Search NASA⌕ Search

SEARCH · Search NASA

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Hybrid Cyber-attack Detection in Photovoltaic Farms

Here, to address the cyber-physical security in PV farms, a hybrid cyber-attack detection is proposed in this manuscript. To secure PV farms, the proposed method integrates model-based and data-driven methods by fusing the detection score at the device and system levels. First, a model-based cyber-attack detection method is developed for each PV inverter. A residual between the estimation of the Kalman filter and measurement is calculated. By leveraging the calculated residual from all inverters, a squared Mahalanobis distance is developed for device detection score generation. At the system level, a convolutional neural network (CNN) is proposed to detect cyber-attack using the waveform data at the point of common coupling (PCC) in PV farms. To improve the CNN detection accuracy, a set of well-designed features are extracted from the raw waveform data. Finally, a weighted detection score fusion method is proposed to combine device and system detection scores by using their complementary strength. The feasibility and robustness of the proposed method are validated by testing cases and a comparative experiment.

14 SOLAR ENERGY↗

Zero-day Attack Detection in Digital Substations Using In-Context Learning

In this paper, we address the critical challenge of detecting zero-day attacks in digital substations that employ the IEC-61850 communication protocol to ensure the security and reliability of modern power systems. While many heuristic and machine learning (ML)-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to unknown or zero-day attacks remains a challenge. We propose an approach that leverages the in-context learning ability of transformer architecture, which enables the model to learn from a few examples of a new task without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 87% detection accuracy on zero-day attacks while the existing baselines fail. We believe this work has the potential to enhance the security of digital substations by enabling the effective detection of zero-day attacks.

LIu, Chen-Ching [Virginia Tech] (ORCID:00000002894↗

Machine Learning-based False Data Injection Attack Detection and Localization in Power Grids

Cyberattacks on critical infrastructures can be catastrophic and bring nations to their knees. Therefore, detecting these attacks is crucial and challenging. This paper presents a novel approach for detecting and locating cyberattacks affecting an electrical power system. The adversary employs a man-in-the-middle technique to inject false data into the communication between distributed energy resources (DER) and Microgrid Controller (MGC) with the goal of disrupting power delivery. The approach for detection and localization is based on integrating multiple machine learning-based anomaly detection models that combine network traffic data and grid measurements. Experiments are performed to assess the method's performance using a hardware-in-the-loop real-time simulation testbed which includes Modbus TCP/IP communication. Power system topology and operating conditions are based on actual topology and real-world data provided by the Holy Cross Energy utility network. Results confirm that the method can be successfully employed for detecting and localizing cyberattacks.

Leao, Bruno P.↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗

Adaptive Hierarchical Cyber Attack Detection and Localization in Active Distribution Systems

Development of a cyber security strategy for the active distribution systems is challenging due to the inclusion of distributed renewable energy generations. Here this paper proposes an adaptive hierarchical cyber attack detection and localization framework for distributed active distribution systems via analyzing electrical waveforms. Cyber attack detection is based on a sequential deep learning model, via which even minor cyber attacks can be identified. The two-stage cyber attack localization algorithm first estimates the cyber attack sub-region, and then localize the specified cyber attack within the estimated subregion. We propose a modified spectral clustering-based network partitioning method for the hierarchical cyber attack ‘coarse’ localization. Next, to further narrow down the cyber attack location, a normalized impact score based on waveform statistical metrics is proposed to obtain a ‘fine’ cyber attack location by characterizing different waveform properties. Finally, compared with classical and state-of-art methods, a comprehensive quantitative evaluation with two case studies shows promising estimation results of the proposed framework.

42 ENGINEERING↗

Data-driven cyber-attack detection for photovoltaic systems: A transfer learning approach

With increasing exposure to software-based sensing and control, power systems are facing higher risks of cyber/physical attacks. Here, to ensure system stability and minimize the potential economic losses, it is imperative to monitor the operating states and detect those attacks at the early stage. In this paper, a transfer learning method is proposed to detect cyber-attacks in photovoltaic (PV) systems with much less training data. First of all, two PV systems with a different number of PV inverters and power ratings are analyzed and their attack models are studied. Next, an attack detection Convolutional Neural Network (CNN) model was trained with rich amount of data from PV #1. Then, transfer learning was proposed to transfer the well-trained features from PV #1 to PV #2. Lastly, the attack detection model on PV #2 was trained based on the transferred CNN model. The experiment results show that the proposed transfer learning method achieves better accuracy and a faster convergence rate with a much less training dataset than conventional deep learning.

