Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems

This paper demonstrates a novel randomization-based approach for verifying power system control signals with application to detecting cyberattacks. We consider fully connected hierarchical systems containing multiple local agents and a global "trust" agent. The global agent uses a time-varying randomized assignment scheme to identify corrupt network links based on principles of zero trust and majority rule. To evaluate the performance of this detection approach, we implement our algorithm in MATLAB and run it against nearly 43 million unique attack scenarios spanning a range of system sizes. For each scenario, the algorithm determines whether the identified corruptions satisfy a set of validity constraints reflecting network topology and uses that result to say whether the recovered state value for one or more local agents is malicious. We compare the algorithm's determination to the true state of the system to assess performance and find that classification accuracy converges to 100% as system size increases, suggesting that the validity constraints become more difficult to satisfy for larger systems. We further explore the scenarios that evade detection to understand practical implications for employing this detection approach.

cybersecurity↗

Flexible Machine Learning-Based Cyberattack Detection Using Spatiotemporal Patterns for Distribution Systems

This letter develops a flexible machine learning detection method for cyberattacks in distribution systems considering spatiotemporal patterns. Spatiotemporal patterns are recognized by the graph Laplacian based on system-wide measurements. A flexible Bayes classifier (BC) is used to train spatiotemporal patterns which could be violated when cyberattacks occur. Cyberattacks are detected by using flexible BCs online. The effectiveness of the developed method is demonstrated through standard IEEE 13- and 123-node test feeders.

97 MATHEMATICS AND COMPUTING↗

Cyberattack Detection and Mitigation on Central Volt‐VAr Using Circuit Law and Machine Learning

ABSTRACT In a distribution grid, voltage is maintained within a nominal range through a Volt‐VAr function that controls capacitor banks, reactive power of distributed energy resources (DER), and on‐load tap changers (OLTC). Availability of communications helps with the implementation of central Volt‐VAr control; however, it also opens the system to cyberattacks, causing voltage disturbances. Previous work has shown the adverse impacts of false data injection (FDI) on the central Volt‐VAr control; however, very few works have studied methods to detect and mitigate FDI on Volt‐VAr control. This paper addresses gaps in the detection and mitigation of FDI on the measurement packets of a central Volt‐VAr control. This work uses a two‐stage algorithm for cyberattack detection since the accuracy of a single‐stage machine learning (ML)–based detection method decreases while dealing with unseen data. The first stage is based on the verification of measurements against circuit laws, and the second stage utilizes a tree search algorithm and an ML method to detect the falsified data. This paper compares long short‐term memory (LSTM) and bidirectional LSTM (BiLSTM) as the employed ML algorithms. Finally, the mitigation algorithm replaces the falsified data with the estimated output of the ML algorithm. The effectiveness of the proposed method is tested for several cases using the IEEE 13‐bus test system in PSCAD software.

Beikbabaei, Milad [Bradley Department of Electrica↗

Data-driven Cyberattack Detection for Photovoltaic (PV) Systems through Analyzing Micro-PMU Data

With increasing exposure to software-based sensing and control, Photovoltaic (PV) systems are facing higher risks of cyber attacks. Here, to ensure the system stability and minimize potential economic losses, it is imperative to monitor operating states and detect attacks at the early stage. To meet this demand, Micro-Phasor Measurement Units (μPMU) are increasingly popular in monitoring distribution networks. However, due to the relatively low sampling rate, μPMU has not yet been used to detect and classify cyber-attacks in power electronics enabled smart grid. To our knowledge, this is one of the first attempts to use μPMU to detect cyber attacks that degrade the performance of power electronics systems. We propose to apply data-driven methods on micro-PMU data to implement attack detection. We have evaluated data-driven methods, including decision tree (DT), K-nearest neighbor (KNN), support vector machine (SVM), artificial neural network (ANN), long short-term memory (LSTM) and convolutional neural network (CNN). The proposed CNN model achieves the required performances with the highest 99.23% accuracy and 0.9963 F 1 score.

