Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Multiple social platforms reveal actionable signals for software vulnerability awareness: A study of GitHub, Twitter and Reddit

Software vulnerabilities are flaws in computer systems that leave users open to attack. In many cases, these vulnerabilities go unnoticed and remain unresolved in codebases. Thus, awareness of software vulnerabilities among the public is crucial to ensure effective cybersecurity practices, the development of high quality software, and ultimately national security. This awareness can be better understood by studying the spread and evolution of software vulnerability discussions in online communities. This work is the first to evaluate and contrast how discussions about software vulnerabilities spread on three social platforms -- Twitter, GitHub, and Reddit. To lay the groundwork, we showcase a novel fundamental framework for measuring information spread that identifies the spread mechanisms and observables across platforms, the units of information, and the groups of measurements that can be applied to focus on a specific phenomena e.g., information cascades. We then analyze and contrast social network topologies for three example social networks and measure the scale and speed of the spread of discussion of specific vulnerabilities to understand how far and how widely they spread, how many users participate in discussions, and the duration of their spread. To demonstrate the awareness of more impactful software vulnerabilities, a subset of our analysis focuses on vulnerabilities targeted during recent major cyber attacks as well as vulnerabilities exploited by advanced persistent threat groups. We discover that usually, vulnerability discussions start on GitHub, before occurring on Twitter and Reddit. While studying how some user-level and content-level characteristics influence vulnerability spread, we observe that Twitter discussions started by users predicted to be humans have larger size, breadth, depth, adoption rate, lifetime, and structural virality compared to those started by users predicted to be bots. On Reddit, we contrast the differences in thread structure that originate from posts with positive, negative and neutral polarity. We find that posts that are positive have larger, deeper and wider discussions compared to negative and neutral posts. We anticipate the results of our analysis to not only increase the understanding of software vulnerability awareness but also inform models for simulating information spread across multiple social environments online.

97 MATHEMATICS AND COMPUTING↗

Hardware-in-the-Loop Testbed for Cyber-Physical Security of Photovoltaic Farms

In the last decades, modem grids with distributed energy resources, such as photovoltaic (PV) farms, are increasingly vulnerable to cyber-attacks that seriously affect the stability and performance of the power system. While cyber-physical security of smart grids is extensively studied, most of the existing work focuses on the grid level and neglects the modeling and features of device-level power electronics converters (PECs). Furthermore, establishing a high-fidelity simulation testbed that can simulate harmonic frequencies of the PV farm is in urgent need. In this paper, a high-fidelity and real-time hardware-in- the-loop testbed is built to simulate the harmonics of power electronics converters for cyber-physical security of PEC-enabled PV farms. Based on this testbed, the impact of typical cyber-attacks and physical faults on the PV converter can be analyzed, thus providing a foundation for cyber-attack detection, root cause diagnosis, and resilient control to mitigate the adverse effects of cyber-attacks.

14 SOLAR ENERGY↗

Supporting Cyber Security of Power Distribution Systems by Detecting Differences Between Real-time Micro-Synchrophasor Measurements and Cyber-Reported SCADA (Final Report)

As modern power grids tend towards greater levels of automation and communication, the challenges of identifying and mitigating vulnerabilities to cyber-attacks are ones that are increasingly demanding attention. Today’s power system has evolved to form the foundational bedrock of modern society, and an attack on this infrastructure could prove disastrous. In this project we were tasked to investigate the use of distribution synchrophasors as an independent isolated sensor network with which we can corroborate, or flag potentially spoofed,Supervisory Control And Data Acquisition (SCADA) data. We adapted an approach to marry the underlying physical properties of power systems with the network communications used by power systems in order to offer insights unattainable by either data stream isolation. While the concept of intrusion detection systems (IDS) is well understood for monitoring network traffic and traditional IT computing systems, the approach discussed in this report is motivated by several key notions: first, current SCADA communications alone presents an incomplete view of the grid. Second, the power grid, and the equipment controlling it, is grounded by laws of physics. Given this, we leverage high-frequency physical grid measurements to understand the physical condition of the grid, and combine this with SCADA. While high-frequency physical grid measurements and SCADA communication over Internet Protocol (IP) networks are fundamentally disparate information sources, when collectively examined through appropriate lenses, they offer a much more nuanced depiction of the grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Deep Reinforcement Learning for Distribution System Cyber Attack Defense with DERs