14 SOLAR ENERGY↗

Cyber-Attack Detection for Active Neutral Point Clamped (ANPC) Photovoltaic (PV) Converter using Kalman Filter

With the upgrading of communication technology, cyber threats to power converters are increasing. In this paper, a model-based cyber-attack detection methodology is proposed for the interleaved Active neutral point clamped (ANPC) Photovoltaic (PV) converter. The proposed methodology identifies cyber-attacks using two estimations based on the Kalman filter and the state-space model of the ANPC PV converter. The residual between the two estimations is analyzed from a statistical perspective. Based on the Cumulative Sum (CUSUM) Control Chart, the standard errors shift of the residual is used to identify cyber-attacks. Besides, to validate the feasibility of the proposed methodology, several conditions are considered in the simulation, including white noise in the sensor, irradiance variation, and cyber-attacks in the PV converter. Furthermore, the simulation result demonstrates the proposed method can identify cyber-attacks in the ANPC PV converter.

14 SOLAR ENERGY↗

A distributed voltage inference framework for cyber-physical attacks detection and localization in active distribution grids

The transition to active distribution grids with real-time monitoring and control depends on the proliferation of advanced communication networks and devices. This paradigm shift towards a cyber-physical architecture also introduces new vulnerabilities for adversaries to exploit and launch sophisticated cyber-physical attacks targeting grid observability. Current research highlights the challenges in distinguishing attacks on voltage phasor or nodal injection measurements and isolating multi-source attack locations in a multiphase distribution grid. The attack detection and localization methods in literature face accuracy issues, applications across diverse attack scenarios, or scalability limits. Here, to bridge these gaps, this paper proposes a distributed Voltage Inference framework for real-time detection and localization of cyber-physical attacks, addressing scalability, adaptability, and accuracy challenges in state-of-the-art methods. The proposed methodology leverages the distributed nature of the Voltage Inference framework through a two-step process of prediction and correction, together with a tractable graph partitioning approach, providing a reliable solution to identify compromised measurement sources and facilitate isolation. Extensive testing on IEEE 13 and 123-node distribution feeders underscores the algorithm’s efficacy, enhancing the security and resilience of active distribution grids against evolving cyber threats. Additionally, Hardware-in-the-Loop (HIL) implementation validates the proposed strategy’s practical applicability in real-world scenarios.

active distribution grids↗

Cyber-Attack Detection and Accommodation for the Energy Delivery System

The goals of this project were to create a software system with a suite of key algorithms for cyber-attack detection and accommodation providing domain layer protection for critical power generation assets. Example assets included gas and steam turbines, heat recovery steam generators, and electrical generators. The aggressive algorithm goals were aimed at reducing the false positive rates in threat detection to <1% using learnings from many evolving disciplines (power turbine and generator physics, power system modeling, modern control theory, system identification, machine learning, deep learning, mathematics and data science). Additional goals for the algorithms involved localizing threats on-the-fly to know in which monitoring node the effects of attacks are present, and then providing accommodation to keep the system running uninterrupted much of the time in the presence of the attack. Accommodation had a performance goal of providing resiliency when up to 50% of monitoring nodes are in an attack state.

cybersecurity, cyber-physical↗

Denial of Service Attack Detection via Differential Analysis of Generalized Entropy Progressions

Denial-of-Service (DoS) attacks are one the most common and consequential cyber attacks in computer networks. While existing research offers a plethora of detection methods, the issue of achieving scalability, a low false positive rate, and high detection accuracy remains open. In this work, we address this problem by developing a differential method based on generalized entropy progression. In this method, named as DoDGE, we continuously fit the line of best fit to the entropy progression of destination addresses and check if the derivative, that is, the slope of this line is less than the negative of the dynamically computed standard deviation of the derivatives. Furthermore, to distinguish from flash events, we leverage the symmetry that when a flash event occurs, the derivative of the entropy progression of source addresses is positive. With this design, we omit the usage of the thresholds and the results with five real-world network traffic datasets confirm that DoDGE outperforms threshold-based DoS attack detection by two orders of magnitude in terms of false positives on average. When compared to ten machine learning (ML) models, DoDGE achieves a balanced accuracy of 99%, while the average balanced accuracy for the ML models is 52%. Moreover, the results show that DoDGE successfully differentiates between a flash event and a DoS attack. Furthermore, since the main computation cost of DoDGE is the entropy computation, which is linear in the volume of the unit-time network flow, uses integer only operations, and works on a small fraction of the total flow, it is lightweight and scalable.

