Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Cyber State Awareness For Resilience

Characterization of cyber-physical attacks requires a holistic understanding of cyber and physical behavior in a system. Machine Learning Anomaly Detection provides a compelling solution for continuously identifying suspicious behavior within these complex systems. In our software, we present an approach for holistic characterization of cyber-physical systems based on cyber and physical anomaly correlation. The approach consists of three main components: 1) an architecture for real-time data acquisition, management, and analysis of both cyber and physical data; 2) cyber and physical data driven anomaly detection systems (ADSs), 3) a metric that combines cyber and physical ADSs to provide a holistic characterization of the system..

Rieger, CraigG.↗

Cyber Physical Protection for Natural Gas Compression

The secure transport of natural gas through North American pipelines is vital for both home and industrial purposes. GE in collaboration with Baker Hughes and Idaho National Laboratory, completed a US Department of Energy grant program to develop a new cyber-physical protection system that monitors the large compressor stations used to boost pressure and maintain proper gas flow. Algorithms were developed to detect the presence of a cyber-attack that impacts the compressor station physical processes, locate the critical functions being manipulated, and potentially neutralize the attack allowing continued operations. The technology was successfully demonstrated at an operating compressor facility located in New York state.

03 NATURAL GAS↗

Machine Learning Based Resilience Testing of an Address Randomization Cyber Defense

Moving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. Here, in this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Data-based and secure switched cyber–physical systems

In this work, we develop a completely model-free moving target defense framework for the detection and mitigation of sensor and/or actuator attacks in cyber–physical systems with dynamics that evolve in discrete-time. We incorporate an intrusion detection mechanism based on an approximate dynamic programming technique that learns the policies for optimal regulation and optimal tracking while simultaneously defending against actuator and sensor attacks in a model-free fashion. Switching rules are leveraged to force proactive and reactive defense mechanisms as well as, guarantee the stability of the equilibrium point. Finally, as a case study, we apply the proposed moving target defense framework to a DC–DC converter that is used in electric vehicles.

42 ENGINEERING↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

Cyber-physical security framework for Photovoltaic Farms

With the evolution of PV converters, a growing number of vulnerabilities in PV farms are exposing to cyber threats. To mitigate the influence of cyber-attack on PV farms, it is necessary to study attacks' impact and propose detection methods. To meet this requirement, a cyber-physical security framework is proposed for PV farms. Data integrity attacks (DIAs) are studied on different control loops. As μPMU is gaining in popularity, a lower sampling rate of μPMU data is applied to develop a detection algorithm. We have evaluated two data-driven methods, which are support vector machine (SVM) and long short-term memory (LSTM). Lastly, the data-driven methods verify the feasibility of μPMU data in attack detection.

Attack Impact Analysis↗

Cybersecurity Governance

Cybersecurity governance helps an organization detect, prevent, and respond to cyber incidents by establishing cybersecurity policies and procedures for use across the enterprise. As modern energy systems become increasingly reliant on smaller and decentralized generation sources-equipped with complex, data-driven communications-governance will be of growing importance for the continued protection of the electric grid. This presentation sheds light on the important aspects of cybersecurity governance, best practices to ensure a culture of cybersecurity, and approaches to frequent monitoring and assessment of an organization's cybersecurity posture.

business requirements↗

Cybersecurity Incident Response Guide for Wind

As wind energy systems become increasingly digitized and interconnected, they face a growing array of cyber threats that can disrupt operations, compromise safety, and trigger cascading impacts across the energy ecosystem. The Wind Incident Response Guide provides a structured, wind-specific framework for preparing for, detecting, responding to, and recovering from cyber incidents. Drawing on lessons from field demonstrations, cyber-physical testbeds, and stakeholder engagement across the wind sector, this guide integrates technical, operational, and regulatory considerations to support asset owners, operators, and responders. It outlines key roles and responsibilities, maps incident response phases to wind-specific scenarios, and highlights applicable laws, regulations, standards, and best practices. By tailoring general cybersecurity principles to the unique architectures and operational constraints of wind systems—including remote access, legacy components, and environmental interfaces—this guide aims to enhance resilience, reduce response time, and support coordinated action across public and private stakeholders. It is intended as a practical resource for utilities, developers, regulators, and emergency managers working to secure the future of wind energy.

