Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack modeling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Bayesian Attack Model (BAM)

The Bayesian Attack Model (BAM) is an analytical tool designed to enhance the comprehension of adversarial activity in OT environments. BAM leverages both expert cybersecurity insights and historical data to characterize the likelihood of adversarial behavior given anomalous observable events.

99 GENERAL AND MISCELLANEOUS↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Ransomware Attack Modeling and Artificial Intelligence-Based Ransomware Detection for Digital Substations

Ransomware has become a serious threat to the current computing world, requiring immediate attention to prevent it. Ransomware attacks can also have disruptive impacts on operation of smart grids including digital substations. This paper provides a ransomware attack modeling method targeting disruptive operation of a digital substation and investigates an artificial intelligence (AI)-based ransomware detection approach. The proposed ransomware file detection model is designed by a convolutional neural network (CNN) using 2-D grayscale image files converted from binary files. Here, the experimental results show that the proposed method achieves 96.22% of ransomware detection accuracy.

artificial intelligence↗

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

Subsonic wind tunnel investigation of a twin-engine attack airplane model having nonmetric powered nacelles

A 1/10-scale powered model of a twin-engine attack airplane was investigated in the Langley high-speed 7- by 10-foot tunnel. The study was made at several Mach numbers between 0.225 and 0.75 which correspond to Reynolds numbers, based on the mean aerodynamic chord, of 1.35 million and 3.34 million. Unheated compressed air was used for jet simulation in the nonmetric engine nacelles which were located ahead of and above the horizontal stabilizer.

Lockwood, V. E.↗

Interference effects of aft reaction-control yaw jets on the aerodynamic characteristics of a space shuttle orbiter model at supersonic speeds

A wind tunnel investigation of the interference effects of aft reaction control system yaw jet plumes on a 0.0125 scale Space Shuttle orbiter model was conducted at Mach numbers from 2.50 to 4.50. Test variables included model angle of attack, model angle of sideslip, jet to free stream mass flow ratio, and number and position of operating jets. The aft reaction control jet plume creates a blockage above and behind the wing on the side in which the jet exhausts and results in flow separation on the wing upper surface and fuselage side. Positive pitching moment and side force increments and negative yawing moment and rolling moment increments due to the flow separations are incurred for left side firing jets, primarily at angles of attack above 10 deg. The yawing moment interference increments are favorable and result in a small jet thrust amplification. As a result of this investigation, the aft reaction control system was certified for operation at supersonic Mach numbers prior to the first flight of the space transportation system (STS-1).

Covell, P. F.↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Acoustic measurements of the X-wing rotor

Noise measurements of a stoppable X-wing rotor system model, tested in the Ames 40- by 80-foot wind tunnel, are summarized. Performance, control system stability, and noise of the model were investigated at various forward speeds, tip speeds, collective blade angles, jet blowing velocities, and model attack angles. The model was tested in the rotating wing helicopter configuration, in the fixed wing configuration, and in wing configurations between the two. Noise data obtained in the helicopter configuration at the two highest tip speeds (Mach 0.44 and 0.47) and at wind tunnel speeds below 140 knots are reported. Test configuration and performance information are included. General acoustic measurements (dB, dBA, and PNdB) at six microphone locations are presented for all conditions under which the background noise was below the model noise. More specific measurements (1/3-octave and blade passage frequency harmonic levels) are presented for selected conditions. Graphs of dBA and 1/3-octave spectra, which show the noise trends as functions of operating condition, are included. The noise depends mainly on the jet blowing velocity. The noise levels were highest at moderate jet blowing velocities, less at the highest velocity, and lowest with no blowing at all.

Mosher, M.↗

Data-driven cyber-attack detection for photovoltaic systems: A transfer learning approach

With increasing exposure to software-based sensing and control, power systems are facing higher risks of cyber/physical attacks. Here, to ensure system stability and minimize the potential economic losses, it is imperative to monitor the operating states and detect those attacks at the early stage. In this paper, a transfer learning method is proposed to detect cyber-attacks in photovoltaic (PV) systems with much less training data. First of all, two PV systems with a different number of PV inverters and power ratings are analyzed and their attack models are studied. Next, an attack detection Convolutional Neural Network (CNN) model was trained with rich amount of data from PV #1. Then, transfer learning was proposed to transfer the well-trained features from PV #1 to PV #2. Lastly, the attack detection model on PV #2 was trained based on the transferred CNN model. The experiment results show that the proposed transfer learning method achieves better accuracy and a faster convergence rate with a much less training dataset than conventional deep learning.

