Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Losing Control of Your Linear Network? Try Resilience Theory

Resilience of cyber-physical networks to unexpected failures is a critical need widely recognized across domains. For instance, power grids, telecommunication networks, transportation infrastructures, and water treatment systems have all been subject to disruptive malfunctions and catastrophic cyberattacks. Following such adverse events, we investigate scenarios where a node of a linear network suffers a loss of control authority over some of its actuators. These actuators are not following the controller's commands and are instead producing undesirable outputs. The repercussions of such a loss of control can propagate and destabilize the whole network despite the malfunction occurring at a single node. To assess system vulnerability, we establish resilience conditions for networks with a subsystem enduring a loss of control authority over some of its actuators. Furthermore, we quantify the destabilizing impact on the overall network when such a malfunction perturbs a nonresilient subsystem. We illustrate our resilience conditions on two academic examples, on an islanded microgrid and on the linearized IEEE 39-bus system.

97 MATHEMATICS AND COMPUTING↗

Guest Editorial: Special section on Resilient Control of Cyber-Physical Power and Energy Systems

Our power and energy systems are becoming more and more integrated and interconnected. The increasing integration of edge devices and dependence on cyber infrastructure provides both the potential for benefits and risks. The integration enables more dynamic and flexible control paradigms while at the same time increasing the cyberattack surface and uncertainty of behavior. Control methodology in this new world must be designed for resilience and must have the ability to withstand, react, and respond to both physical faults and cyber-induced threats. Finally, understanding system resilience under adverse conditions requires studying control performance and how cyber infrastructure can integrate with and support the overall resilience of the system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distributed Intrusion Detection System using Semantic-based Rules for SCADA in Smart Grid

Cyber-physical system (CPS) security for the smart grid enables secure communication for the SCADA and wide-area measurement system data. Power utilities world-wide use various SCADA protocols, namely DNP3, Modbus, and IEC 61850, for the data exchanges across substation field devices, remote terminal units (RTUs), and control center applications. Adversaries may exploit compromised SCADA protocols for the reconnaissance, data exfiltration, vulnerability assessment, and injection of stealthy cyberattacks to affect power system operation. In this paper, we propose an efficient algorithm to generate robust rule sets. We integrate the rule sets into an intrusion detection system (IDS), which continuously monitors the DNP3 data traffic at a substation network and detects intrusions and anomalies in real-time. To enable CPS-aware wide-area situational awareness, we integrated the methodology into an open-source distributed-IDS (D-IDS) framework. The D-IDS facilitates central monitoring of the detected anomalies from the geographically distributed substations and to the control center. The proposed algorithm provides an optimal solution to detect network intrusions and abnormal behavior. Different types of IDS rules based on packet payload, packet flow, and time threshold are generated. Further, IDS testing and evaluation is performed with a set of rules in different sequences. The detection time is measured for different IDS rules, and the results are plotted. All the experiments are conducted at Power Cyber Lab, Iowa State University, for multiple power grid models. After successful testing and evaluation, knowledge and implementation are transferred to field deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Machine Learning Based Resilience Testing of an Address Randomization Cyber Defense

Moving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. Here, in this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING↗

Detecting Masquerade Attacks in Controller Area Networks Using Graph Machine Learning

Modern vehicles rely on a myriad of electronic control units (ECUs) interconnected via controller area networks (CANs) for critical operations. Despite their ubiquitous use and reliability, CANs are susceptible to sophisticated cyberattacks, particularly masquerade attacks, which inject false data that mimic legitimate messages at the expected frequency. These attacks pose severe risks such as unintended acceleration, brake deactivation, and rogue steering. Traditional intrusion detection systems (IDS) often struggle to detect these subtle intrusions due to their seamless integration into normal traffic. This paper introduces a novel framework for detecting masquerade attacks in the CAN bus using graph machine learning (ML). We hypothesize that the integration of shallow graph embeddings with time series features derived from CAN frames enhances the detection of masquerade attacks. We show that by representing CAN bus frames as message sequence graphs (MSGs) and enriching each node with contextual statistical attributes from time series, we can enhance detection capabilities across various attack patterns compared to using graph-based features only. Our method ensures a comprehensive and dynamic analysis of CAN frame interactions, improving robustness and efficiency. Extensive experiments on the ROAD dataset validate the effectiveness of our approach, demonstrating statistically significant improvements in the detection rates of masquerade attacks compared to a baseline that uses graph-based features only as confirmed by Mann-Whitney U and Kolmogorov-Smirnov tests (p < 0.05) .