Cybersecurity, wireless communication↗

Advancing Cyber-Attack Detection in Power Systems: A Comparative Study of Machine Learning and Graph Neural Network Approaches

This paper explores the detection and localization of cyber-attacks on power systems, focusing on comparing conventional machine learning (ML) and deep learning methods, and graph neural network (GNN)-based techniques. We assess the detection accuracy of these approaches and their potential to pinpoint the locations of specific buses under attack. Given the demonstrated success of GNNs in other time series anomaly detection applications, we aim to evaluate their performance within the context of power systems cyber-attack. Utilizing the IEEE 68-bus system, we simulated four types of attacks to test the selected approaches. Our results indicate that GNN-based methods outperform conventional machine learning and deep learning models in detection. Additionally, GNNs show promise in accurately localizing attacks for simple scenarios, although they still face challenges in more complex cases.

artificial intelligence↗

Automatic DDoS Attack Detection on SDNs: Preprint

Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks pose a serious threat to computing networks - especially to critical systems within the U.S. electrical grid. As attack mechanisms have increased in complexity and variety, more sophisticated detection mechanisms have become necessary to ensure network security. This paper explores the use of artificial intelligence to automate the process of detection and mitigation of DoS and DDoS attacks within the framework of Software-Defined Networking (SDN), to a high degree. Machine learning algorithms are trained to recognize DoS and DDoS attacks and are deployed in real-time to mitigate malicious network traffic. The results show a well-tuned gradient-boosted decision tree detecting DoS and DDoS attacks, as well as initial successful mitigation of attacks within an SDN framework.

cyber detection↗

Bayesian GAN-Based False Data Injection Attack Detection in Active Distribution Grids With DERs

Advancements in information and communication technologies have revolutionized monitoring and control capabilities within smart grids. However, it also brings new vulnerabilities to data acquisition systems and state estimation functions, which attackers can subtly tamper with the measurement data through compromising the communication network. Moreover, the high penetration of renewable energy sources with the inherited characteristics of uncertainty and variability further complicates the design of effective intrusion detection systems. In this paper, a Bayesian deep learning-based approach is developed to detect cyber attacks and maintain the security of smart grids. Our method specifically addresses the prevalent issue of imbalanced data in real power systems, which arises from the predominance of normal system operations over compromised or attacked states. Employing a novel Bayesian GAN-based technique, our approach successfully discriminates between secure and compromised measurement data, even in scenarios with significant data imbalance. Furthermore, the proposed method accommodates various practical application factors, ensuring accurate intrusion detection despite the presence of measurement noise. The feasibility and effectiveness of the proposed detection mechanism are validated by testing on IEEE 13-node and 123-node test systems. Simulation results and comparisons with literature methods demonstrate the superiority of proposed cybersecurity solutions.

Bayesian GAN↗

SNNPG: Using Spiking Neural Networks to Detect Attacks in the Power Grid

We explore the potential of Spiking Neural Networks (SNN) to enhance the security of power grid operations by detecting False Data Injection (FDI) attacks. These attacks manipulate PMU readings, leading to erroneous control decisions and grid disruptions. We develop a method to convert Phase Measurement Unit (PMU) data into spike trains, capturing both temporal and spatial dimensions. Using an SNN model, we conduct evaluations with simulated power grid data, showcasing accuracy in detecting FDI attacks. SNN models rapidly identify anomalies in real-time PMU data, safeguarding grid operations by alerting operators to irregular readings and preventing incorrect decisions.

artificial intelligence↗

Machine Learning 5G Attack Detection in Programmable Logic

Machine learning-assisted network security may significantly contribute to securing 5G components. However, machine learning network security inference speeds generally require tens to hundreds of milliseconds thereby introducing significant latency in 5G operations. The inference latency can be reduced by deploying the machine learning model to programmable logic in a field programmable gate array (FPGA) at the cost of a small loss in accuracy. In order to quantify this loss, as well as to establish baseline performance inference speeds for programmable logic implementations, this work explores an autoencoder and a ß-variational autoencoder deployed on two different FPGA evaluation boards and compares accuracy and performance against an NVIDIA A100 GPU implementation. A publicly available 5G dataset containing 10 types of attacks along with normal traffic is introduced as part of the evaluation.

97 MATHEMATICS AND COMPUTING↗