Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber Research”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Data-Driven Probabilistic Anomaly Detection for Electricity Market under Cyber Attacks

Information and communication technologies have been widely used in smart grid for efficient operation. However, these technologies are vulnerable to malicious cyber attacks, which may lead to severe reliability and economic issues. Recently, a variety of data-driven anomaly detection approaches have been explored to detect potential cyber attacks in smart grids. In this paper, we researched on the electricity market data aiming to identify anomalies from the locational marginal prices (LMPs) and provide a new indicator for potential cyber attacks in power grids. Specifically, a novel data-driven probabilistic anomaly detection framework is proposed for electricity market, which consists of three major components: long short-term memory (LSTM) based deterministic electricity price forecasting, probabilistic electricity price forecasting and anomaly detection. This framework is tested on a model-based electricity market simulator under two types of cyber attacks, i.e., load redistribution attack (LRA) and price responsive attack (PRA). Numerical results on the simulated LMPs show that the proposed framework is capable of detecting data anomalies over these attacks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

CP‐SyNet: A tool for generating customised cyber‐power synthetic network for distribution systems with distributed energy resources

Abstract The integration of distributed energy resources and advancement in information technology has enabled the transition of traditional power distribution systems to active cyber‐physical distribution systems. A growing amount of research has been done on the modelling, analysis, and optimisation of power distribution system behaviour. However, existing publicly available distribution test feeders are limited in numbers and have minimal features. Furthermore, these test feeders do not include cyber models and are not customisable. To bridge this gap, we propose and develop Cyber‐physical synthetic distribution system network (CP‐SyNet), a tool for generating customisable cyber‐physical synthetic distribution test feeders. CP‐SyNet generates three‐phase unbalanced test feeders according to users' requirements, while simultaneously considering both the cyber side and the physical side of the network for cyber‐physical analysis. The physical test network is developed using a graph‐theoretical approach that employs information from existing test feeders. The cyber side considers an equivalent communication network by transforming the physical topology into possible and feasible simulated network. Two examples are presented to demonstrate the feasibility of the proposed framework to generate cyber‐physical test feeders.

Wang, Lusha↗

Using the CYBER-Champ Model to Determine Cyber Competencies and Role Alignment

Cybersecurity roles, tasks, and skills are seen by many organizations as nonessential, abstract, or complicated. Although standards are in place, such as the National Institute of Standards and Technology (NIST) 800-181 document titled “Workforce Framework for Cybersecurity (NICE Framework)” available since September 2012, companies are still showing security vulnerabilities in their cyber networks (Hatzes, 2020). Barriers towards creating a cyber-ready workforce are not always due to a lack of resources, but often caused by organizational structure. The need for cyber-cognizant job postings, improved communication between Operational Technology (OT) and Information Technology (IT) employees, increases in staffing and funding for cyber teams, and better communication of standards and training can all contribute to increasing an organization’s cyber resilience. Cybersecurity Competency Health and Maturity Progression model (CYBER-CHAMP) is a model aimed at evaluating an organization’s structure and individual employee’s cyber knowledge and helps develop a plan to reach competency. This model was used to engage with organizations to promote proper cyber protocols and policies. The aim of this paper is to answer if it is possible for an organization to build a cyber-ready workforce by providing education and training options for current employees and prepare the future workforce to be ready on day one of employment. Both open source and firsthand interviews with organizations were used to conduct the research contained in this document. Further research may include additional development to the CYBER-CHAMP model and its delivery platform.

