Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

CYDRES: CYber Defense and REsilient System for securing grid-interactive efficient buildings

Smart buildings, especially Grid-interactive Efficient Buildings (GEBs), suffer from cyber-attacks and physical faults due to the integration of a large number of sensors and controls, connected devices, and associated communication networks. This study demonstrated a real-time advanced building resilient platform, called CYber Defense and REsilient System (CYDRES), which is deployable for existing and emerging Building Automation Systems (BASs). CYDRES aims to empower GEBs with cyber-attack-immune capabilities through multi-layer prevention and adaptation mechanisms to monitor, detect, and respond to cyber-attacks and physical operational faults. CYDRES is demonstrated through real-time experiments in a Hardware-in-the-Loop (HIL) testbed.

Building automation system, Cyber-attacks, Physica↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

High-fidelity model-driven deception platform for cyber-physical systems

A system is described for protecting a cyber-physical system against a potential attacker of the cyber-physical system. The system includes at least one processor configured to: collect historical information about the cyber-physical system, and train, based on the historical information, a machine-learned model to predict future conditions of at least a portion of the cyber-physical system. Responsive to detecting an input signal to the cyber-physical system, the system is configured to output an alert to the cyber-physical system indicative of a potential attacker, and respond to the input signal by simulating, based on the future conditions predicted by the machine-learned model, functionality and communications of the at least a portion of the cyber-physical system.

Edgar, Thomas W.↗

Cyote Research Tool Library

The software is a library of individual proof-of-concept tools to be further developed in research efforts with partner utilities to detect indicators of Cyber Attacks within the Operational Technology Environments.

Wellman, LawrenceR.↗

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

Cybersecurity for Distributed Energy Resources: All Hazards Approach for Grid Modernization

Distributed energy resources (DER) sit at the intersection of IoT and critical infrastructure. As we work towards clean energy and decarbonization targets, high rates of growth of DER are expected, making them an important component of generation and grid services. They have been a part of the explosion of internet connected devices developed to solve real-world problems and make life easier by providing clean, local energy and enable the smart management of grid services. However, the quick-to-market, low-cost drivers for DER, combined with a historically relative low-impact has meant that cybersecurity has not been a top priority. So as DER penetration increases, will DER be a part of the growing challenge of securing the grid, or part of the solution for necessary grid modernization? In this talk, we will discuss the factors that have led to our current position and what makes cybersecurity for DER unique. A wide range of research is conducted at national labs, in partnership with industry and academia, to inform everything from standards and regulation, to the development of cyber-physical anomaly detection through use of digital twins, and even advanced threat analytics to SBOM and HBOM tracking. Even with this multi-faceted approach to the challenges, the question remains: is this too little too late or are we doing enough to secure the grid for the next 30 years?

14 SOLAR ENERGY↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in Urban Air Mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex components has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens safety and the efficiency of transportation networks.In response to these challenges, this paper presents a study on the need for cyber resilient techniques within future air traffic environments. It will pay specific attention to the implementation of a Host-Based Intrusion Detection System (HIDS) utilizing Atomic OSSEC software, tailored specifically to a NASA simulation of an UrbanAirMobility environments’ unique demands. Further, this study seeks to outline the rational for NASA’s recommendation for a HIDS in such environments. It explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the Urban Air Mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organizations overall cybersecurity posture. Finally, this study aims to provide recommendations and include learned takeaways that the Urban Air Mobility industry should consider. In brief, this paper highlights the significance of host-based intrusion detection in UrbanAirMobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Electrical substation grid testbed for DLT applications of electrical fault detection, power quality monitoring, DERs use cases and cyber-events

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation, and are associated with customer-owned distributed energy resources (DERs). The integrity and confidentiality of data from these IEDs, like power meters and protective relays, is crucial. Blockchain technology could improve the resilience of microgrids by improving the security of data sharing. The penetration of customer-owned DERs (renewable energy sources) and the increasing deployment of IEDs can lead to integrate power system applications with Distributed Ledger Technology (DLT). In this study, we implemented the electrical faulted phase detection and power quality monitoring algorithms with a Cyber Grid Guard (CGG) system using DLT. In addition, the DERs (wind turbine farms) use case and protective relay cyber-event tests were assessed, by using the CGG system with DLT. In the experimental model, the testbed was created by using a real-time simulator and CGG system with power meters/ protective relays in-the-loop. The data collected from the CGG system and IEDs were compared with the same time stamp source. These results had shown the successful assessment of protection, control and monitoring applications using a CGG system with DLT. In the future, the ESGT with DERs and the CGG system will be used in other power system applications, based on implementing smart contracts between electrical utilities with customer-owned DERs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in urban air mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex infrastructures has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens’ safety and the efficiency of transportation networks. In response to these challenges, this paper presents a study on implementing a Host-Based Intrusion Detection System (HIDS) tailored explicitly to urban mobility environments’ unique demands. This study explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the urban mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organization’s overall cybersecurity posture. In conclusion, this paper highlights the significance of host-based intrusion detection in urban mobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Anomaly Detection and Mitigation in FACTS-based Wide-Area Voltage Control Systems using Machine Learning