17 - WIND ENERGY↗

DER Cybersecurity Detection and Response Suite

SAND2024-08475O The Distributed Energy Resource (DER) Cybersecurity Detection and Response Suite is a solution for distributed energy resource (DER) systems. The DER Security Orchestration, Automation, and Response (SOAR) solution that uses alerts from signature- and behavior-based Intrusion Detection Systems are intended to be deployed as bump-in-the-wire (BITW) devices in front of DER equipment. The fielded application would use multiple intrusion detection systems that report data to SOAR to respond to cyberattacks. The suite consists of two software components: • The proactive intrusion detection and mitigation system (PIDMS) secures grid-edge photovoltaic smart inverters and other equipment in distributed energy resource systems. It is a distributed BITW solution; cyber and physical data are automatically processed using network inspection tools and custom machine learning algorithms to detect abnormal events and correlate cyber-physical events. • The Security Orchestration, Automation, and Response for Distributed Energy Resources (SOAR4DER) application ingests data from several intrusion detection systems to quickly block attacks and revert DER systems to good states. Using a collection of intrusion detection system technologies on a BITW device, it incorporates physical and cyber data to detect abnormal and potential malicious behaviors. Multiple SOAR playbooks then use the intrusion detection system data streams to automatically defend the system. SOAR4DER system testing showed detection and response times under 30 seconds for all adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute-force logins, and machine-in-the-middle attacks. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Johnson, Jay↗

Attack detection and localization with adaptive thresholding

According to some embodiments, a system, method, and non-transitory computer readable medium are provided comprising a plurality of real-time monitoring nodes to receive streams of monitoring node signal values over time that represent a current operation of the cyber physical system; and a threat detection computer platform, coupled to the plurality of real-time monitoring nodes, to: receive the monitoring node signal values; compute an anomaly score; compare the anomaly score with an adaptive threshold; and detect that one of a particular monitoring node and a system is outside a decision boundary based on the comparison, and classify that particular monitoring node or system as anomalous. Numerous other aspects are provided.

Abbaszadeh, Masoud↗

A Hybrid Anomaly Detection Approach for Obfuscated Malware

With the rapid evolution of malicious software, cyber threats have become increasingly sophisticated, employing advanced obfuscation techniques to evade traditional detection methods. This study presents a hybrid anomaly detection approach applied to obfuscated malware. Even though there is a large body of research in this field, existing malware detection techniques have some drawbacks, such as requiring large amounts of data, trustworthiness (imprecise results) of algorithms, and advanced obfuscation. To overcome these challenges, there is a need to employ solid and efficient techniques for malware detection. This paper proposes a hybrid approach, combining an autoencoder with traditional machine-learning methods to create an efficient malware detection framework. We used the malware memory dataset (MalMemAnalysis-2022) to evaluate this framework. The results indicate that our proposed approach can detect obfuscated malware when a deep autoencoder used for feature learning is combined with logistic regression, and it is extremely fast with an Accuracy, Detection Rate (DR), Matthew Correlation Coefficient(MCC), and Statistical Parity Difference

malware detection, Hybrid Anomly Detection, Obfusc↗

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy↗

Detecting Electrical Anomalies via Overlapping Measurements

As cyber-attacks against critical infrastructure become more frequent, it is increasingly important to be able to rapidly identify and respond to these threats. Therefore, we are investigating using multiple independent systems with overlapping electrical measurements to more rapidly identify anomalies. While prior research has explored the benefits of fusing measurements, the possibility of overlapping measurements from an existing electrical system has not been investigated. To that end, we explore the potential benefits of combining overlapping measurements both to improve the speed/accuracy of anomaly detection and to provide additional validation of collected measurements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessment of the Electrical Substation-Grid Testbed with Inside/Outside Devices and Distributed Ledger Technology

