Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Synchrophasors-based Master State Awareness Estimator for Cybersecurity in Power Grid: Testbed Implementation & Field Demonstration

The integration of distributed energy resources(DERs) and expansion of complex network in the distribution grid requires an advanced distributed state estimator to monitor the grid health at micro-level. The distribution state estimator will improve the situational awareness and resiliency of distributed power system. This paper proposes a synchrophasors-based master state awareness (MSA) estimator to enhance the cybersecurity in distribution grid by providing a real-time estimation of system operating states to control center operators. In this paper, the proposed MSA estimator utilizes only phasor measurements, bus magnitudes and angles, from phasor measurement units (PMUs),deployed in local substations, to estimate the system states and also detects data integrity attacks, such as load tripping attack that disconnects the load. To validate the proof of concept, we implement the proposed methodology in cyber-physical testbed environment at the Idaho National Laboratory (INL) Electric Grid Security Testbed. Further, to address the “valley of death” and support technology commercialization, field demonstration is also performed at the Critical Infrastructure Test Range Complex(CITRC) at the INL. Our experimental results reveal a promising performance in detecting load tripping attack and providing an accurate situational awareness through an alert visualization dashboard in real-time

42 ENGINEERING↗

Detecting Living-off-the-land Attacks Using K-means And Graph Convolutional Networks

The code ingests Zeek logs derived from network packet captures and goes through data preprocessing before it gets passed into a K-Means model that labels each device as either a client or server. Graph Convolutional Network (GCN) model is used to obtain the embeddings to represent the features in lower dimension. Last, K-means cluster analysis is used to cluster the embeddings for each class.

Quach, Anna [Idaho National Laboratory (INL), Idah↗

Ransomware Attack Modeling and Artificial Intelligence-Based Ransomware Detection for Digital Substations

Ransomware has become a serious threat to the current computing world, requiring immediate attention to prevent it. Ransomware attacks can also have disruptive impacts on operation of smart grids including digital substations. This paper provides a ransomware attack modeling method targeting disruptive operation of a digital substation and investigates an artificial intelligence (AI)-based ransomware detection approach. The proposed ransomware file detection model is designed by a convolutional neural network (CNN) using 2-D grayscale image files converted from binary files. Here, the experimental results show that the proposed method achieves 96.22% of ransomware detection accuracy.

artificial intelligence↗

Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A comprehensive guide to CAN IDS data and introduction of the ROAD dataset

Although ubiquitous in modern vehicles, Controller Area Networks (CANs) lack basic security properties and are easily exploitable. A rapidly growing field of CAN security research has emerged that seeks to detect intrusions or anomalies on CANs. Producing vehicular CAN data with a variety of intrusions is a difficult task for most researchers as it requires expensive assets and deep expertise. To illuminate this task, we introduce the first comprehensive guide to the existing open CAN intrusion detection system (IDS) datasets. We categorize attacks on CANs including fabrication (adding frames, e.g., flooding or targeting and ID), suspension (removing an ID’s frames), and masquerade attacks (spoofed frames sent in lieu of suspended ones). We provide a quality analysis of each dataset; an enumeration of each datasets’ attacks, benefits, and drawbacks; categorization as real vs. simulated CAN data and real vs. simulated attacks; whether the data is raw CAN data or signal-translated; number of vehicles/CANs; quantity in terms of time; and finally a suggested use case of each dataset. State-of-the-art public CAN IDS datasets are limited to real fabrication (simple message injection) attacks and simulated attacks often in synthetic data, lacking fidelity. In general, the physical effects of attacks on the vehicle are not verified in the available datasets. Only one dataset provides signal-translated data but is missing a corresponding “raw” binary version. This issue pigeon-holes CAN IDS research into testing on limited and often inappropriate data (usually with attacks that are too easily detectable to truly test the method). The scarcity of appropriate data has stymied comparability and reproducibility of results for researchers. As our primary contribution, we present the Real ORNL Automotive Dynamometer (ROAD) CAN IDS dataset, consisting of over 3.5 hours of one vehicle’s CAN data. ROAD contains ambient data recorded during a diverse set of activities, and attacks of increasing stealth with multiple variants and instances of real (i.e. non-simulated) fuzzing, fabrication, unique advanced attacks, and simulated masquerade attacks. To facilitate a benchmark for CAN IDS methods that require signal-translated inputs, we also provide the signal time series format for many of the CAN captures. Our contributions aim to facilitate appropriate benchmarking and needed comparability in the CAN IDS research field.