With the increasing deployment of Flexible AC Transmission System (FACTS) devices in wide-area voltage control systems (WAVCS) for achieving improved voltage stability of bulk power systems, the possibility for cyber attacks on these systems is also increasing. Successful stealthy cyber attacks that are difficult to detect by traditional informational technology (IT)-based cybersecurity solutions or threshold-based bad data detectors can lead to a voltage collapse in power grid. This paper presents the testbed-based attacks implementation and real-time evaluation of machine learning (ML) algorithm for detecting and mitigating stealthy cyber attacks on FACTS-based WAVCS on a hardware-in-the-loop (HIL) testbed. Initially, we discuss the implementation of a fuzzy logic controller (FLC) that controls a Static VAR Compensator (SVC) device deployed in a two-area four-machine Kundur power system for improving transient voltage stability. Later, the ML-based Anomaly Detection and Mitigation (ADM) system is implemented on the cyber-physical HIL testbed to detect and mitigate various stealthy cyber attacks, which are injected in real-time over the wide-area network (WAN). The experimental results show accurate and effective performance of ADM system in detecting and mitigating anomalies while keeping the grid stable and within the system operating limits, as defined by the North America Electric Reliability Corporation (NERC).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Enhancing Automotive Intrusion Detection Through Multi-Modal Fusion: A CAN FD-LiDAR Approach

As vehicles become smarter and more autonomous, they increasingly depend on advanced sensors and communication technologies to operate securely. However, such growing dependence on technology—whether it’s CAN (Controller Area Network) for internal communication or LiDAR (Light Detection and Ranging) for sensing the world around them—also expands the attack surface for the types of cyber attacks. Traditional intrusion detection systems (IDS) typically monitor these systems in isolation, limiting their ability to detect sophisticated, crosssystem attacks. To address this, we propose a multi-modal fusion approach that combines real-world CAN FD signals (from the HCRL dataset) with LiDAR features (from the nuScenes dataset) to enhance attack detection. Our method employs a twostage ensemble approach. Calibrated XGBoost and LightGBM models initially process CAN FD (Fuzzing Data) and LiDAR data independently, detecting timing anomalies and space abnormalities. They are subsequently logarithmically combined with a logistic regression meta-model along with 17 engineered features capturing cross-modal behavior, prediction conflicts, and nonlinear interactions. This approach achieves an AUC of 0.87 and an F1-score of 0.82, surpassing single-modality baselines and early fusion methods, at merely 2 ms inference latency. Compared with deep learning competitors, it is 3 times more efficient, providing a lightweight, interpretable, and real time solution to automotive cybersecurity.

97 MATHEMATICS AND COMPUTING↗

Cognitive IoT and Edge Computing for Intrusion Detection with Federated TinyML

Internet of Things (IoT) and Edge Computing (EC) are rapidly becoming an integral part of the modern society. By 2030, there is estimated to be over 40 billion active and connected IoT devices [1]. This rapid progress also comes with a significant implication on cybersecurity. Back-end infrastructure and systems have a much broader attack than they did previously due to vulnerable IoT/EC devices being connected to wireless networks. This expanding attack surface is a growing concern because IoT/EC are increasingly being used in critical systems such as power grids, health care, and smart homes. To effectively address a problem of this scale, cognitive cyber methods—which can autonomously detect and react to cyber attacks as they develop—are needed. To address this, we bring Artificial Intelligence (AI) and Machine Learning (ML) to IoT/EC devices, using tinyML to monitor voluminous IoT data against cyber threats, and using Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. We propose a novel three-layer architecture: (1) an IoT layer for tinyML-based inference, (2) an edge layer for ML model training, and (3) a cloud layer for FL operations. Using the publicly available 11-class N-BaIoT dataset [2], we demonstrate that this architecture mitigates resource constraints at the IoT layer while improving detection accuracy over standard two-layer designs. An outlier-resistant scaler, feature reduction, and quantization enable the tinyML model to maintain detection accuracy with a reduced model size. Additionally, federated learning that only utilizes the intersection (across heterogenous devices) of the reduced feature set achieves superior detection accuracy compared to locally trained models.

Li, Mingyan [ORNL] (ORCID:0009000569532640)↗

Hybrid feature-driven learning system for abnormality detection and localization

A cyber-physical system may have a plurality of monitoring nodes each generating a series of current monitoring node values over time representing current operation of the system. A data-driven features extraction computer platform may receive the series of current monitoring node values and generate current data-driven feature vectors based on the series of current monitoring node values. A residual features extraction computer platform may receive the series of current monitoring node values, execute a system model and utilize a stochastic filter to determine current residual values, and generate current residual-driven feature vectors based on the current residual values. An abnormal detection platform may then receive the current data-driven and residual-driven feature vectors and compare the current data-driven and residual-driven feature vectors with at least one decision boundary associated with an abnormal detection model. An abnormal alert signal may then be transmitted when appropriate based on a result of said comparison.

Abbaszadeh, Masoud↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Physical Events Emulation Based Transmission and Distribution Co-Simulation for Situation Awareness and Grid Anomaly (SAGA) Detection: Preprint

Energy management of transmission and distribution networks is becoming more challenged with the accelerated increasing of distributed energy resources (DERs) such as distributed photovoltaic (PV) generation and distributed energy storage. To better analyze the impacts of DERs on both transmission and distribution systems, a comprehensive transmission and distribution co-simulation platform should be developed. Furthermore, with DERs more actively participated in system operation such as providing real time grid services, their cyber vulnerability should be better understood to maintain system reliability. This paper discussed a cyber-physical events emulation based transmission & distribution co-simulation platform to perform different cyber events emulation and analyze the impacts of cyber physical events happened in distribution system on the T&D system operation. The case studies with both a transmission network and a synthetic distribution network data validate that the proposed T&D co-simulation platform can perform comprehensive cyber physical events emulation. Therefore, with extensive simulation using the proposed model, the system operator can accumulate adequate training data for the system situation awareness and grid anomaly detection purpose.

31 CESER - Office of Cybersecurity, Energy Securit↗