14 SOLAR ENERGY↗

Toward more environmentally resistant gas turbines: Progress in NASA-Lewis programs

A wide range of programs are being conducted for improving the environmental resistance to oxidation and hot corrosion of gas turbine and power system materials. They range from fundamental efforts to delineate attack mechanisms, allow attack modeling and permit life prediction, to more applied efforts to develop potentially more resistant alloys and coatings. Oxidation life prediction efforts have resulted in a computer program which provides an initial method for predicting long time metal loss using short time oxidation data by means of a paralinear attack model. Efforts in alloy development have centered on oxide-dispersion strengthened alloys based on the Ni-Cr-Al system. Compositions have been identified which are compromises between oxidation and thermal fatigue resistance. Fundamental studies of hot corrosion mechanisms include thermodynamic studies of sodium sulfate formation during turbine combustion. Information concerning species formed during the vaporization of Na2SO4 has been developed using high temperature mass spectrometry.

Lowell, C. E.↗

A Generic T-Tail Transport Airplane Simulation for High-Angle-Of-Attack Dynamics Modeling Investigations

A preliminary simulation of a generic T-tail transport airplane configuration has been developed at the National Aeronautics and Space Administration Langley Research Center. The primary purpose of this piloted simulation is to assess aerodynamic model fidelity requirements for training airline pilots to recognize and recover from full-stall flight conditions in a T-tail airplane. As a result, significant flexibility has been designed into the flight dynamics model. The flight dynamics model is based on newly acquired static and dynamic stability and control data from sources that include: wind tunnel, water tunnel, and computational fluid dynamics. Preliminary results for initial stall show an unstable stall pitch break (if the stick pusher is inhibited), un-commanded motions due to stall asymmetries, significantly reduced dynamic roll stability, and decreased control effectiveness. Preliminary studies indicated an insensitivity to the fidelity of the pitch damping model.

Cunningham, Kevin↗

Resilient Observer Design for Cyber-Physical Systems with Data-Driven Measurement Pruning

Resilient observer design for Cyber-Physical Systems (CPS) in the presence of adversarial false data injection attacks (FDIA) is an active area of research. The existing state-of-the-art algorithms tend to break down as more and more knowledge of the system is built into the attack model; also as the percentage of attacked nodes increases. From the view of optimization theory, the problem is often cast as a classical error correction problem for which a theoretical limit of has been established as the maximum percentage attacked nodes for which state recovery is guaranteed. Beyond this limit, the performance of -minimization based schemes, for instance, deteriorates rapidly. Similar performance degradation occurs for other types of resilient observers beyond certain percentages of attacked nodes. In order to increase the corresponding percentage of attacked nodes for which state recoveries can be guaranteed, researchers have begun to incorporate prior information into the underlying resilient observer design framework. For the most pragmatic cases, this prior information is often obtained through a data-driven machine learning process. Existing results have shown a strong positive correlation between the maximum attacked percentages that can be tolerated and the accuracy of the data-driven model. Motivated by these results, this chapter examines the case for pruning algorithms designed to improve the Positive Prediction Value (PPV) of the resulting prior information, given stochastic uncertainty characteristics of the underlying machine learning model. Theoretical quantification of the achievable improvement is given. Simulation results show that the pruning algorithm significantly increases the maximum correctable percentage of attacked nodes, even for machine learning model whose prediction power is comparable to the random flip of a coin.

Resilient Observer, Cyber-physical Systems, Data-D↗

Deception-Based Cyber Attacks on Hierarchical Control Systems using Domain-Aware Koopman Learning

Industrial control systems are subject to cyber attacks that produce physical consequences. These attacks can be both hard to detect and protracted. Here, we focus on deception-based sensor bias attacks made against a hierarchical control system where the attacker attempts to be stealthy. We develop a a data-driven, optimization-based attacker model and use the Koopman operator to represent the system dynamics in a domain-aware and computationally efficient manner. Using this model, we compute several different attacks against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. Finally, we discuss some computational considerations and identify avenues for future research.

koopman operator, Cyber-Physical Security, machine↗

A Risk Assessment Framework for Cyber-Physical Security in Distribution Grids with Grid-Edge DERs

Integration of inverter-based distributed energy resources (DERs) is reshaping the landscape of distribution grids to fulfill the socioeconomic, environmental, and sustainability goals. Addressing the technological challenges of DER grid integration requires an adaptive communication layer for efficient DER management and control. This transition has given rise to a cyberphysical system (CPS) architecture within the distribution system, causing new vulnerabilities for cyberphysical attacks. To better address potential threats, this paper presents a comprehensive risk assessment framework for cyberphysical security in distribution grids with grid-edge DERs. The framework incorporates a detailed CPS model accounting for dynamic DER characteristics within the distribution grid. It identifies vulnerabilities in DER communication systems, models attack scenarios, and addresses communication latency crucial for inverter control timescales. Subsequently, the quantification of attack impacts employs an attack probability model including both the vulnerability and criticality of cyber components. The proposed risk assessment framework was validated through testing on the modified IEEE 13-node and 123-node test feeders.

cyberattack↗