The electrical substation-grid testbed was created to integrate the GOOSE and/or DNP (Distributed Network Protocol) messages with time synchronized sources and Distributed Ledger Technology (DLT). The objective was to study the impact of faults and cyber-events at an electrical substation with inside (protective relays) and outside (power meters) substation devices. The electrical substation-grid testbed was based on the design of a 34.5/ 12.47 kV electrical substation (sectionalized bus configuration) with two power transformers, connected to radial power lines and load feeders. The electrical substation-grid testbed was installed at 252 lab space (Advanced Power System Protection), Grid Research Integration and Deployment Center (GRID-C), Oak Ridge National Laboratory. This testbed was created for Task 5, DarkNet project. The electrical substation-grid testbed was created to simulate fault and/or cyber events that could potentially result in damage to the electrical infrastructure. In addition, tests were run that are usually not allowed to be performed in an operational electrical power grid, because these test scenarios could trip breakers and/or generate fault situations that could potentially damage equipment. The number of tests performed in the electrical substation-grid testbed were executed in a better way than in a real electrical substation and/or power grid, because multiple tests could be run in a short period of time, and complex permits, and safety/ schedule restrictions like in a real electrical substation environment were not needed. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that are used by electrical utilities, to have same conditions that we could observe in a real power grid or electrical substation. The electrical substation-grid testbed was based on using a real time simulator and expansion box with amplifiers that were wired to electrical substation-grid devices. This hardware-in-the-loop (HIL) was provided by protective relays, power meters, ethernet switches, remote terminal units, synchronized timing network clock, DLT devices, workstations, and servers. This report includes the design, installation, and assessment of the electrical substation-grid testbed that was similar to an operational electrical substation, integrating the power system protection, communication, and control systems. The results for the electrical substation-grid testbed were based on:• verifying the analog signals for protective relays and power meters, • observing the synchronized time source frame at devices, • authenticating the GOOSE (IEC 61850) and DNP messages from power meters and protective relays, and • verifying the trip conditions of protective relays at fault tests with the power system fault event detection, using DLT devices. For future work, the electrical substation-grid testbed with protective relays and power meters, using DLT and synchronized time source from DarkNet, will be used to study the impact of cyber-events at inside and outside substation devices. Advanced algorithms for detecting cyber-events produced by non-desired protective relay settings will be studied, to improve the detection and reliability of protection, control, and communication systems at power grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

ThunderSecure: deploying real-time intrusion detection for 100G research networks by leveraging stream-based features and one-class classification network

Nowadays, data generated by large-scale scientific experiments are on the scale of petabytes per month. These data are transferred through dedicated high-bandwidth networks (40/100G) across distributed sites for processing, storage, and analysis. Like general purpose networks, research networks experience intrusions. However, monitoring anomalies in such high-speed network traffics is challenging given current cyber-infrastructure. Moreover, traditional network intrusion detection systems (NIDS) are signature based. However, anomaly patterns are difficult to define and that rulesets are often not updated frequently enough to reflect the changes of attack behaviors. We present ThunderSecure, a high-throughput, unsupervised learning-based intrusions detection system for 100G research networks. ThunderSecure implements an efficient packet processing and detection pipeline using multi-cores and GPUs. It extracts statistical and temporal features from real-time network data streams and feeds them to a one-class anomaly detection network. A baseline of normal distribution will be created based on the training observation. Testing traffic deviated from the learned profile will be marked as anomalies. We trained ThunderSecure on hundreds of billions of science data packets mirrored from two 100G network connections at Fermi National Accelerator Laboratory. The detection performance was evaluated on traffic captured from the same research network days and weeks after the training with different types of attack flows injected. Results show that ThunderSecure can recognize science data traffic captured long after the training and made nearly certain detection on the segment of the streams where anomalous flows were injected.

100G research network↗

On the Limits of EM Based Detection of Control Logic Injection Attacks In Noisy Environments

The difficulty in applying traditional security mechanisms in Industrial Control System (ICS) environments makes a large portion of these mission-critical assets vulnerable to cyber attacks. Therefore, there is a dire need for the development of novel security mechanisms specifically designed to protect such critical systems. Recently a lot of attention has been given to mechanisms that exploit the EM emanations of devices for defense purposes. Such practices may lead to the development of robust external and non-intrusive anomaly detection systems. Nevertheless, the majority of current work in the area neglects to consider the implications of real-life environments, particularly environmental noise. In this work, we explore the limits of EM-based anomaly detection towards identifying injection attacks in control logic software in noisy environments. Our study conducted upon both synthetically generated and real signals identified that indeed environmental noise might significantly degrade the accuracy of the anomaly detection process. Experiments done upon synthetic data indicated that assuming that signals are captured with high sampling rates, even minor code injections can be detected with above-90% accuracy in noisy environments where SNR is up to -2dB. This is true even if naive detection methods are considered. Moreover, experiments done using a real-life testbed attest that even single-instruction injections can be detected with near-perfect accuracy in relatively clean environments. Finally, noise-elimination techniques can drastically improve the reliability of the detection mechanism even in noisy environments.

97 MATHEMATICS AND COMPUTING↗