99 GENERAL AND MISCELLANEOUS↗

Cyber Risk Considerations for Nuclear Digital I&C Systems

Many engineers and scientists researching modeling and analysis methods for nuclear energy advancement are focused on proof-of-concept and early-stage development for new reactor designs. Since instrumentation and control (I&C) systems are traditionally developed later in the systems engineering lifecycle, researchers may be unfamiliar with modern digital technology used in these I&C systems. It is even more likely that they are unfamiliar with the cyber risks associated with them. This paper provides a brief overview of nuclear digital I&C systems before examining the importance of cyber risk management at nuclear reactors and the benefits of including Cyber-Informed Engineering throughout the systems engineering lifecycle. The primary goal is for engineers and scientists to develop a mindset that incorporates cybersecurity as another discipline alongside safety when designing and developing new technologies, regardless of technology readiness level.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A real-time multiphysics model of a pressurized solid oxide electrolysis cell (SOEC) for cyber-physical simulation

Solid oxide electrolysis cells (SOEC) can play important roles in integrated energy systems (IES) as the hydrogen production hub and the resilience energy hub. When tied to a microgrid with high renewable penetration, the SOEC is subjected to rapid load transitions in response to the intermittent renewable generations that occur not only in diurnal cycles but also in short timeframes (e.g., sub-minute). The cyber-physical simulation approach can derisk operability research but requires a real-time dynamic SOEC model. In the present work, a real-time multiphysics model for pressurized SOEC is developed and validated in the pressure range from 1.4 to 8bar. Further, the accuracy of the single repeating unit (SRU) assumption in SOEC stack simulation is quantified. A guidance of more than 45 cells in one SOEC stack is recommended to safely apply the SRU assumption. Modeling results suggest that at a given current density, more power is consumed by SOEC at elevated operating pressures. The anode air and cathode stream have major impacts on thermal management, highlighting the potential benefit of integrating SOEC with other thermal processes in IES. To achieve high hydrogen production efficiency, the SOEC could operate at the maximum endothermic point to maximize the use of thermal energy. The real-time execution of the developed SOEC model is also demonstrated, which only takes 0.1% of the fixed time step of 5ms. The developed model establishes the basis for cyber-physical simulation of SOEC hybrid systems.

25 ENERGY STORAGE↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

Attack-Resilient Weighted $\ell_{1}$ Observer with Prior Pruning

Security related questions for Cyber Physical Systems (CPS) have attracted much research attention in searching for novel methods for attack-resilient control and/or estimation. Specifically, false data injection attacks (FDIAs) have been shown to be capable of bypassing bad data detection (BDD), while arbitrarily compromising the integrity of state estimators and robust controller even with very sparse measurements corruption. Moreover, based on the inherent sparsity of pragmatic attack signals, ℓ1 -minimization scheme has been used extensively to improve the design of attack-resilient estimators. For this, the theoretical maximum for the percentage of compromised nodes that can be accommodated has been shown to be 50%. In order to guarantee correct state recoveries for larger percentage of attacked nodes, researchers have begun to incorporate prior information into the underlying resilient observer design framework. For the most pragmatic cases, this prior information is often obtained through some data-driven machine learning process. Existing results have shown strong positive correlation between the tolerated attack percentages and the precision of the prior information. In this paper, we present a pruning method to improve the precision of the prior information, given corresponding stochastic uncertainty characteristics of the underlying machine learning model. Then a weighted ℓ1 -minimization is proposed based on the pruned prior. The theoretical and simulation results show that the pruning method significantly improves the observer performance for much larger attack percentages, even when moderately accurate machine learning model used.

Resilient observer, Cyber-physical systems, prunin↗

Design and evaluation of a cyber‐physical testbed for improving attack resilience of power systems

Abstract A power system is a complex cyber‐physical system whose security is critical to its function. A major challenge is to model, analyse and visualise the communication backbone of the power systems concerning cyber threats. To achieve this, the design and evaluation of a cyber‐physical power system (CPPS) testbed called Resilient Energy Systems Lab (RESLab) are presented to capture realistic cyber, physical, and protection system features. RESLab is architected to be a fundamental platform for studying and improving the resilience of complex CPPS to cyber threats. The cyber network is emulated using Common Open Research Emulator (CORE), which acts as a gateway for the physical and protection devices to communicate. The physical grid is simulated in the dynamic time frame using Power World Dynamic Studio (PWDS). The protection components are modelled with both PWDS and physical devices including the SEL Real‐Time Automation Controller (RTAC). Distributed Network Protocol 3 (DNP3) is used to monitor and control the grid. Then, the design is exemplified and the tools are validated. This work presents four case studies on cyberattack and defence using RESLab, where we demonstrate false data and command injection using Man‐in‐the‐Middle and Denial of Service attacks and validate them on a large‐scale synthetic electric grid.