The use of smart inverter capabilities of distributed energy resources (DERs) enhances the grid reliability but in the meanwhile exhibits more vulnerabilities to cyber-attacks. This paper proposes a deep reinforcement learning (DRL)-based defense approach. The defense problem is reformulated as a Markov decision making process to control DERs and minimizing load shedding to address the voltage violations caused by cyber-attacks. The original soft actor-critic (SAC) method for continuous actions has been extended to handle discrete and continuous actions for controlling DERs' setpoints and loadshedding scenarios. Numerical comparison results with other control approaches, such as Volt-VAR and Volt-Watt on the modified IEEE 33-node, show that the proposed method can achieve better voltage regulation and have less power losses in the presence of cyber-attacks.

active distribution systems↗

Communication Network Layer State Estimation Measurement Model for a Cyber-Secure Smart Grid

Network communication has been proven to be a very important tool and a key factor in the recent development and progress of the power grid operation. It is also considered as the foundation for the smart grid because information and communication are integrated into electricity distribution to achieve reliable and accurate knowledge of the power grid. In previous years, absorbing energy from substations and delivering it to customers was the only type of interaction we knew between utility companies and customers. Presently, the growing connections of small distributed generation units caused by the cost reduction of most of the technologies used in generation and storage of electrical energy, along with the potential benefits of renewable energy have pushed many researchers to look into the improvement of information and communication technologies (ICT) in order to ensure a bidirectional flow of power and data. Moreover, the evolution of information and communication technologies and its applications to smart grid have converted the smart grid into a cyber-physical system where vulnerabilities and additional security challenges such as cyber-threats and cyber-attacks have emerged. Previously, we have demonstrated that using machine learning-based processing on data gathered from communication networks and the power grid was a promising solution for detecting cyber threats by implementing a co-simulation of cyber-security for cross-layer strategy. Since the majority of the challenges observed can only be solved in the network communication layer, we present in this work a physics-based state estimation model of the communication network system towards enhanced cyber-physical security of the smart grid. Information integration with the previously developed machine learning model is developed, providing a enhanced cyber-physical security application for the smart grid. Easy-to-implement model, without hard-to-derive parameters, highlight potential aspects of the model for real-life applications.

Mathieu, Reynold↗

A holistic cyber-physical security protocol for authenticating the provenance and integrity of structural health monitoring imagery data

Modern infrastructure systems, such as bridges, dams, power generation stations, and buildings increasingly have an intrinsic cyber-physical nature to them. Infrastructure now commonly, includes actuators, network connections, sensors, control systems, and computational resources. It is of increasing concern that modern infrastructure is vulnerable to cyber-attacks that can damage both the cyber and physical nature of the infrastructure. To date, the physical and cyber health of infrastructure has been considered separately. However, the increasing concerns associated with the cyber-physical security of infrastructure coupled with the emergence of 5G networks made using components that are not universally considered trustworthy, and the emergence of techniques for creating deepfakes and adversarial examples suggests the time has come to begin considering cyber health and structural health with a more holistic approach. In this work, a protocol is developed for ensuring the imagery data captured by a structural health monitoring system can be unambiguously attributed to legitimate sensors associated with the structural health monitoring system. A computer vision approach based on the idea of mutual information is then presented to detect damage in an image. This work presents the protocol for authenticating the provenance of imager data and demonstrates that this protocol does not have overly adverse effects when used with the mutual information-based technique for detecting damage in the resulting imagery data.

Jung, HweeKwon↗

Cy-Phy ADS: Cyber Physical Anomaly Detection Framework for EV Charging Systems

Today’s large-scale Electric Vehicle (EV) infrastructures are heavily dependent on information communication technologies to maintain their operation and to support communication within sub-system components as well as the outside world. These technologies are vulnerable to various cyber and physical threats. Timely identification and mitigation of these threats are critical for improving human safety, avoiding economic losses, and preventing catastrophic system failures. By addressing this, our work presents a ResNet Autoencoder (AE) based Cyber-Physical Anomaly Detection System (Cy-Phy ADS) for detecting anomalies in EV Controller Area Network (CAN) protocol communication. It consists of four main components: Cyber-Physical Feature Extractor, ResNet AE-based Anomaly Detection Framework, Cyber-Physical Health Metric (CPHM), and Visualization Dashboard. The presented framework was trained and tested using CAN data collected from the EV charging system testbed at the Idaho National Laboratory. The presented Cy-Phy ADS compared against six widely used unsupervised anomaly detection algorithms: One Class Support Vector Machine (OCSVM), Variational Autoencoder (VAE), LSTM Autoencoder (LSTM AE), Isolation Forest (IForest), Principle Component Analysis (PCA) and Local Outlier Factor (LOF). Here the presented approach showed the highest accuracy among the compared methods. Further, the proposed approach showed comparable performance in terms of precision, F1, and False positive rate. It also showed the lowest training and inference time compared to the neural network-based baseline algorithms compared against with. Additionally, the Cy-Phy ADS has advantages such as unsupervised training, the ability to provide a holistic metric for system health characterization, and non-linear feature extraction.