Marfo, William [Univ. of Texas, El Paso, TX (Unite↗

Adaptive Control of Distributed Energy Resources for Distribution Grid Voltage Stability

Volt-VAR and Volt-Watt functionality in photovoltaic (PV) smart inverters provide mechanisms to ensure system voltage magnitudes and power factors remain within acceptable limits. However, these control functions can become unstable, introducing oscillations in system voltages when not appropriately configured or maliciously altered during a cyberattack. In the event that Volt-VAR and Volt-Watt control functions in a portion of PV smart inverters in a distribution grid are unstable, the proposed adaptation scheme utilizes the remaining and stably-behaving PV smart inverters and other Distributed Energy Resources to mitigate the effect of the instability. The adaptation mechanism is entirely decentralized, model-free, communication-free, and requires virtually no external configuration. Here we provide a derivation of the adaptive control approach and validate the algorithm in experiments on the IEEE 37 and 8500 node test feeders.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Robust Restoration From Cyber-Physical Attacks in Active Distribution Grids With Grid-Edge IBRs

The inverter-based resources (IBRs) have enabled the integration of renewable energy at the grid edge with enhanced control capabilities to support the reliable operation of power grids. Different control frameworks, such as hierarchical or distributed architecture, have been proposed with the expansion of cyber networks for real-time monitoring and control. This evolution of critical infrastructure into cyber-physical systems also brings more vulnerabilities for the broadened attack surfaces, and significantly increases the possibility of physical system failures or outages caused by cyberattacks. Among tremendous efforts in the defense-in-depth approach, it remains challenging to provide prompt detection and accurate location of attack entry points or paths. Therefore, the prevailing restoration framework may struggle to fully consider the cyber-physical interdependence, successfully isolate the compromised cyber and physical components, and safely recover the systems without the potential risks leading to secondary outages. This paper is motivated to develop a cyber-physical restoration framework for distribution grids to recover from cyber attacks by harnessing grid-edge IBRs. The framework is first built on the operational guidelines of IBRs considering the compromised cyber layer. Then, an ambiguity set is established to represent the uncertainty of attack scenarios and their possibility levels. Next, a distributionally robust optimization model is developed to provide the optimal load restoration strategy across all scenarios. The effectiveness of the proposed model is demonstrated through various use cases on the modified IEEE 13-node and 123-node test systems. Finally, simulation results demonstrate the effectiveness and advancement of developed post-attack restoration strategies.

Cybersecurity↗

A Photovoltaic MPPT Charge Controller Real-Time Testbed for Cybersecurity Applications

The increasing deployment of distributed energy resources (DER) over the last decade is a great ally to combat climate change and strengthen the grid during increasingly common extreme weather events. However, DER systems, combined with the ongoing transition to a digital power grid, also pose substantial cybersecurity threats. One of the most common communication protocols used in DER integration is the Distributed Network Protocol 3 (DNP3), which is known to have many security vulnerabilities. Thus, it is essential to investigate cyberattack behaviors and mitigation on power systems using DNP3. In this paper, we designed and implemented a cybersecurity testbed for a simulated photovoltaic (PV) maximum power point tracking (MPPT) charge controller. Our testbed uses an MPPT charge controller simulated on a Typhoon HIL602+ real-time simulator with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) systems.

14 SOLAR ENERGY↗

Analyzing Infrastructure Interdependencies Using Network-Of-Networks Modeling

Infrastructure networks play a crucial role in our day-to-day lives, and modeling these infrastructure networks can help decisionmakers prepare for and respond to disruptions such as natural disasters or cyberattacks. Because these infrastructure networks depend on each other, it is not sufficient to model a single network in isolation. We build on previous single-network-modeling techniques to develop a methodology for modeling infrastructure interdependencies as a Network-of-Networks. Using distributionlevel data from a real U.S. city on the power grid, road geometry, and hospital locations, we show how to apply this methodology to modeling three of the U.S. Department of Homeland Security's Critical Infrastructure Sectors: Healthcare, Transportation, and Energy. We also analyze three primary metrics before and after a simulated disaster: 1) impact on hospital access; 2) road network impact with the change in betweenness centrality; 3) electric customer outage. We simulate three different disruptions: 1) road flooding from nearby rivers; 2) a malicious actor targeting the road networks; 3) a malicious actor targeting the electric grid. Finally, we discuss how our methodology can be applied to additional infrastructure networks and types of disruption, and how Artificial Intelligence (AI) techniques may be incorporated into this methodology for further research.

