Search NASA⌕ Search

SEARCH · Search NASA

Results for “attack modeling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Bayesian Attack Model (BAM)

The Bayesian Attack Model (BAM) is an analytical tool designed to enhance the comprehension of adversarial activity in OT environments. BAM leverages both expert cybersecurity insights and historical data to characterize the likelihood of adversarial behavior given anomalous observable events.

99 GENERAL AND MISCELLANEOUS↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Ransomware Attack Modeling and Artificial Intelligence-Based Ransomware Detection for Digital Substations

Ransomware has become a serious threat to the current computing world, requiring immediate attention to prevent it. Ransomware attacks can also have disruptive impacts on operation of smart grids including digital substations. This paper provides a ransomware attack modeling method targeting disruptive operation of a digital substation and investigates an artificial intelligence (AI)-based ransomware detection approach. The proposed ransomware file detection model is designed by a convolutional neural network (CNN) using 2-D grayscale image files converted from binary files. Here, the experimental results show that the proposed method achieves 96.22% of ransomware detection accuracy.

artificial intelligence↗

Grid Cyber-Security Strategy in an Attacker-Defender Model

The progression of cyber-attacks on the cyber-physical system is analyzed by the Probabilistic, Learning Attacker, and Dynamic Defender (PLADD) model. Although our research does apply to all cyber-physical systems, we focus on power grid infrastructure. The PLADD model evaluates the effectiveness of moving target defense (MTD) techniques. We consider the power grid attack scenarios in the AND configurations and OR configurations. In addition, we consider, for the first time ever, power grid attack scenarios involving both AND configurations and OR configurations simultaneously. Cyber-security managers can use the strategy introduced in this manuscript to optimize their defense strategies. Specifically, our research provides insight into when to reset access controls (such as passwords, internet protocol addresses, and session keys), to minimize the probability of a successful attack. Our mathematical proof for the OR configuration of multiple PLADD games shows that it is best if all access controls are reset simultaneously. For the AND configuration, our mathematical proof shows that it is best (in terms of minimizing the attacker's average probability of success) that the resets are equally spaced apart. We introduce a novel concept called hierarchical parallel PLADD system to cover additional attack scenarios that require combinations of AND and OR configurations.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

Subsonic wind tunnel investigation of a twin-engine attack airplane model having nonmetric powered nacelles

A 1/10-scale powered model of a twin-engine attack airplane was investigated in the Langley high-speed 7- by 10-foot tunnel. The study was made at several Mach numbers between 0.225 and 0.75 which correspond to Reynolds numbers, based on the mean aerodynamic chord, of 1.35 million and 3.34 million. Unheated compressed air was used for jet simulation in the nonmetric engine nacelles which were located ahead of and above the horizontal stabilizer.

Lockwood, V. E.↗

Interference effects of aft reaction-control yaw jets on the aerodynamic characteristics of a space shuttle orbiter model at supersonic speeds

A wind tunnel investigation of the interference effects of aft reaction control system yaw jet plumes on a 0.0125 scale Space Shuttle orbiter model was conducted at Mach numbers from 2.50 to 4.50. Test variables included model angle of attack, model angle of sideslip, jet to free stream mass flow ratio, and number and position of operating jets. The aft reaction control jet plume creates a blockage above and behind the wing on the side in which the jet exhausts and results in flow separation on the wing upper surface and fuselage side. Positive pitching moment and side force increments and negative yawing moment and rolling moment increments due to the flow separations are incurred for left side firing jets, primarily at angles of attack above 10 deg. The yawing moment interference increments are favorable and result in a small jet thrust amplification. As a result of this investigation, the aft reaction control system was certified for operation at supersonic Mach numbers prior to the first flight of the space transportation system (STS-1).

Covell, P. F.↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Acoustic measurements of the X-wing rotor

Noise measurements of a stoppable X-wing rotor system model, tested in the Ames 40- by 80-foot wind tunnel, are summarized. Performance, control system stability, and noise of the model were investigated at various forward speeds, tip speeds, collective blade angles, jet blowing velocities, and model attack angles. The model was tested in the rotating wing helicopter configuration, in the fixed wing configuration, and in wing configurations between the two. Noise data obtained in the helicopter configuration at the two highest tip speeds (Mach 0.44 and 0.47) and at wind tunnel speeds below 140 knots are reported. Test configuration and performance information are included. General acoustic measurements (dB, dBA, and PNdB) at six microphone locations are presented for all conditions under which the background noise was below the model noise. More specific measurements (1/3-octave and blade passage frequency harmonic levels) are presented for selected conditions. Graphs of dBA and 1/3-octave spectra, which show the noise trends as functions of operating condition, are included. The noise depends mainly on the jet blowing velocity. The noise levels were highest at moderate jet blowing velocities, less at the highest velocity, and lowest with no blowing at all.