99 GENERAL AND MISCELLANEOUS↗

Using the CYBER-Champ Model to Determine Cyber Competencies and Role Alignment

Cybersecurity roles, tasks, and skills are seen by many organizations as nonessential, abstract, or complicated. Although standards are in place, such as the National Institute of Standards and Technology (NIST) 800-181 document titled “Workforce Framework for Cybersecurity (NICE Framework)” available since September 2012, companies are still showing security vulnerabilities in their cyber networks (Hatzes, 2020). Barriers towards creating a cyber-ready workforce are not always due to a lack of resources, but often caused by organizational structure. The need for cyber-cognizant job postings, improved communication between Operational Technology (OT) and Information Technology (IT) employees, increases in staffing and funding for cyber teams, and better communication of standards and training can all contribute to increasing an organization’s cyber resilience. Cybersecurity Competency Health and Maturity Progression model (CYBER-CHAMP) is a model aimed at evaluating an organization’s structure and individual employee’s cyber knowledge and helps develop a plan to reach competency. This model was used to engage with organizations to promote proper cyber protocols and policies. The aim of this paper is to answer if it is possible for an organization to build a cyber-ready workforce by providing education and training options for current employees and prepare the future workforce to be ready on day one of employment. Both open source and firsthand interviews with organizations were used to conduct the research contained in this document. Further research may include additional development to the CYBER-CHAMP model and its delivery platform.

99 GENERAL AND MISCELLANEOUS↗

Cybersecurity Resiliency of Marine Renewable Energy Systems-Part 1: Identifying Cybersecurity Vulnerabilities and Determining Risk

Technology innovation, market demand, and the potential impacts of a changing climate are driving the marine renewable energy (MRE) industry to develop market-ready systems to provide low-carbon electricity for emerging, off-grid markets. The advanced operational and information technology devices used in MRE systems create a pathway for a cyber threat actor to gain unauthorized access to data or disrupt operation. To improve the resiliency of MRE systems as a predictable, affordable, and reliable source of energy from oceans and rivers, guidance was developed for an end users' organization that describes a framework for identifying and managing cybersecurity risk. The development of the cybersecurity guidance is based on standards described in the Risk Management Framework and Cybersecurity Framework developed by the National Institute of Standards and Technology (NIST). This paper is the first of a two-part series that describes an approach to determine the cybersecurity risk for MRE systems based on assessing potential cyber threats, identifying vulnerabilities (people, processes, and technology, including physical and operational environment), and evaluating the consequences a cyberattack would have on operation of the MRE system and impact on end users' mission and business objectives. MRE developers and stakeholders can use this approach to assess their current cybersecurity risk posture to incorporate appropriate cybersecurity controls to reduce the consequences and impacts from a cyberattack on MRE systems. This approach can be refined further as MRE systems are deployed and operational configurations are available.

97 MATHEMATICS AND COMPUTING↗

Cyber-Secure and Safe Operation of Solar Photovoltaic Power Distribution Systems

Solar photovoltaic (PV)-rich power distribution systems are networked Cyber-Physical Systems (CPS). These are control systems where multiple computing nodes and diverse intelligent agents interact with the physical world in real-time. However, the presence of networked components renders them vulnerable to potential cyber-attacks, cyber-intrusions, and other malicious events. This is because these systems depend on the measurements reported from their heterogeneous sensors. This makes them vulnerable to potential cyber-attacks where malicious agents can compromise the sensors or the communication networks carrying the sensor measurements. This paper proposes a novel methodology for enhancing the cyber-security and cyber-resilient post-attack safe operation of solar PV-rich power distribution systems against potential cyber-attacks through the Dynamic Watermarking (DW), using online system identification. The resiliency of the proposed technique is tested and validated with several attack scenarios on both a lab-scale 3kW grid-connected PV inverter and a Hardware-in-the-Loop (HiL) system. The proposed approach can be applied to other types of power distribution systems to enhance their cyber-secure and cyber-resilient safe operation. This paper thereby contributes to the field of cyber-security of Cyber-Physical Energy Systems (CPES).

