Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

Cybersecurity Enhancement in Digital Substations: Hidden Markov Model-Based Smart Cyber Switching and Threat Response

The rising incidence of cyber-attacks on critical infrastructure and power grids poses significant threats to the stability and reliability of electrical substations, with potentially devastating consequences such as extended blackouts. This paper introduces an advanced cybersecurity framework aimed at safeguarding IEC 61850-based substations through the integration of software-defined networking (SDN) and digital twin (DT) technologies. The proposed DT-based framework employs smart cyber switching (SCS) for proactive threat mitigation and concurrent intelligent electronic device (CIED) for swift system restoration, thereby maintaining continuous operational integrity and robust cybersecurity defenses. Central to this framework is the adaptive port controller (APC), which enables dynamic port management to adapt to evolving threats, and an intrusion detection system (IDS) designed to detect and neutralize malicious attacks on IEC 61850-based sampled value (SV) and generic object-oriented substation event (GOOSE) messages within the substation’s communication network. Further, novel predictive intrusion detection and response (PIDR) algorithm is implemented on a digital substation (DS) to predict the best route to be taken by the attacker. The efficacy of these comprehensive cybersecurity frameworks is validated through rigorous simulations and a hardware-in-the-loop (HIL) testbed, showcasing the system’s ability to sustain substation operations amidst cyber-attacks.

Digital substation↗

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

Sensor and Actuator Attacks on Hierarchical Control Systems with Domain-Aware Operator Theory

Cyber-Physical Systems (CPSs) provide opportunities for cyber attacks to have physical impacts. Advanced Persistent Threats (APTs) are a subclass of cyber threats that act stealthily to avoid detection and enable long-term attacks. Here, we build on our past work in APT modelling to combine deception-based sensor bias attacks and direct actuator manipulations in attacks against a hierarchical control system. That past work used the Koopman operator to develop a data-driven, domain-aware, optimization-based attacker model. Using an expansion of this model, we compute several different attacks, including multiple simultaneous attacks, against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. One next step of interest is to construct a defender system, built on the same modelling approach, designed to detect and mitigate such attacks.

koopman operator, Cyber-Physical Security, machine↗

Feature Engineering and Ensemble Methods for Imbalanced ICS Intrusion Detection: Pipeline Audit and Constrained Evaluation

Industries are becoming increasingly connected and are more vulnerable to cyberattacks due to the widened attack surface. Industrial Control Systems (ICS) are among the most critical sectors that malicious actors can target, as such attacks can cause significant operational disruption and physical damage. It is imperative to detect such attacks as early as possible. This paper evaluates constraint-conditioned optimistic performance estimates for traditional ML models in ICS intrusion detection (i.e., estimates obtained under contiguous, non-shuffled temporal evaluation without test-set alteration, but with pre-split feature engineering that may introduce temporal leakage, due to dataset constraints). Our findings are threefold. First, we quantify how iterative feature engineering affects tree-based ensemble performance and examine how pipeline decisions (split strategy, sampling scope, and cleaning policy) can inflate or reduce reported IDS results under constraint-bound evaluation. Second, we compare intrinsic class-imbalance handling across ensemble models. Third, under our current pipeline constraints (including pre-split feature engineering), CatBoost achieves the best performance on Water Storage Tank (accuracy: 0.9831, class-1 F1: 0.9682), while Light- GBM achieves the best performance on Gas Pipeline (accuracy: 0.9618, class-1 F1: 0.9086).

97 MATHEMATICS AND COMPUTING↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

L-Basin Microbial Monitoring Program - Evaluation of 20 Years of Monitoring

The SRNL L-Basin corrosion surveillance and microbial monitoring programs provide early detection and characterization of corrosion attack to the fuel and storage system materials resulting from prolonged exposure to the L-Basin water environment and of changes to and impact of the diverse microbial population, respectively. The early detection of corrosion allows for adjustment of the water quality, engineering management, and fuel storage configurations to mitigate excessive corrosion attack. While microbial influenced corrosion in L-Basin has not been detected, tracking and understanding the effect of microbial populations on the stored fuel and basin water will aid in identifying remedial measures to mitigate any detrimental impact. This report reviews the microbial monitoring activities since initial characterizations in the mid-1990s.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Electrical Fault Detection, Power Quality, Distributed Energy Resource Use Cases, and Cyber Event Applications with the Cyber Grid Guard System Using Distributed Ledger Technology

