Search NASA⌕ Search

Engineering topics

St. Michel, Curtis P.

Publications and source records attributed to St. Michel, Curtis P..

CCE Case Study: Baltavia Substation Power Outage

In this case study, we will examine a fictional event broadly inspired by the real power outages in Ukraine that took place in December 2015 and December 2016—both the result of cyber-enabled sabotage. The actual events of 2015 and 2016 were well-documented—the adversaries in these attacks gained access to a few power companies’ corporate networks, pivoted to industrial control system (ICS) networks, and created widespread physical effects in the form of power outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CCE Case Study: Baltavia Substation Power Outage

In this case study, we will examine a fictional event broadly inspired by the real power outages in Ukraine that took place in December 2015 and December 2016 - both the result of cyber-enabled sabotage. The actual events of 2015 and 2016 were well-documented - the adversaries in these attacks gained access to a few power companies’ corporate networks, pivoted to industrial control system (ICS) networks, and created widespread physical effects in the form of power outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CCE Phase 4: Mitigations and Protections

During the first three phases, the CCE Team identified any instances of unverified trust in the organization’s technologies, processes, and procedures, any or all of which could be used to adversely impact the system. In Phase 4, the primary goal is to remove the possibility of the end effect—that is, to develop means or mechanisms that will ensure an adversary cannot achieve their Objective (identified in Phase 1) via cyber means. Such measures are known as “protections.” In some cases, this may not be possible, or the implementation of protections may not be desirable due to other considerations. In such cases, means and mechanisms should be developed that focus on putting an organization in a better position to identify adversary activities directed against it, increasing the cost of cyber-enabled sabotage for the adversary (including making things more difficult for the adversary and attempting to lower the chances an adversary may succeed), or decreasing the recovery cost of a victim organization. These measures are known as “mitigations.”

99 GENERAL AND MISCELLANEOUS↗

CCE Phase 3: Consequence-based Targeting

While Phase 2 was a data collection effort, Phase 3 is a targeting effort. In Phase 3, organizations systematically identify the necessary steps for adversary success - all from the adversary’s perspective. A key component to this approach is identifying the critical information needs, targets, access, and actions required for the adversary to achieve the desired effect. These Critical Needs are tied to accomplishing the HCE, such as the technical requirements for the payload (Development), or the access required to deliver a payload (Deployment).

99 GENERAL AND MISCELLANEOUS↗

CCE Phase 2: System-of-System Analysis

During Phase 1, Consequence Prioritization, the CCE Team identified High Consequence Events (HCEs) that can be accomplished through cyber means to impact critical functions, services, and processes. During Phase 2, System-of-Systems Analysis (SoS Analysis), the CCE Team will conduct a systematic review and analysis of information related to the equipment, systems, processes, operations, maintenance, testing, and procurement practices based on the HCEs identified in Phase 1.

99 GENERAL AND MISCELLANEOUS↗

CCE Phase 1: Consequence Prioritization

Idaho National Laboratory (INL) developed the Consequence-driven Cyber-informed Engineering (CCE) methodology to provide public and private organizations with steps to work collaboratively and establish a working relationship to protect critical infrastructure and other national assets. This process is a considerable undertaking, iterative in nature, and—as time and resources allow—should become a part of a company’s culture. By focusing on the impact of potentially negative Events, CCE provides a better understanding of how and why adversaries can affect critical functions and services using cyber-enabled sabotage. This document describes Phase 1 of the CCE process.

99 GENERAL AND MISCELLANEOUS↗