Mosher, M.↗

Data-driven cyber-attack detection for photovoltaic systems: A transfer learning approach

With increasing exposure to software-based sensing and control, power systems are facing higher risks of cyber/physical attacks. Here, to ensure system stability and minimize the potential economic losses, it is imperative to monitor the operating states and detect those attacks at the early stage. In this paper, a transfer learning method is proposed to detect cyber-attacks in photovoltaic (PV) systems with much less training data. First of all, two PV systems with a different number of PV inverters and power ratings are analyzed and their attack models are studied. Next, an attack detection Convolutional Neural Network (CNN) model was trained with rich amount of data from PV #1. Then, transfer learning was proposed to transfer the well-trained features from PV #1 to PV #2. Lastly, the attack detection model on PV #2 was trained based on the transferred CNN model. The experiment results show that the proposed transfer learning method achieves better accuracy and a faster convergence rate with a much less training dataset than conventional deep learning.

14 SOLAR ENERGY↗

Toward more environmentally resistant gas turbines: Progress in NASA-Lewis programs

A wide range of programs are being conducted for improving the environmental resistance to oxidation and hot corrosion of gas turbine and power system materials. They range from fundamental efforts to delineate attack mechanisms, allow attack modeling and permit life prediction, to more applied efforts to develop potentially more resistant alloys and coatings. Oxidation life prediction efforts have resulted in a computer program which provides an initial method for predicting long time metal loss using short time oxidation data by means of a paralinear attack model. Efforts in alloy development have centered on oxide-dispersion strengthened alloys based on the Ni-Cr-Al system. Compositions have been identified which are compromises between oxidation and thermal fatigue resistance. Fundamental studies of hot corrosion mechanisms include thermodynamic studies of sodium sulfate formation during turbine combustion. Information concerning species formed during the vaporization of Na2SO4 has been developed using high temperature mass spectrometry.

Lowell, C. E.↗

A Flexible and Generic Functional Mock-up Unit Based Threat Injection Framework for Grid-interactive Efficient Buildings: A Case Study in Modelica

Grid-interactive efficient buildings (GEBs) have been considered as an important asset to support the power grid reliability by utilizing the demand flexibility offered by GEBs. GEBs are enabled by advances in sensors and controls, and the communication between building equipment, whole buildings, and the grid. The integration of different building technologies and network-based communication system makes GEBs vulnerable to passive threats such as equipment failure and active threats such as cyber-attacks. Modeling and simulation is an effective way to evaluate the impact of threats on the system performance. This paper proposes a generic and flexible threat injection framework for commonly-used building energy simulators such as EnergyPlus and Modelica to support threat modeling and evaluation. This framework leverages functional mock-up unit (FMU) to develop a general modeling interface for threat injection and simulation. A numerical case study using Modelica as a building energy simulator is conducted to demonstrate the capability of the framework for supporting single/multiple-order threat modeling and simulation of a GEB. Four threats and their combinations are injected on a Modelica-based threat-free building energy and control system, including operating supply fan at its full speed, remotely cycling the chiller on and off, blocking the chiller from receiving the chilled water supply temperature setpoints, and hijacking the global zone air temperature setpoint. Simulation results show that the cyber-attack that leads to short-term signal blocking has small effects on the system operation due to the "self-healing" feature of the heating, ventilation, and air-conditioning (HVAC) interactive control system. The threat that takes control of resetting the global zone air temperature setpoints has the most adverse impact on the system energy use, peak power demand, thermal comfort and the provision of demand flexibility. The combination of four threats have aggregative effects on the system but the effects are less than the additive effects of the individual threat.

Fu, Yanyang↗

A Generic T-Tail Transport Airplane Simulation for High-Angle-Of-Attack Dynamics Modeling Investigations

A preliminary simulation of a generic T-tail transport airplane configuration has been developed at the National Aeronautics and Space Administration Langley Research Center. The primary purpose of this piloted simulation is to assess aerodynamic model fidelity requirements for training airline pilots to recognize and recover from full-stall flight conditions in a T-tail airplane. As a result, significant flexibility has been designed into the flight dynamics model. The flight dynamics model is based on newly acquired static and dynamic stability and control data from sources that include: wind tunnel, water tunnel, and computational fluid dynamics. Preliminary results for initial stall show an unstable stall pitch break (if the stick pusher is inhibited), un-commanded motions due to stall asymmetries, significantly reduced dynamic roll stability, and decreased control effectiveness. Preliminary studies indicated an insensitivity to the fidelity of the pitch damping model.

Cunningham, Kevin↗