manufacturing framework with a robust platform for monitoring and control to increase U.S. biopharma manufacturing resilience. Then, the chapter discusses some of the inherent vulnerabilities and challenges at the nexus of health and advanced manufacturing. Next, the chapter highlights that as the Pandemic evolves, we need agility and resilience to overcome significant obstacles. This section highlights an innovative application of Cyber Informed Engineering to developing and deploying a BioSecure Digital Twin to improve the resilience and security of the biopharma industrial supply chain and production processes. Finally, the chapter concludes with a process framework to complement the Digital Twin platform, called the Biopharma (Observe, Orient, Decide, Act) OODA Loop Framework (BOLF), a four-step approach to decision-making outputs from the Digital Twin. The BOLF will help end users leverage twin technology by distilling the available information, focusing the data on context, and rapidly making the best decision while remaining cognizant of changes that can be made as more data becomes available.

99 GENERAL AND MISCELLANEOUS↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Precursor Analysis Report: Cyber Attack on Thyssenkrupp Blast Furnace 2014

The Cyber Attack on Thyssenkrupp Blast Furnace 2014 Precursor Analysis Report leverages publicly available information about the Thyssenkrupp Steel Mill cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. In December 2014, the German Government’s Federal Office for Information Security (BSI) released a report detailing a cyber attack on a German steel mill that occurred earlier that year, though exact dates and details of the attack were not revealed. While the report did not specify the name of the company, multiple sources identified the victim as one of Europe’s largest steel manufacturers, Thyssenkrupp AG. Further, Thyssenkrupp announced on 16 May of that year that Europe’s largest blast furnace, “Schwelgern 2,” located at its facility in Duisburg, Germany, would be offline for several weeks for repairs and upgrades, suggesting Schwelgern 2 was likely the target of the attack. The attack began in early 2014, when adversaries infiltrated the victim steel mill’s Information Technology (IT) network via a spearphishing campaign, then worked their way into the Operational Technology (OT) environment, where they executed software that caused denial of service, denial of control, and eventually a loss of control. This led to the blast furnace shutting down without proper safety procedures, resulting in catastrophic physical damage. No lives were lost in the incident, but ThyssenKrupp suffered $4 million in damage to the blast furnace and an additional $6 million in lost revenue. The adversaries required specialized knowledge and expertise in steel production, which enabled them to compromise a variety of internal systems and components across both IT and OT networks. The attack also demonstrated detailed knowledge of the industrial control systems (ICS) and production processes being used. This combination resulted in one of the earliest known publicly reported cybersecurity incidents resulting in physical damage to ICS equipment. Researchers and analysts identified 19 unique techniques (used in a sequence of 20 steps) utilized during the attack with a total of 454 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Fifteen of the identified techniques used during the Thyssenkrupp cyber attack were precursors to the triggering event. Analysis identified 369 observables associated with these precursor techniques, 316 of which were assessed to have an increased likelihood of being perceived in the 120 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Precursor Analysis Report: Industroyer2 and Wiper Malware Targeting Ukrainian Energy Provider 2022

The Industroyer2 and Wiper Malware Targeting Ukrainian Energy Provider 2022 Precursor Analysis Report leverages publicly available information about the Industroyer2 cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. An adversary attempted to cause a blackout in Ukraine in April 2022 by using the Industroyer2 malware against a regional Ukrainian energy provider. The adversary targeted eight high-voltage electrical substations and utilized the malware in tandem with disk wipers for Windows, Linux, and Solaris operating systems in an attempt to make response and recovery efforts more difficult. The adversary reused a piece of the original Industroyer malware designed to open circuit breakers and de-energize target substations. The adversary gained initial access to the victim’s enterprise network through unknown means in February 2022 and was able to perform reconnaissance, pivot to the operations network, and reside in the system for at least 51 days. This gave the adversary a detailed understanding of the environment and allowed them to customize the Industroyer2 malware to the victim’s operations network. However, defenders detected and stopped the attack before the adversary could achieve their intended impact. Had the Industroyer2 attack been successful, it could have caused a blackout for more than two million people during the early stages of Russia’s invasion of Ukraine. Researchers and analysts identified 22 unique techniques (used in a sequence of 31 steps) utilized during the attack with a total of 297 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-three of the identified techniques used during the Industroyer2 cyber attack were precursors to the triggering event. Analysis identified 224 observables associated with these precursor techniques, 122 of which were assessed to have an increased likelihood of being perceived in the 51 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Architecture Design for Remote Operation of Microreactors: Poster

