Search NASA⌕ Search

SEARCH · Search NASA

Results for “cyber attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Hybrid Cyber-attack Detection in Photovoltaic Farms

Here, to address the cyber-physical security in PV farms, a hybrid cyber-attack detection is proposed in this manuscript. To secure PV farms, the proposed method integrates model-based and data-driven methods by fusing the detection score at the device and system levels. First, a model-based cyber-attack detection method is developed for each PV inverter. A residual between the estimation of the Kalman filter and measurement is calculated. By leveraging the calculated residual from all inverters, a squared Mahalanobis distance is developed for device detection score generation. At the system level, a convolutional neural network (CNN) is proposed to detect cyber-attack using the waveform data at the point of common coupling (PCC) in PV farms. To improve the CNN detection accuracy, a set of well-designed features are extracted from the raw waveform data. Finally, a weighted detection score fusion method is proposed to combine device and system detection scores by using their complementary strength. The feasibility and robustness of the proposed method are validated by testing cases and a comparative experiment.

14 SOLAR ENERGY↗

Small-Signal Angle Stability-Oriented False Data Injection Cyber-Attacks on Power Systems

The small-signal angle stability (SSAS) of a power system is determined by the property of operation points. The widely applied false data injection (FDI) cyber-attack, however, is able to stealthily mislead the optimal power flow (OPF) and thus compromise operation points, leading to damages to the SSAS margin. Here, to provide insights for cyber defenders, this paper proposes and investigates a stealthy SSAS-oriented FDI cyber-attack focusing on two attacking purposes, i.e., the SSAS margin and operation cost, with higher priority on the former one. First, this paper establishes a novel bi-level model with an implicit SSAS constraint based on a structure preserving model to compromise operation points. Then, for the SSAS interarea mode in a typical two-area system, this paper formulates closed-form expressions of how the SSAS margin and operation cost behave with respect to stealthy injections. By comparison, for the SSAS local mode in general power systems, this paper proposes a moving target cyber-attack-based hierarchical solution algorithm. Simulation results on a two-area system, a Kundur 11 bus system, and a modified IEEE 14 bus system demonstrate the significant damaging effects of the proposed SSAS-oriented FDI cyber-attack and the conflict between the two attacking purposes.

Benders decomposition↗

Adaptive Hierarchical Cyber Attack Detection and Localization in Active Distribution Systems

Development of a cyber security strategy for the active distribution systems is challenging due to the inclusion of distributed renewable energy generations. Here this paper proposes an adaptive hierarchical cyber attack detection and localization framework for distributed active distribution systems via analyzing electrical waveforms. Cyber attack detection is based on a sequential deep learning model, via which even minor cyber attacks can be identified. The two-stage cyber attack localization algorithm first estimates the cyber attack sub-region, and then localize the specified cyber attack within the estimated subregion. We propose a modified spectral clustering-based network partitioning method for the hierarchical cyber attack ‘coarse’ localization. Next, to further narrow down the cyber attack location, a normalized impact score based on waveform statistical metrics is proposed to obtain a ‘fine’ cyber attack location by characterizing different waveform properties. Finally, compared with classical and state-of-art methods, a comprehensive quantitative evaluation with two case studies shows promising estimation results of the proposed framework.