14 SOLAR ENERGY↗

Forced Power Systems Oscillations Due to Cyberattacks: Threats, Detection and Partial Mitigation

Forced oscillations in power systems can be caused by misconfigured controllers at generator stations. They can also be caused by cyberattacks against the exciters or governors. This paper explores the effects of forced oscillations from cyberattacks on generator excitation and governor systems and the effectiveness of a novel control system for a static var compensator in mitigating those oscillations to enhance transmission system resilience. A brief overview of oscillations, especially forced oscillations, within power systems is presented, along with an overview of cyberattacks on power systems. This paper also examines and implements FACTS devices to partially mitigate the forced oscillations created by cyberattacks by reducing the magnitude of the oscillations caused by the attack. The proposed approach is more effective against attacks targeting exciters.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CEDS Differential Privacy (CEDSDP) v0.1

A Python package that provides differentially private queries optimized for energy systems' data. It may be used to publish queries such as clustering, averaging, metadata inference, etc. that are useful for a variety of grid-related analytics, including cyberattack detection.

Peisert, Sean↗

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because it can aid in both cybersecurity analysis and the evaluation of other cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

cyber-physical systems↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because they can aid in both cybersecurity analysis and the evaluation of cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

alfalfa↗

SHARP-Net: Platform for Self-Healing and Attack Resilient PMU Networks

Synchrophasor technology plays a pivotal role in developing the next generation of wide-area monitoring, protection, and control in the smart grid environment. As technology and communications infrastructures evolve, however, so do the attack surfaces in the synchrophasor network that can be exploited by advanced persistent threat (APT) actors to affect power system stability and reliability. In this paper, we propose a novel platform for developing a self-healing and attack-resilient PMU network (SHARP-Net) by instituting a state-of-the-art intrusion detection system (IDS) with an intrusion mitigation system (IMS) and an alert management system (AMS). In particular, the proposed platform detects anomalies during cyberattacks on phasor data concentrators (PDCs) based on the rules defined in the IDS, then the generated alerts are published to the IMS through the AMS. The proposed IMS proceeds to take automated corrective responses to mitigate cyberattacks by reconfiguring the synchrophasor network to isolate the compromised PDCs, and it orchestrates new PDCs to prevent the future propagation of attacks. Further, the IMS restores the system's observability by reconnecting the new PDCs to make the grid attack-resilient. In this work, the SHARP-Net platform is developed by using Python-based libraries, minimega's software-defined network, and virtual machine orchestration. We implement and validate the proposed SHARP-Net architecture by testing a PMU network in the smart grid environment. SHARP-Net showed promising performance in detecting cyberattacks and mitigating them through the network reconfiguration.

computer architecture↗

Time Sequence Machine Learning-Based Data Intrusion Detection for Smart Voltage Source Converter-Enabled Power Grid

Smart inverters of distributed energy resources can enable cloud computing, condition monitoring, result visualization, remote control, and peer-to-peer energy trading in advanced power systems. However, the advent of data injection attacks in the communication architecture can alter measurement characteristics of power grids and have devastating consequences. In this article, we propose a time sequence machine learning-based anomaly detection methodology for detecting cyber intrusion into control signal setpoints and dc voltage signal measurement bias of the voltage source converter (VSC) in wind generators. We first investigated the effects of four types of denial of service, tampering signal, and stealthy-type data intrusion attacks on smart VSCs and overall wind farms. We then proposed a novel time sequence machine learning-based intrusion detection framework that can be implemented to detect different cyberattacks in the VSCs. The performance of the proposed framework has been compared with that of autoencoder and clustering-based intrusion detection framework. The proposed framework was validated by using the IEEE 39 bus power system in the presence of four wind farms in different locations. Using several metrics for intrusion detection performance, we validated the effectiveness of the proposed framework.

42 ENGINEERING↗

Detecting False Data Injection Attacks in Smart Grids: A Semi-Supervised Deep Learning Approach

The dependence on advanced information and communication technology increases the vulnerability in smart grids under cyber-attacks. Recent research on unobservable false data injection attacks (FDIAs) reveals the high risk of secure system operation, since these attacks can bypass current bad data detection mechanisms. To mitigate this risk, this paper proposes a data-driven learning-based algorithm for detecting unobservable FDIAs in distribution systems. We use autoencoders for efficient dimension reduction and feature extraction of measurement datasets. Further, we integrate the autoencoders into an advanced generative adversarial network (GAN) framework, which successfully detects anomalies under FDIAs by capturing the unconformity between abnormal and secure measurements. Also, considering that the datasets collected from practical power systems are partially labeled due to expensive labeling costs and missing labels, the proposed method only requires a few labeled measurement data in addition to unlabeled data for training. Numerical simulations in three-phase unbalanced IEEE 13-bus and 123-bus distribution systems validate the detection accuracy and efficiency of this method.

97 MATHEMATICS AND COMPUTING↗