97 MATHEMATICS AND COMPUTING↗

Voltage Stability Constrained Moving Target Defense Against Net Load Redistribution Attacks

Moving target defense (MTD) using distributed flexible AC transmission system (D-FACTS) devices is a promising defense strategy to detect stealthy false data injection (FDI) attacks against the power system state estimation. However, all existing studies myopically perturb the reactance of D-FACTS lines without considering the system voltage stability. In this paper, we first illustrate voltage instability induced by MTDs in a three-bus system. To address this issue, we further propose a novel MTD framework that explicitly considers system voltage stability by using continuation power flow and voltage stability indices. We mathematically derive the sensitivity matrix of voltage stability index to line impedance, on which an optimization problem for maximizing voltage stability index is formulated. This framework is tested on the IEEE 14-bus and the IEEE 118-bus transmission systems, in which net load redistribution attacks are launched by sophisticated attackers. Here, the simulation results show the effectiveness of the proposed framework in circumventing the voltage instability while maintaining the detection effectiveness of MTD. We conduct case studies with and without the proposed framework under different MTD planning and operational methods. The impacts of the proposed two methods on attack detection effectiveness and system economic metrics are also revealed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Time-frequency based cyber security defense of wide-area control system for fast frequency reserve

Global power systems are transiting from conventional fossil fuel energy to renewable energies due to their environmental benefits. The increasing penetration of renewable energies presents challenges for power system operation. The efficiency and sufficiency of responsive reserves have become increasingly important for power systems with a high proportion of renewable energies. The Fast Frequency Reserve (FFR), especially the Wide-area Monitoring System (WAMS)-based FFR, is a promising and effective solution to secure and enhance the stability of power systems. However, cyber security has become a new challenge for the WAMS-based FFR system. Cyber attacks on the FFR control system may threaten the safety of power system operation due to the rapid power controllability requirement of FFR. Therefore, to address this problem, a time-frequency based cyber security defense framework is proposed to detect the cyber spoofing of synchrophasor data in WAMS-based FFR control systems. This paper first introduces the Continuous Wavelet Transforms (CWTs) to decompose spoofing signals. Then, the Dual-frequency Scale Convolutional Neural Networks (DSCNN) is proposed to identify the time-frequency domains matrix from two frequency scales. Integrating CWTs and DSCNN, an identification framework called CWTs-DSCNN is further proposed to detect the spoofing attacks in the WAMS-based FFR system. Multiple experiments using the actual data from FNET/GridEye are performed to verify the effectiveness of the framework in securing WAMS-based FFR systems.

25 ENERGY STORAGE↗

Review of internal cyber attacks in nuclear facilities and an artificial neural network model for implementing internal cyberforensics

Deployment of digital technologies within a modern shift in cyber defense systems is essential for protecting the energy production units. One of the important components of defense is cyberforensics: once an attack has been detected to locate its origin. In this paper, a review of well-known cyberattacks in nuclear facilities is provided, with the lessons learned leading to the development of a machine learning approach implementing identification of internal at- tacks in the facility's data networks. Our approach may be seen as one of the layers in a defense-in-depth strategy that identifies if the attack comes from inside, which may result in identifying faster the attacker's origin. The presented model exploits network packet examination to cast accurate predictions on detailing the origin of malicious network connections. The approach fuses multiple mathematical functions within an artificial neural network to provide a response in the form of 0/1, i. e., whether the attack is identified as internal or not. The utilization of a variety of test cases is developed to explore the relevance and validity of the predictive approach. The proposed implementation is examined with network data packet variance, and the results obtained exhibit a highly accurate detection rate.