The nuclear sector is pursuing a number of advanced reactor concepts, one of which is the microreactor, an advanced reactor characterized by a power output of less than 20 MWth. These reactors are intended for use in applications where traditional power solutions are economically or logistically impractical. One key feature required for the successful deployment of microreactors is a remote operation capability, which can dramatically cut staffing expenses by eliminating the need for licensed operators to be present at the site of each reactor and instead concentrate in a centrally located operations center. In moving to a remote operations framework for nuclear reactors, the number of potential attack surfaces for a cyber adversary looking to cause harm or disruption increases. Therefore, a robust cybersecurity architecture is required to mitigate these potential vulnerabilities. This paper explores the functional infrastructure, security, and communication requirements to adapt remote operations to nuclear applications. It then presents a reference architecture for remote operations of microreactors that applies best practices in cybersecurity and remote communications in the context of a digital twin remote operation system.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Roadmap for Solar Photovoltaic (PV) Cybersecurity: A vision for improving cyber maturity of distributed and utility-scale solar energy installations

As the solar energy sector continues to expand, its integration into the broader energy infrastructure presents both unprecedented opportunities and new risks. The increasing reliance on digital technologies and interconnected systems in solar energy creates an expanded attack surface for motivated cyber adversaries. Cyberattacks have the potential to cause disruptions in energy production, damage to equipment, financial losses, and compromises in national security. Therefore, ensuring robust cybersecurity measures is paramount to protect the integrity, availability, confidentiality, and access control of solar energy systems. However, there are still key gaps and challenges to be addressed in industry and research, which stakeholders must race to address as they combat a growing number of real-world cyber incidents that affect solar energy systems and a growing number of vulnerabilities discovered and disclosed in key types of equipment. This roadmap explore the current state of solar PV cybersecurity and the gaps and challenges still to be addressed.

14 - SOLAR ENERGY↗

A Review of Technologies that can Provide a 'Root of Trust' for Operational Technologies

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims at providing a survey of technologies that have the potential to reduce exposure of sensitive networks and equipment to these attacks, thereby improving tamper resistance. The recent advances in the performance and capabilities of these technologies in recent years has increased their potential applications to reduce or mitigate exposure of the supply chain attack pathway. The focus being on providing an analysis of the benefits and disadvantages of smart cards, secure tokens, and elements to provide root of trust. This analysis provides evidence that these roots of trust can increase the technical capability of equipment and networks to authenticate changes to software and configuration thereby increasing resilience to some supply chain attacks, such as those related to logistics and ICT channels, but not development environment attacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

DER Cybersecurity Detection and Response Suite

SAND2024-08475O The Distributed Energy Resource (DER) Cybersecurity Detection and Response Suite is a solution for distributed energy resource (DER) systems. The DER Security Orchestration, Automation, and Response (SOAR) solution that uses alerts from signature- and behavior-based Intrusion Detection Systems are intended to be deployed as bump-in-the-wire (BITW) devices in front of DER equipment. The fielded application would use multiple intrusion detection systems that report data to SOAR to respond to cyberattacks. The suite consists of two software components: • The proactive intrusion detection and mitigation system (PIDMS) secures grid-edge photovoltaic smart inverters and other equipment in distributed energy resource systems. It is a distributed BITW solution; cyber and physical data are automatically processed using network inspection tools and custom machine learning algorithms to detect abnormal events and correlate cyber-physical events. • The Security Orchestration, Automation, and Response for Distributed Energy Resources (SOAR4DER) application ingests data from several intrusion detection systems to quickly block attacks and revert DER systems to good states. Using a collection of intrusion detection system technologies on a BITW device, it incorporates physical and cyber data to detect abnormal and potential malicious behaviors. Multiple SOAR playbooks then use the intrusion detection system data streams to automatically defend the system. SOAR4DER system testing showed detection and response times under 30 seconds for all adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute-force logins, and machine-in-the-middle attacks. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Johnson, Jay↗