Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Resilient Hierarchical Networked Control Systems: Secure Controls for Critical Locations and at Edge

Integration of information and communication technology (ICT) offers new opportunities in improving the management and operation of critical infrastructures such as power systems as it allows connection of different sensors and control components via a communication network, leading to the so-called networked control systems (NCS). However, the use of open and pervasive ICT such as the Internet or wireless communication technologies comes at a price of making NCS vulnerable to cyber intrusions/attacks which may cause physical damage. Here, this chapter presents control algorithms to ensure resilient and safe operation of NCS under unknown cyberattacks. Specifically, a variant of dynamic watermarking strategies is presented by embedding encoding/decoding components of chaotic signals into the NCS for secure control for critical locations where the measurement/control signals are transmitted to/from the control center via a communication network. In addition, resilient cooperative control algorithms are discussed to ensure safe operation at edge of the NCS which consists of a large number of distributed controllable devices. Several numerical examples are provided to illustrate the proposed control strategies.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Systems and methods for control system security

A resilient security agent determines a cyber and/or physical health of a control system by, inter alia, communicating cyber-physical key data through cyber-physical control paths of the system, and determining error introduced by the communication. The resilient security agent may be further configured to verify the integrity of acquired cyber-physical state information. The cyber health of the control system may be evaluated by comparing the acquired cyber state information to one or more cyber state profiles. The physical health of the control system may be evaluated by comparing the acquired physical state information to one or more physical state profiles.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for control system security

A component security device may be disposed at an interface between a component and a cyber-physical system. The disclosed component security device may be physically and/or electrically coupled between the component and infrastructure of the cyber-physical system, such as a backplane, bus, and/or the like. The component security device may be configured to monitor the component, and selectively isolate the component from the cyber-physical system. Since the component security device is interposed at the interface of the component, the component security device may be capable of isolating the component regardless of whether the component has been compromised (e.g., regardless of whether the component is capable of complying with system commands).

Rieger, Craig G.↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Towards Provable Security in Industrial Control Systems Via Dynamic Protocol Attestation

Industrial control systems (ICSs) increasingly rely on digital technologies vulnerable to cyber attacks. Cyber attackers can infiltrate ICSs and execute malicious actions. Individually, each action seems innocuous. But taken together, they cause the system to enter an unsafe state. These attacks have resulted in dramatic consequences such as physical damage, economic loss, and environmental catastrophes. This paper introduces a methodology that restricts actions using protocols. These protocols only allow safe actions to execute. Protocols are written in a domain specific language we have embedded in an interactive theorem prover (ITP). The ITP enables formal, machine-checked proofs to ensure protocols maintain safety properties. We use dynamic attestation to ensure ICSs conform to their protocol even if an adversary compromises a component. Since protocol conformance prevents unsafe actions, the previously mentioned cyber attacks become impossible. We demonstrate the effectiveness of our methodology using an example from the Fischertechnik Industry 4.0 platform. We measure dynamic attestation's impact on latency and throughput. Our approach is a starting point for studying how to combine formal methods and protocol design to thwart attacks intended to cripple ICSs.

97 MATHEMATICS AND COMPUTING↗

High-Reliability Systems and the Control of National Security Data and Information

High-reliability systems are characterized by catastrophic implications in the event of failure. These implications can include substantive damage to the environment, social order, and loss of life. Examples of high-reliability systems include nuclear submarines, nuclear reactors, the electric grid, and nuclear weapons. Due to the catastrophic implications of failure, there are heightened awareness and control mechanisms surrounding related data and information. However, defining the difference between data and information is often ambiguous across scholarly disciplines and in United States policy and legislation. For high-reliability systems, the implications of ambiguity between data and information may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and how to control them. Control is necessary to ensure that data and information are not unintentionally released to foreign governments, the public, or those without need-to-know. A primary concern in the practice of security is the control of data to avoid the unintended conversion to information. Intra-institutionally, this control is highly complex given the amalgam of legacy data systems and the numerous and constantly evolving nature of modern data systems that were not necessarily designed to be integrated. The complexity of this concern is augmented when institutions are part of interinstitutional collaborations or networks of public-private partnerships that share data and information. Additionally, institutions that share data as a function of policy and legislative action— particularly formally integrated data and information system infrastructures—may be at higher security risk. This paper will present an intra-institutional paradigm that utilizes and integrates concepts from numerous disciplines to frame a critical and underspecified practical issue in security—controlling for the unintended conversion of data to information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

High-Reliability Systems and the Control of National Security Data and Information