Nuclear Science & Technology↗

Load Margin Constrained Moving Target Defense against False Data Injection Attacks

Cyber physical security of power systems with high penetration of renewable generation has attracted attention from researchers. One critical issue is that cyber-physical attacks, disguised as uncertain renewable generation, can target conventional power system state estimation (SE). Moving target defense (MTD) is a promising defense strategy to detect stealthy false data injection (FDI) attacks against SE. However, all existing studies myopically perturb the reactance of transmission lines equipped with distributed flexible AC transmission system (D-FACTS) devices without adequately considering the system voltage stability. Exacerbated by the renewable generation uncertainty, existing MTD may cause voltage instability when the power grid is under stress. To address this issue, we propose a novel MTD framework that explicitly considers system voltage stability by using continuation power flow. We utilize the sensitivity matrix of power injection to line impedance, on which an optimization problem for maximizing load margin is formulated. This framework is validated on the IEEE 14-bus system and the IEEE 118-bus system, in which net load redistribution attacks are launched by sophisticated attackers. Steady-state simulations and dynamic simulations on PSS/E show the effectiveness of the proposed framework in circumventing the voltage instability while maintaining the detection effectiveness of MTD. The impact of the proposed method on attack detection effectiveness is also revealed.

Zhang, Hang↗

Evaluating cyber-risk in synchrophasor systems

Technology related to evaluating cyber-risk for synchrophasor systems is disclosed. In one example of the disclosed technology, a method includes generating an event tree model of a timing-attack on a synchrophasor system architecture. The event tree model can be based on locations and types of timing-attacks, an attack likelihood, vulnerabilities and detectability along a scenario path, and consequences of the timing-attack. A cyber-risk score of the synchrophasor system architecture can be determined using the event tree model. The synchrophasor system architecture can be adapted in response to the cyber-risk score.

Pal, Seemita↗

Operational Technology Behavioral Analytics (OTBA) (Final Technical Report DE-FE0031640)

This final report provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company Services, Inc. at Alabama Power Company’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

20 FOSSIL-FUELED POWER PLANTS↗

Model-Based Diagnostics and Mitigation of Cyber Threats

The report summarizes key tasks performed to develop a toolkit for detecting cyber-attack events in instrumentation and control (I&C) systems of nuclear power plants. The toolkit connects the state-of-the-art GPWR Simulator with the RELAP5 code providing best-estimate nuclear steam supply system (NSSS) analyses, via the application programming interface (API), and allows users to introduce potential cyber-attack scenarios into power plant operational simulation. This summary for the project reflects topical reports submitted during the project as well as a journal paper published in 2022. The focus areas of the summary include: (1) modeling I&C systems for the AP1000 Generation III+ nuclear plant and GPWR simulator, (2) simulation and monitoring of plant response to cyber-attack events, (3) API structure for the toolkit interfacing the GPWR simulator and RELAP5 code, and (4) restructuring of the three-loop NSSS software of GPWR to model the two-loop AP1000 structure. Discussed in some details are (a) the attack tree analysis assessing the susceptibility of the AP1000 I&C system, resulting in reactor trips, in terms of the attack possibility and component sensitivity and (b) realistic estimation of the time to steam generator trip due to cyber-intrusions in the GPWR Simulator. Finally, sample demonstrations of the cyber-security tool kit, in the form of the GPWR-RELAP5 API, are summarized.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Resilience Through Data-Driven, Intelligent Designed Control: A Formal Methods Approach

The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.

97 MATHEMATICS AND COMPUTING↗

OPERATIONAL TECHNOLOGY BEHAVIORAL ANALYTICS (OTBA) – A DATA-CENTRIC APPROACH FOR REDUCING CYBERSECURITY RISK

This paper provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company at Alabama Power’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

Black, Clifton↗

CANShield: Signal-based Intrusion Detection for Controller Area Networks

Modern vehicles rely on complex cyber-physical systems made up of hundreds of electronic control units (ECUs) connected through controller area network (CAN) buses. However, the CAN bus attack surface is increasing due to advanced features in automobiles, making it prone to injection attacks. The ordinary injection attacks disrupt the typical timing properties of the CAN data stream, and the rule-based intrusion detection systems (IDS) can easily detect them. However, advanced attackers can inject false data to the signal level, maintaining the regular pattern/frequency of the CAN messages. Such attacks can bypass the rule-based IDS or any anomaly-based IDS built on binary payload data. To make the vehicles robust against such intelligent attacks, we propose CANShield, a signal-based intrusion detection framework for the CAN bus that consists of three modules. A data preprocessing module handles the high-dimensional CAN data stream at the signal level and make them suitable for any machine learning model. A data analyzer module consists of multiple deep autoencoder networks, each analyzing the time series data from a different perspective. Finally, an attack detection module uses an ensemble method to make the final decision. Evaluation results on a standard signal-based dataset show the effectiveness of the CANShield in detecting five advanced attacks.

Shahriar, Md Hasan↗