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation and are associated with distributed energy resources (DERs). The integrity and confidentiality of data from IEDs is crucial, and distributed ledger technology (DLT) could improve the resilience of microgrids by helping to make these data more secure. The most popular applications using blockchain technology for electrical utilities is in the field is based on energy trading. However, the dynamism of the penetration of customer owned DERs and the deployment of sensors with IEDs have led to the identification of new applications using DLT that are focused on other areas, such as monitoring, operation and management of the grid and its assets. In addition, the majority of studies on electrical grid applications with blockchain were validated with software simulations. Although general monitoring of power systems for using DLT could be evaluated in operational electric grids, other DLT research applications such as defense against cyber-attacks and/or electrical fault detection are not likely to be performed in a real infrastructure because of possible risks to the network/equipment security. This report summarizes the application of power system applications using distributed ledger technology (DLT), providing a secure DLT framework for collecting data from IEDs like power meters and protective relays inside and outside of an electrical substation and/or between two different electrical utilities. In this study, the use case scenarios were created and assessed for different power system application by using DLT. The electrical fault detection for faulted phases (1), power quality monitoring of phase voltage magnitudes, frequency levels and load power factor (2), DERs use case monitoring (3), and cyber-event applications (4) were performed in a test bed with a Cyber-Grid Guard (CGG) system using DLT. It had a real-time simulator with power meters and protective relays in-the-loop. The first section of this report presents a literature review of power system applications using blockchain at research level. The second section shows the theory and equations used on this report. The third section shows the description of the test bed, equipment, architecture, and electrical grid diagrams. The fourth section shows the experimental models and use case scenarios that were performed for the electrical fault detection, power quality, DERs use case, and cyber event applications with the CGG system using DLT. The fifth section shows the results collected from the tests based on comparing the time stamped events of the analog signals from the IEDs, DLT computer and real time simulator. The sixth section performed the discussion of the results for the use case scenarios. Finally, section seven presents the conclusions for this report were presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Community detection robustness of graph neural networks

Graph neural networks (GNNs) are increasingly widely used for community detection in attributed networks. They combine structural topology with node attributes through message passing and pooling. However, their robustness or lack thereof with respect to different perturbations and targeted attacks in conjunction with community detection tasks is not well understood. To shed light on latent mechanisms behind GNN sensitivity on community detection tasks, we conduct a systematic computational evaluation of six widely adopted GNN architectures graph convolutional network, graph attention network, graph sample and aggregate (GraphSAGE), differentiable pooling (DiffPool), minimum cut pooling (MinCUT), and deep modularity networks (DMoN). The analysis covers three perturbation categories: node attribute manipulations, edge topology distortions, and adversarial attacks. We use element-centric similarity as the evaluation metric on synthetic benchmarks and real-world citation networks. Our findings indicate that supervised GNNs tend to achieve higher baseline accuracy, while unsupervised methods, particularly DMoN, maintain stronger resilience under targeted and adversarial perturbations. Furthermore, robustness appears to be strongly influenced by community strength, with well-defined communities reducing performance loss. Across all models, node attribute perturbations associated with targeted edge deletions and shifts in attribute distributions tend to cause the largest degradation in community recovery. These findings highlight important trade-offs between accuracy and robustness in GNN-based community detection and offer insights into selecting architectures resilient to noise and adversarial attacks.

Goel, Jaidev [Virginia Polytechnic Inst. and State↗

Safe and Robust Binary Classification and Fault Detection Using Reinforcement Learning

In this paper, we propose a learning-based method utilizing the Soft Actor-Critic (SAC) algorithm to train a binary Support Vector Machine (SVM) classifier. This classifier is designed to identify valid input spaces in high-dimensional, highly constrained systems while minimizing the total runtime of offline simulations. The simulations adapt their runtime based on the likelihood that a given training input will be informative to the classifier. Furthermore, we introduce a method for using the trained SAC model to predict whether a desired system input is likely to violate constraints, along with a technique to adjust the input as necessary. Additionally, we explore the potential of this model to detect faults or adversarial attacks within the system. The effectiveness of our approach is demonstrated through various simulations of challenging classification problems and a constrained quadrotor model.

Netter, Josh [Georgia Institute of Technology, Atl↗

Deception-Based Cyber Attacks on Hierarchical Control Systems using Domain-Aware Koopman Learning

Industrial control systems are subject to cyber attacks that produce physical consequences. These attacks can be both hard to detect and protracted. Here, we focus on deception-based sensor bias attacks made against a hierarchical control system where the attacker attempts to be stealthy. We develop a a data-driven, optimization-based attacker model and use the Koopman operator to represent the system dynamics in a domain-aware and computationally efficient manner. Using this model, we compute several different attacks against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. Finally, we discuss some computational considerations and identify avenues for future research.

koopman operator, Cyber-Physical Security, machine↗