Scherrer, Evan [Drake University, Iowa]↗

CEDS Differential Privacy (CEDSDP) v0.1

A Python package that provides differentially private queries optimized for energy systems' data. It may be used to publish queries such as clustering, averaging, metadata inference, etc. that are useful for a variety of grid-related analytics, including cyberattack detection.

Peisert, Sean↗

Adaptive Control Algorithm to Adjust Settings in Photovoltaic Inverters for Electric Grid Cybersecurity (DERAC) v0.1

Volt-VAR and Volt-Watt functionality in photovoltaic (PV) smart inverters provide mechanisms to ensure system voltage magnitudes and power factors remain within acceptable limits. However, these control functions can become unstable, introducing oscillations in system voltages when not appropriately configured or maliciously altered during a cyberattack. In the event that Volt-VAR and Volt-Watt control functions in a portion of PV smart inverters in a distribution grid are unstable, the proposed adaptation scheme utilizes the remaining and stably-behaving PV smart inverters and other Distributed Energy Resources to mitigate the effect of the instability in real-time. The adaptation mechanism is entirely decentralized, model-free, communication-free, and requires virtually no external configuration. This repository provides code to simulate the algorithm in experiments on the IEEE 37 node test feeder.

Arnold, Daniel↗

DER Cybersecurity Detection and Response Suite

SAND2024-08475O The Distributed Energy Resource (DER) Cybersecurity Detection and Response Suite is a solution for distributed energy resource (DER) systems. The DER Security Orchestration, Automation, and Response (SOAR) solution that uses alerts from signature- and behavior-based Intrusion Detection Systems are intended to be deployed as bump-in-the-wire (BITW) devices in front of DER equipment. The fielded application would use multiple intrusion detection systems that report data to SOAR to respond to cyberattacks. The suite consists of two software components: • The proactive intrusion detection and mitigation system (PIDMS) secures grid-edge photovoltaic smart inverters and other equipment in distributed energy resource systems. It is a distributed BITW solution; cyber and physical data are automatically processed using network inspection tools and custom machine learning algorithms to detect abnormal events and correlate cyber-physical events. • The Security Orchestration, Automation, and Response for Distributed Energy Resources (SOAR4DER) application ingests data from several intrusion detection systems to quickly block attacks and revert DER systems to good states. Using a collection of intrusion detection system technologies on a BITW device, it incorporates physical and cyber data to detect abnormal and potential malicious behaviors. Multiple SOAR playbooks then use the intrusion detection system data streams to automatically defend the system. SOAR4DER system testing showed detection and response times under 30 seconds for all adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute-force logins, and machine-in-the-middle attacks. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Johnson, Jay↗

Dynamic Disruption Resilience in Intermodal Transport Networks: Integrating Flow Weighting and Centrality Measures

Resilient intermodal freight networks are vital for sustaining supply chains amid increasing threats from natural hazards and cyberattacks. Transportation resilience has been widely studied; understanding how random and targeted disruptions affect structural connectivity and functional performance remains a key challenge. To address this, this study evaluates the robustness of the US intermodal freight network, which consists of rail and water modes, using a simulation-based framework that integrates graph-theoretic metrics with flow-weighted centrality measures. Disruption scenarios are examined, including random failures as well as targeted node and edge removals based on static and dynamically updated degree and betweenness centrality. To reflect more realistic conditions, flow-weighted degree centralities (WDC) and partial node degradation are considered. Two resilience indicators are used: (1) the size of the giant connected component to measure structural connectivity; and (2) flow-weighted network efficiency (NE) to assess freight mobility under disruption. The results show that progressively degrading nodes ranked by WDC to 60% of their original functionality causes a sharper decline in normalized NE, for up to approximately 45 affected nodes, than complete failure (100% loss of functionality) applied to nodes targeted by weighted betweenness centrality or selected at random. This highlights how partial degradation of high-tonnage hubs can produce disproportionately large functional losses. The findings emphasize the need for resilience strategies that go beyond network topology to incorporate freight flow dynamics.