42 ENGINEERING↗

Precursor Analysis Report: Cyber Attack on Thyssenkrupp Blast Furnace 2014

The Cyber Attack on Thyssenkrupp Blast Furnace 2014 Precursor Analysis Report leverages publicly available information about the Thyssenkrupp Steel Mill cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. In December 2014, the German Government’s Federal Office for Information Security (BSI) released a report detailing a cyber attack on a German steel mill that occurred earlier that year, though exact dates and details of the attack were not revealed. While the report did not specify the name of the company, multiple sources identified the victim as one of Europe’s largest steel manufacturers, Thyssenkrupp AG. Further, Thyssenkrupp announced on 16 May of that year that Europe’s largest blast furnace, “Schwelgern 2,” located at its facility in Duisburg, Germany, would be offline for several weeks for repairs and upgrades, suggesting Schwelgern 2 was likely the target of the attack. The attack began in early 2014, when adversaries infiltrated the victim steel mill’s Information Technology (IT) network via a spearphishing campaign, then worked their way into the Operational Technology (OT) environment, where they executed software that caused denial of service, denial of control, and eventually a loss of control. This led to the blast furnace shutting down without proper safety procedures, resulting in catastrophic physical damage. No lives were lost in the incident, but ThyssenKrupp suffered $4 million in damage to the blast furnace and an additional $6 million in lost revenue. The adversaries required specialized knowledge and expertise in steel production, which enabled them to compromise a variety of internal systems and components across both IT and OT networks. The attack also demonstrated detailed knowledge of the industrial control systems (ICS) and production processes being used. This combination resulted in one of the earliest known publicly reported cybersecurity incidents resulting in physical damage to ICS equipment. Researchers and analysts identified 19 unique techniques (used in a sequence of 20 steps) utilized during the attack with a total of 454 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Fifteen of the identified techniques used during the Thyssenkrupp cyber attack were precursors to the triggering event. Analysis identified 369 observables associated with these precursor techniques, 316 of which were assessed to have an increased likelihood of being perceived in the 120 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Systems and methods for controlling an industrial asset in the presence of a cyber-attack

Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, a cyber-attack model predicts a plurality of operational impacts on the industrial asset resulting from a plurality of potential cyber-attacks. The cyber-attack model also predicts a corresponding plurality of potential mitigation responses. In operation, a cyber-attack impacting at least one component of the industrial asset is detected via the cyber-attack neutralization module and a protected operational impact of the cyber-attack is identified based on the cyber-attack model. The cyber-attack neutralization module selects at least one mitigation response of the plurality of mitigation responses based on the predicted operational impact and an operating state of the industrial asset is altered based on the selected mitigation response.

D'Amato, Fernando Javier↗

Modeling and Evaluation of Cyber-Attacks on Grid-Interactive Efficient Buildings

Grid-interactive efficient buildings (GEBs) are not only exposed to passive threats (e.g., physical faults) but also active threats such as cyber-attacks launched on the network-based control systems. The impact of cyber-attacks on GEB operation are not yet fully understood, especially as regards the performance of grid services. To quantify the consequences of cyber-attacks on GEBs, this paper proposes a modeling and simulation framework that includes different cyber-attack models and key performance indexes to quantify the performance of GEB operation under cyber-attacks. The framework is numerically demonstrated to model and evaluate cyber-attacks such as data intrusion attacks and Denial-of-Service attacks on a typical medium-sized office building that uses the BACnet/IP protocol for communication networks. Simulation results show that, while different types of attacks could compromise the building systems to different extents, attacks via the remote control of a chiller yield the most significant consequences on a building system’s operation, including both the building service and the grid service. It is also noted that a cyber-attack impacts the building systems during the attack period as well as the post-attack period, which suggests that both periods should be considered to fully evaluate the consequences of a cyber-attack.

Fu, Yanyang↗

WAMS-Based HVDC Damping Control for Cyber Attack Defense

Owing to the fast and large power regulating the capacity of the HVDC system, the wide-area measurement system (WAMS) based high voltage direct current (HVDC) system has been regarded as a prospective solution to deal with the low-frequency oscillation issue. However, due to the vulnerability of the WAMS communication, WAMS based HVDC system control can be a prime target of malicious penetrations that could lead to disastrous events. To remediate this adverse effect, an improved WAMS based HVDC damping control framework is proposed in this paper. First, a lightweight network named Attack Shuffle convolutional neural Networks (ASNet) is proposed to learn the characteristics of cyber attacks. Then, a model-free-based cyber attack defense framework is introduced to quickly identify the attack types based on the continuous wavelet transform and ASNet. Additionally, an improved control framework of the WAMS and HVDC-based wide-area power oscillation damping control (WH-PODC) is developed to provide different response control for mitigation of the impact of cyber attacks. Finally, the performance of the proposed WH-PODC control framework is evaluated with real PMU data in multiple scenarios in RTDS, where the results indicate that the response intensity can be kept under multiple types of cyber attacks while providing similar effectiveness in oscillation suppression to conventional controls.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Attack Detection for Active Neutral Point Clamped (ANPC) Photovoltaic (PV) Converter using Kalman Filter