Sahu, Abhijeet↗

Denial of Service Attack Detection via Differential Analysis of Generalized Entropy Progressions

Denial-of-Service (DoS) attacks are one the most common and consequential cyber attacks in computer networks. While existing research offers a plethora of detection methods, the issue of achieving scalability, a low false positive rate, and high detection accuracy remains open. In this work, we address this problem by developing a differential method based on generalized entropy progression. In this method, named as DoDGE, we continuously fit the line of best fit to the entropy progression of destination addresses and check if the derivative, that is, the slope of this line is less than the negative of the dynamically computed standard deviation of the derivatives. Furthermore, to distinguish from flash events, we leverage the symmetry that when a flash event occurs, the derivative of the entropy progression of source addresses is positive. With this design, we omit the usage of the thresholds and the results with five real-world network traffic datasets confirm that DoDGE outperforms threshold-based DoS attack detection by two orders of magnitude in terms of false positives on average. When compared to ten machine learning (ML) models, DoDGE achieves a balanced accuracy of 99%, while the average balanced accuracy for the ML models is 52%. Moreover, the results show that DoDGE successfully differentiates between a flash event and a DoS attack. Furthermore, since the main computation cost of DoDGE is the entropy computation, which is linear in the volume of the unit-time network flow, uses integer only operations, and works on a small fraction of the total flow, it is lightweight and scalable.

Cybersecurity, wireless communication↗

Resilience in an Evolving Electrical Grid

Fundamental shifts in the structure and generation profile of electrical grids are occurring amidst increased demand for resilience. These two simultaneous trends create the need for new planning and operational practices for modern grids that account for the compounding uncertainties inherent in both resilience assessment and increasing contribution of variable inverter-based renewable energy sources. This work reviews the research work addressing the changing generation profile, state-of-the-art practices to address resilience, and research works at the intersection of these two topics in regards to electrical grids. The contribution of this work is to highlight the ongoing research in power system resilience and integration of variable inverter-based renewable energy sources in electrical grids, and to identify areas of current and further study at this intersection. Areas of research identified at this intersection include cyber-physical analysis of solar, wind, and distributed energy resources, microgrids, network evolution and observability, substation automation and self-healing, and probabilistic planning and operation methods.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Development and application of the GIM code for the Cyber 203 computer

The GIM computer code for fluid dynamics research was developed. Enhancement of the computer code, implicit algorithm development, turbulence model implementation, chemistry model development, interactive input module coding and wing/body flowfield computation are described. The GIM quasi-parabolic code development was completed, and the code used to compute a number of example cases. Turbulence models, algebraic and differential equations, were added to the basic viscous code. An equilibrium reacting chemistry model and implicit finite difference scheme were also added. Development was completed on the interactive module for generating the input data for GIM. Solutions for inviscid hypersonic flow over a wing/body configuration are also presented.

Stainaker, J. F.↗

Development and application of a program to calculate transonic flow around an oscillating three-dimensional wing using finite difference procedures

A finite difference method for solving the unsteady transonic flow about harmonically oscillating wings is investigated. The procedure is based on separating the velocity potential into steady and unsteady parts and linearizing the resulting unsteady differential equation for small disturbances. The differential equation for the unsteady potential is linear with spatially varying coefficients and with the time variable eliminated by assuming harmonic motion. Difference equations are derived for harmonic transonic flow to include a coordinate transformation for swept and tapered planforms. A pilot program is developed for three-dimensional planar lifting surface configurations (including thickness) for the CRAY-XMP at Boeing Commercial Airplanes and for the CYBER VPS-32 at the NASA Langley Research Center. An investigation is made of the effect of the location of the outer boundaries on accuracy for very small reduced frequencies. Finally, the pilot program is applied to the flutter analysis of a rectangular wing.