42 ENGINEERING↗

Driver Identification Dataset

The ORNL Driver Identification Dataset was created to collect and analyze driving behavior data from 50 different drivers. Each driver operated a 2014 Kenworth T270 Class 6 truck around Fort Collins, Colorado while various data sources recorded their driving behavior and vehicle performance. The dataset includes CANbus (Controller Area Network) data, GPS data, inertial measurement data, and biometric data from a heart rate monitor. A cyberattack was executed during each drive, which caused multiple dashboard warning lights to illuminate and set the tachometer and speedometer to zero, regardless of actual speed. The attack was stopped either after one minute or if the driver pulled over. By downloading the dataset, you agree to the following: 1) I will not use or disclose the data for any purpose other than Research as that term is defined in 10 CFR 745.102. 2) I will not, under any circumstances, request or accept private or linking identifiers for the data used. 3) I will not attempt to determine the identity of the individuals associated with the data. 4) I will use appropriate safeguards to prevent the use or disclose of the data for any purpose other than Research.

99 GENERAL AND MISCELLANEOUS↗

Strengthening the Security of Operational Technology: Understanding Contemporary Bill of Materials

The evolution of cyber-physical infrastructure has made its security more challenging. The last few years have witnessed a convergence of hardware and software segments in various domains, including operational technology (OT) which is responsible for carrying out critical tasks such as monitoring and controlling power grids, nuclear plants, transportation, and emergency services. Both hardware and software encapsulate numerous open source and proprietary subcomponents, making it crucial for end-users to understand the composition of the products they are using. For example, wind turbines incorporate thousands of lines of code (software) used for the turbine's design, planning, operation, and analytics in addition to the numerous hardware subcomponents that construct it. Due to the highly complex nature of software and hardware, knowledge of the components and subcomponents is required to mitigate cyber vulnerabilities and defend against cyberattacks. There has also been a transformation from a traditional linear supply chain into a global, dynamic, diverse, and interconnected system. The digitization of the supply chain makes it easier to find and exploit vulnerabilities. Critical infrastructures (e.g., power grids, oil, natural gas, water, and wastewater) rely on OT to function, and if the OT is compromised, equipment damage and potential interruption of services could result. A significant security measure to protect OT systems from disruption is to develop a supply chain bill of materials (BoM) corresponding to the software and hardware used in OT, along with attestations amongst vendors and asset owners. A supply chain BoM is a proactive way to understand the inherent vulnerabilities in the system and mitigate them in advance of being exploited. BoMs bolster the trust placed in the digital infrastructure and enhance software supply chain security by sustaining the management of component obsolescence and compliance, along with the seclusion of unsafe segments of a specific product. Adopting BoM tools is becoming increasingly important across various government sectors, as evidenced by the recent U.S. executive order on cybersecurity (NIST 2021). This paper aims to classify BoMs based on structure, functionality, component type, and architecture. The work also discusses case studies to further highlight the benefits of BoMs. In addition, it identifies missing pieces in existing BoM implementations so that future research may identify bounds on where it could expect to make improvements and directly enable researchers to identify promising areas for exploration. Further, the authors provide valuable recommendations to tool developers, researchers, and standardizing organizations (policymakers), additionally benefitting critical infrastructure owners and government executives. This aids in paving a path for future work, thereby, providing suggestions to determine a tool for consumers that best suit their needs.

97 MATHEMATICS AND COMPUTING↗

Securing Vehicle Charging Infrastructure

As the US electrifies the transportation sector, cyber attacks targeting vehicle charging could bring consequences to electrical system infrastructure. This is a growing area of concern as charging stations increase power delivery and must communicate to a range of entities to authorize charging, sequence the charging process, and manage load (grid operators, vehicles, OEM vendors, charging network operators, etc.). The research challenges are numerous and are complicated because there are many end users, stakeholders, and software and equipment vendors interests involved. Poorly implemented electric vehicle supply equipment (EVSE), electric vehicle (EV), or grid communication system cybersecurity could be a significant risk to EV adoption because the political, social, and financial impact of cyberattacks - or public perception of such - ripples across the industry and has lasting and devastating effects. Unfortunately, there is no comprehensive EVSE cybersecurity approach and limited best practices have been adopted by the EV/EVSE industry. There is an incomplete industry understanding of the attack surface, interconnected assets, and unsecured interfaces. Thus, comprehensive cybersecurity recommendations founded on sound research are necessary to secure EV charging infrastructure. This project is providing the power, security, and automotive industry with a strong technical basis for securing this infrastructure by developing threat models, determining technology gaps, and identifying or developing effective countermeasures. Specifically, the team is creating a cybersecurity threat model and performing a technical risk assessment of EVSE assets, so that automotive, charging, and utility stakeholders can better protect customers, vehicles, and power systems in the face of new cyber threats.

33 ADVANCED PROPULSION SYSTEMS↗