With the upgrading of communication technology, cyber threats to power converters are increasing. In this paper, a model-based cyber-attack detection methodology is proposed for the interleaved Active neutral point clamped (ANPC) Photovoltaic (PV) converter. The proposed methodology identifies cyber-attacks using two estimations based on the Kalman filter and the state-space model of the ANPC PV converter. The residual between the two estimations is analyzed from a statistical perspective. Based on the Cumulative Sum (CUSUM) Control Chart, the standard errors shift of the residual is used to identify cyber-attacks. Besides, to validate the feasibility of the proposed methodology, several conditions are considered in the simulation, including white noise in the sensor, irradiance variation, and cyber-attacks in the PV converter. Furthermore, the simulation result demonstrates the proposed method can identify cyber-attacks in the ANPC PV converter.

14 SOLAR ENERGY↗

Emulation and detection of physical faults and cyber-attacks on building energy systems through real-time hardware-in-the-loop experiments

The increasing use of remote or mobile access, integrated wearable technologies, data exchange, and cloud-based data analytics in modern smart buildings is steering the building industry towards open communication technologies. The increased connectivity and accessibility could lead to more cyber-attacks in smart buildings. On the other hand, physical faults (e.g., HVAC -heating, ventilation, and air-conditioning faults) may have similar adverse impacts as those from the cyber-attacks on building energy systems, such as occupant discomfort, energy wastage, and equipment downtime. However, current physical behavior-based anomaly detection methods fail to differentiate between cyber-attacks and physical faults in building energy systems. Moreover, the challenge in collecting real-world threat data with ground truth has led researchers to rely on numerical models with user-defined assumptions, which may not accurately reflect real-world conditions due to the lack of in-situ experimental datasets. To address these challenges and gaps, this paper presents a flexible hardware-in-the-loop (HIL) testbed for generating cyber-attack and physical fault datasets and demonstrating threat detection algorithms in a real building automation system (BAS) environment. This testbed combines hardware (i.e., real BAS with local HVAC controllers and a physical network) with software (i.e., high-fidelity models to represent behaviors of building envelope and HVAC energy systems), enabling emulations of realistic threats. Five HIL experiments, including one baseline without any threats, two with physical faults, and two with cyber-attacks, were conducted to generate datasets containing detailed network traffic and system states. A joint classification framework, incorporating a network analyzer and a physical HVAC fault detector, was proposed to automatically detect cyber-physical abnormalities on BAS at both the network and the physical HVAC levels. The network analyzer comprises a conditional random fields (CRF) based command validator and a statistics-based detection strategy. The fault detector employs a weather and schedule-based pattern matching and feature-based principal component analysis (WPM-FPCA) method. Evaluation of the classification using four metrics from the multi-class confusion matrix revealed an average accuracy of 90.2%, recall of 89.7%, precision of 88.5% and F1-score of 89.2%. Finally, these results demonstrate that the proposed joint classification framework can effectively differentiate between specific types of cyber-attacks (e.g., device reinitialization attack, network Denial-of-Service attack) and physical faults (e.g., air handling unit operational fault, cooling coil valve stuck) in real time for improved building energy management.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Data-Driven Cyber-Attack Detection for PV Farms via Time-Frequency Domain Features

The internetworking of grid-connected power electronics converters (PECs) in photovoltaic (PV) farms has inevitably expanded the cyber-attack surfaces. Here this paper presents a comprehensive study on cyber-attack detection and diagnosis for PEC-enabled PV farms via single waveform sensor to distinguish between normal conditions, open-circuit faults, short-circuit faults, and cyber-attacks. To our knowledge, this has not been attempted before. Firstly, we propose frequency-domain magnitude-based residuals to identify short-circuit faults and a time-domain mean current vector-based feature to distinguish open-circuit faults from other threats. These features can fully reflect the specific physical characteristics of PV farms during threat duration. Secondly, unlike micro phasor measurement units (µPMU) and raw electric waveform-based methods, the proposed innovative features can address novel cyber-attacks that are excluded from the training process. Thirdly, an online hardware-in-the-loop (HIL) testbed using the OPAL-RT real-time digital simulator has verified the effectiveness. The monitoring system runs in real-time while using HIL as an operational solar farm and a National Instruments (NI) data acquisition card as the electric waveform sensor at the point of coupling.