Weatherill, Warren H.↗

Using Structured Intelligence Graph (STIG) to protect our critical infrastructure against cyber attacks [Poster]

STIG is a revolutionary cybersecurity tool developed by researchers at the U. S. Department of Energy's Idaho National Laboratory and it is a software that allows utility owners and operators to easily visualize, create, and edit cyberthreat intelligence information. STIG uses Structured Threat Information eXpression (STIX) and converts complex data on cybersecurity vulnerabilities into a visualization that is easy to understand and act on. With STIG, utility owners and operators have a common system for sharing threat intelligence information, thus increasing the chances of detecting and mitigating cyber exploits before they lead to a cyberattack.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Cyber-Resilience Risk Management Architecture for Distributed Wind

Distributed wind is an electric energy resource segment with strong potential to be deployed in many applications, but special consideration of resilience and cybersecurity is needed to address the unique conditions associated with distributed wind. Distributed wind is a strong candidate to help meet renewable energy and carbon-free energy goals. However, care must be taken as more systems are installed to ensure that the systems are reliable, resilient, and secure. The physical and communications requirements for distributed wind mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity risk management for distributed wind systems specifically. This research develops an architecture for the consideration of cyber risks associated with distributed wind systems. The architecture takes into account the configurations, challenges, and standards for distributed wind to create a risk-focused perspective that considers of threats, vulnerabilities, and consequences, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We discuss common distributed wind architectures and how they are interconnected to larger power systems. Because cybersecurity cannot exist independently, the cyber-resilience architecture must consider the system holistically. Finally, we discuss the implementation of a risk assessment process that uses the cyber-resilience framework to address challenges specific to distributed wind.

17 WIND ENERGY↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

U.S. and Allied Cyber Security Cooperation in the Indo-Pacific (Workshop Summary)

On March 30, 31, and April 1, 2021, the Center for Global Security Research (CGSR) at Lawrence Livermore National Laboratory (LLNL) hosted a workshop titled "U.S. and allied Cyber Security Cooperation in the Indo-Pacific". This session brought together participants drawn across the policy, military, and private sector in the United States and among allied countries in Europe and the Indo-Pacific. The workshop evaluated threat perceptions, assessed cyber power in a regional context, and explored opportunities for building capacity and trust with allies, partners, and the private sector. The region's cyber threat landscape is marked by increasing malicious activity, with threats persistent and ever-growing. Grounded by this strategic reality, the workshop advocated for 1) a concerted push into the arena of norm setting from the bottom up, 2) an agreed metric by which to assess progress, and 3) the creation of future lines of collaborative effort for the United States and its allies to ensure an open, interoperable, and secure internet.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Science and Engineering of Cybersecurity by Uncertainty quantification and Rigorous Experimentation (SECURE) (Final Report)

This report summarizes the activities performed as part of the Science and Engineering of Cybersecurity by Uncertainty quantification and Rigorous Experimentation (SECURE) Grand Challenge LDRD project. We provide an overview of the research done in this project, including work on cyber emulation, uncertainty quantification, and optimization. We present examples of integrated analyses performed on two case studies: a network scanning/detection study and a malware command and control study. We highlight the importance of experimental workflows and list references of papers and presentations developed under this project. We outline lessons learned and suggestions for future work.

97 MATHEMATICS AND COMPUTING↗

Supply Chain Cybersecurity Recommendations for Solar Photovoltaics

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV has increased, cyber risk has also increased. However, utility solar PV installations are not required to comply with North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) unless they meet a minimum generation threshold of 75 Megawatts (MW). Individual residential scale solar PV deployments will not meet that generation threshold and are therefore excluded from NERC CIP requirements. With most solar installations below 75MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that make up the digital supply chain can include software, code, data, as well as other digital components. However as clean energy technology advances, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Solar PV faces a unique challenge in which it can be deployed in residential buildings and purchased by a consumer directly. This makes the supply chain of PV a unique challenge, where responsible parties for cybersecurity vary widely depending on the type of solar PV being deployed. Supply chain cybersecurity for solar PV represents a critical area for ensuring safe operations as the U.S. moves towards a clean energy future.

14 SOLAR ENERGY↗