High-reliability systems are characterized by catastrophic implications in the event of failure. These implications can include substantive damage to the environment, social order, and loss of life. Examples of high-reliability systems include nuclear submarines, nuclear reactors, the electric grid, and nuclear weapons. Due to the catastrophic implications of failure, there are heightened awareness and control mechanisms surrounding related data and information. However, defining the difference between data and information is often ambiguous across scholarly disciplines and in United States policy and legislation. For high-reliability systems, the implications of ambiguity between data and information may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and how to control them. Control is necessary to ensure that data and information are not unintentionally released to foreign governments, the public, or those without need-to-know. A primary concern in the practice of security is the control of data to avoid the unintended conversion to information. Intra-institutionally, this control is highly complex given the amalgam of legacy data systems and the numerous and constantly evolving nature of modern data systems that were not necessarily designed to be integrated. The complexity of this concern is augmented when institutions are part of inter-institutional collaborations or networks of public-private partnerships that share data and information. Additionally, institutions that share data as a function of policy and legislative action—particularly formally integrated data and information system infrastructures—may be at higher security risk. This paper will present an intra-institutional paradigm that utilizes and integrates concepts from numerous disciplines to frame a critical and underspecified practical issue in security—controlling for the unintended conversion of data to information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber Security Analysis for Nuclear Reactor Control Systems (Final Technical Report)

This project investigated the cyber-security impacts of moving from an all analog, point-to-point, instrumentation and control (I&C) system to a digital I&C system based on Modbus and a shared communication medium. A formalism called a hybrid attack graph was expanded to support the nuclear research reactor system. The hybrid attack graph allows one to check a system for vulnerabilities, in this case cyber-security vulnerabilities, and to document the attack vectors (scenarios) causing those vulnerabilities. In parallel, a simulation of the system was developed to model both the physical reactor parameters and operations, as well as the network interconnects and communications. This simulation platform was modeled on the nuclear research reactor located at Washington State University. The simulation platform provided a sandbox to evaluate and quantify the impact of identified and proposed vulnerabilities in the system and to determine the effectiveness of countermeasures at stopping these attacks. The simulation and hybrid attack graph tools were integrated to provide a streamlined process of generating attack scenarios, playing those scenarios out in the simulation, and then analyzing the results to correlate system state to states in the hybrid attack graph. This process was used to (1) quantify the impact of attack scenarios and (2) to determine if the system moved through the hybrid attack graph as anticipated. The hybrid attack graph tool was extended and customized to produce a tool to automatically identify critical assets (CAs) and critical digital assets (CDAs) as defined by NRC Regulatory Guide 5.71. This tool was verified using the nuclear research reactor at Washington State University. Finally, a series of educational modules covering the findings of the different aspects of this research have been created.

97 MATHEMATICS AND COMPUTING↗

Opdefender Network Monitoring And Control System

OpDefender is a new system designed to enhance the cyber security of control system networks. It accomplishes this by inspecting each network packet using a novel, patent-pending method that extends software defined networking into the application/ICS protocol layer. OpDefender consists of two key components: 1. Smart, “ICS-aware” network switches that analyze and filter network traffic in real time. 2. A network management human machine interface (HMI) that allows an operator to monitor and control network traffic in real time. The “ICS-aware” switches can serve as a drop-in replacement for typical network switches, or they can be used in conjunction with existing network switches. OpDefender is configured and controlled in real time via a custom-built, web-based HMI designed with the operator in mind.

Johnson, BriamE.↗

Device Classification for Industrial Control Systems Using Predicted Traffic Features

To achieve a secure interconnected Industrial Control System (ICS) architecture, security practitioners depend on accurate identification of network host behavior. However, accurate machine learning based host identification methods depends on the availability of significant quantities of network traffic data, which can be difficult to obtain due to system constraints such as network security, data confidentiality, and physical location. In this work, we propose a network traffic feature prediction method based on a generative model, which achieves high host identification accuracy. Furthermore, we develop a joint training algorithm to improve host identification performance compared to separate training of the generative model and the classifier responsible for host identification.

97 MATHEMATICS AND COMPUTING↗

Neural Lyapunov Control for Power System Transient Stability: A Deep Learning-Based Approach

We report that power system control and transient stability analysis play essential roles in secure system operation. Control of power systems typically involves highly nonlinear and complex dynamics. Most of the existing works address such problems with additional assumptions in system dynamics, leading to a requirement for a complete and general solution. This paper, therefore, proposes a novel control framework for various power system control and stability problems leveraging a learning-based approach. The proposed framework includes a two-module structure that iteratively and jointly learns the candidate Lyapunov function and control law via deep neural networks in a learning module. Meanwhile, it guides the learning procedure towards valid results satisfying Lyapunov conditions in a falsification module. The introduced termination criteria ensure provable system stability. This control framework is verified through several studies handling different types of power system control problems. The results show that the proposed framework is generalizable and can simplify the control design for complex power systems with the stability guarantee and enlarged region of attraction.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Technologies for providing secure emergency power control of high voltage direct current transmission system