Kim, Jaewon↗

Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Security Analysis for Nuclear Reactor Control Systems (Final Technical Report)

This project investigated the cyber-security impacts of moving from an all analog, point-to-point, instrumentation and control (I&C) system to a digital I&C system based on Modbus and a shared communication medium. A formalism called a hybrid attack graph was expanded to support the nuclear research reactor system. The hybrid attack graph allows one to check a system for vulnerabilities, in this case cyber-security vulnerabilities, and to document the attack vectors (scenarios) causing those vulnerabilities. In parallel, a simulation of the system was developed to model both the physical reactor parameters and operations, as well as the network interconnects and communications. This simulation platform was modeled on the nuclear research reactor located at Washington State University. The simulation platform provided a sandbox to evaluate and quantify the impact of identified and proposed vulnerabilities in the system and to determine the effectiveness of countermeasures at stopping these attacks. The simulation and hybrid attack graph tools were integrated to provide a streamlined process of generating attack scenarios, playing those scenarios out in the simulation, and then analyzing the results to correlate system state to states in the hybrid attack graph. This process was used to (1) quantify the impact of attack scenarios and (2) to determine if the system moved through the hybrid attack graph as anticipated. The hybrid attack graph tool was extended and customized to produce a tool to automatically identify critical assets (CAs) and critical digital assets (CDAs) as defined by NRC Regulatory Guide 5.71. This tool was verified using the nuclear research reactor at Washington State University. Finally, a series of educational modules covering the findings of the different aspects of this research have been created.

97 MATHEMATICS AND COMPUTING↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Analyzing the Effects of Cyberattacks on Distribution System State Estimation

Key components of power systems—such as energy management systems, automatic generation control, and state estimation—are under serious vulnerability from cyberattacks. Cyber threats in electric grids have increased significantly because of the increased interconnectivity of supervisory control and data acquisition systems and public network infrastructure. As the penetration level of distributed energy resources increases, it is imperative to employ system-monitoring techniques such as state estimation for the reliable operation of distribution systems. Recently, multiple methods have been developed that exploit the low rank property of distribution system state matrix and are robust to bad data, such as matrix completion. This paper analyzes the impact of various realistic cyberattack scenarios on matrix completion. Realistic cyberattack scenarios are converted into data corruption models that are used in an extensive simulation of a custom IEEE 123-bus system.

41 EE - Solar Energy Technologies Office (EE-4S)↗

Resilient Communication Scheme for Distributed Decision of Interconnecting Networks of Microgrids

Networking of microgrids can provide the operational flexibility needed for the increasing number of DERs deployed at the distribution level and supporting end-use demand when there is loss of the bulk power system. But, networked microgrids are vulnerable to cyber-physical attacks and faults due to the complex interconnections. As such, it is necessary To design resilient control systems to support the operations of networked microgrids in responses to cyber-physical attacks and faults. This paper introduces a resilient communication scheme for interconnecting multiple microgrids to support critical demand, in which the interconnection decision can be made distributedly by each microgrid controller even in the presence of cyberattacks to some communication links or microgrid controllers. This scheme blends a randomized peer-to-peer communication network for exchanging information among controllers and resilient consensus algorithms for achieving reliable interconnection agreement. The network of 6 microgrids divided from a modified 123-node test distribution feeder is used to demonstrate the effectiveness of the proposed resilient communication scheme.

Vu, Thanh Long↗

Towards Smart Grids Enhanced Situation Awareness: A Bi-Level Quasi-Static State Estimation Model

Smart Grid situational awareness is provided by Energy Management Systems. A core process of these systems is State Estimation. The great majority of state estimators model the Smart Grid through a set of nonlinear algebraic equations, named the measurement model. Problem formulation considers the Gauss solution. Several model improvements have been presented regarding the Gauss solution, aiming between others to provide measurement noise robustness to the state estimation process. While considerable effort has been focused on such developments, state estimation is still constrained by the implicit modelling error, and thus inevitably vulnerable to cyber-threats. In this work, a state estimation bi-level formal model is presented towards Smart Grids enhanced situational awareness considering the concepts of synthetic measurements and innovation. Comparative test results with the state-of-the-art on the IEEE 14-bus system are presented highlighting improved situational awareness to bad data. Easy-to-implement model, without hard-to-derive parameters, built-on the classic weighted least squares solution, highlight potential aspects for real-life implementation.

cyber security↗

Discovery of False Data Injection Attacks on Power Grid Frequency Controllers with Reinforcement Learning [Poster]

While inverter-based DER (distributed energy resources) are instrumental to integrating renewable energy into the power grid, they reduce the grid's mechanical inertia, thereby increasing the risk of frequency instabilities. To compensate for frequency instability risks, the grid must also undergo a transformation to include digital technologies that allow for two-way communication between the utility and customers. The current and future state of the power grid allows for building a cleaner energy landscape. However, the grid may also become vulnerable to novel cyber threats. To preemptively protect the power grid against elaborate cyber-attacks, we propose to discover potential threats via reinforcement learning. In this work, the focus is on studying false data injection attacks that target the control logic of frequency controllers. We show that a reinforcement learning agent can successfully discover how to best inject false data into linear droop controllers.

24 POWER TRANSMISSION AND DISTRIBUTION↗