Technologies for providing secure emergency power control of a high voltage direct current transmission (HVDC) system include a controller. The controller includes circuitry configured to receive status data indicative of a present physical status of a power system. The circuitry is also configured to obtain an emergency power control command triggered by a remote source. The emergency power control command is to be executed by an HVDC transmission system of the power system. Further, the circuitry is configured to determine, as a function of the status data, whether the emergency power control command is consistent with the present physical status of the power system and block, in response to a determination that the emergency power control command is not consistent with the present physical status of the power system, execution of the emergency power control command by the HVDC transmission system.

Pan, Jiuping↗

Intrinsic use control for system and use controlled component security

An Initialization Unit (IU) initiates an initial secure connection with an Intrinsic Use Control (IUC) Chip based on very large random numbers (VLRNs). The IUC Chip in turn initiates a secondary secure connection between it and one or more Use Controlled Components (UCCs). Polling by the IU allows confirmation of an ongoing secure connection, and also allows the IUC Chip to confirm the secondary secure connection to the UCCs. Removal or improper polling response from one of the UCCs results in a response from the IUC Chip that may include notification of tampering, or temporary or permanent discontinued operation of the offending UCC. Permanent discontinued operation may include destruction of the offending UCC, and cascaded discontinued operation of all other UCCs secured by the IUC Chip. A UCC may in turn be another nested layer of IUC Chips, controlling a corresponding layer of UCCs, ad infinitum.

Hart, Mark Miles↗

Remote operation of the DIII-D National Fusion Facility

Abstract Full remote scientific operation of the DIII-D National Fusion Facility is now possible through significant advances in the computer science hardware and software infrastructure made over the last decade. Capabilities around information visualization, data movement, and communication have all been enhanced. The level of capability deployed to remotely operate DIII-D required an infrastructure advancement over what had previously been achieved in the fusion community. The large quantity of real-time data that is automatically displayed on DIII-D’s control room screens can now be visualized by remote participants via web-based applications. New audio/video solutions using the VoIP and instant messaging application Discord have been implemented to mimic the dynamic and ad-hoc scientific conversations that are critical in successfully operating an experimental campaign. Discord’s ability for a user to rapidly move between audio channels, text with images, and share screens is a significant enhancement over traditional videoconferencing tools. In addition, multiple combinations of broadcast audio are made available via a web-based application to allow remote participants to simultaneously listen to general announcements/sounds while conducting their own specific conversations. Secure methodologies have been put into place to allow remote control of hardware including DIII-D’s plasma control system application. Secure methods also included the ability of the on-site team to closely coordinate their work with remote team members which has been enhanced through extensions to the wireless network and the use of tablet computers for audio/video/screen sharing. However, no amount of software can fully replace the need for ‘hands on hardware.’ This infrastructure was severely stress tested during the COVID-19 pandemic where occupancy of the DIII-D control room was restricted. Operational efficiency during the pandemic, measured in discharges per hour, remained high (3.8 ± 0.8) compared to values obtained pre-pandemic (3.7 ± 0.8).

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Time-frequency based cyber security defense of wide-area control system for fast frequency reserve

Global power systems are transiting from conventional fossil fuel energy to renewable energies due to their environmental benefits. The increasing penetration of renewable energies presents challenges for power system operation. The efficiency and sufficiency of responsive reserves have become increasingly important for power systems with a high proportion of renewable energies. The Fast Frequency Reserve (FFR), especially the Wide-area Monitoring System (WAMS)-based FFR, is a promising and effective solution to secure and enhance the stability of power systems. However, cyber security has become a new challenge for the WAMS-based FFR system. Cyber attacks on the FFR control system may threaten the safety of power system operation due to the rapid power controllability requirement of FFR. Therefore, to address this problem, a time-frequency based cyber security defense framework is proposed to detect the cyber spoofing of synchrophasor data in WAMS-based FFR control systems. This paper first introduces the Continuous Wavelet Transforms (CWTs) to decompose spoofing signals. Then, the Dual-frequency Scale Convolutional Neural Networks (DSCNN) is proposed to identify the time-frequency domains matrix from two frequency scales. Integrating CWTs and DSCNN, an identification framework called CWTs-DSCNN is further proposed to detect the spoofing attacks in the WAMS-based FFR system. Multiple experiments using the actual data from FNET/GridEye are performed to verify the effectiveness of the framework in securing WAMS-based FFR systems.

25 ENERGY STORAGE↗