42 ENGINEERING↗

Impact of cyber attacks on distributed compressive sensing based state estimation in power distribution grids

Modern power distribution grids suffer from multiple vulnerabilities due to the tight integration between the physical system and the cyber infrastructure. Sophisticated and malicious cyber attacks continue to adversely impact the grid operation leading to performance degradation, service interruption, and grid failure. State estimation plays an essential role in grid monitoring and advancing cyber-attack situational awareness. In this regard, this paper first proposes a distributed compressive sensing (CS) state estimation approach for an unobservable distribution grid. Further, the proposed distributed CS approach divides the distribution grid into sub-areas to perform local state estimation. Then an alternating direction method of multipliers (ADMM) based iterative information exchange among neighboring areas is employed to complete the estimation process. In this estimation process, the impact of loss of measurement data, false data injection (FDI), replay, and neighborhood cyber-attacks is analyzed. Extensive simulations are performed on the IEEE 37-bus and IEEE 123-bus standard networks to demonstrate the algorithm’s robustness to the aforementioned cyber-attacks. A quantitative analysis of computational complexity and simulation time of the distributed CS based approach is also presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Model-based Cyber-attack Detection for Voltage Source Converters in Island Microgrids

With the upgrading of communication and control in microgrids, cyber threats on the power converters are increasing. Here, in this paper, a novel model-based cyber-attack detection methodology is proposed for each voltage source converter in microgrids. The Harmonics State Space Matrix (H-Matrix) is used to build the closed-loop transfer function, providing model-based estimation with the grid voltage and control reference. Then, the space phase model (SPM) is used to calculate residual to detect cyber-attacks in voltage source converter (VSC). As controller and converter parameters are included in the H-matrix, the proposed method also could detect cyber-attacks when voltage fluctuation occurs in the grid. To verify the feasibility of the proposed method, several attacks targeting VSC in an islanded microgrid are simulated in MATLAB. Simulation and detection results are introduced to demonstrate the resilience and feasibility of the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Deep Reinforcement Learning for Distribution System Cyber Attack Defense with DERs

The use of smart inverter capabilities of distributed energy resources (DERs) enhances the grid reliability but in the meanwhile exhibits more vulnerabilities to cyber-attacks. This paper proposes a deep reinforcement learning (DRL)-based defense approach. The defense problem is reformulated as a Markov decision making process to control DERs and minimizing load shedding to address the voltage violations caused by cyber-attacks. The original soft actor-critic (SAC) method for continuous actions has been extended to handle discrete and continuous actions for controlling DERs' setpoints and loadshedding scenarios. Numerical comparison results with other control approaches, such as Volt-VAR and Volt-Watt on the modified IEEE 33-node, show that the proposed method can achieve better voltage regulation and have less power losses in the presence of cyber-attacks.

active distribution systems↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗

Reactor System Demonstration with Cyber-Attack Scenarios Using CrowPis and Arduino Microcontrollers

This study covers developing and simulating nuclear reactor system using CrowPis and Arduino microcontrollers for demonstrating cyber-attack scenarios. The team was tasked with implementing more sensors and cybersecurity aspects to the reactor program that was created by last year’s high school interns. The team received the opportunity to collaborate and obtain advice from multiple university interns that helped us gain a better perspective of our project. Our mentor’s background in nuclear science was pivotal to our understanding what we could add to the reactor program to make it as realistic as possible. The first week of our internship was spent reading as much material as possible to gain an understanding of and the background for cyber-attacks and nuclear science. Nuclear science was a new horizon for each of the high school interns on the team, so spending this time in the beginning of our internship was crucial to our success. For the remaining portion of our internship, the team collectively did our best to implement as many sensors and use as much hardware as we could to make an accurate representation of a nuclear reactor in the program that was created. This internship was a big learning experience for everyone on the team. We all gained so many insights into the nuclear world and how it can benefit our lives, as well as how so many moving pieces are needed for it to work properly.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Adaptive Deep Reinforcement Learning Algorithm for Distribution System Cyber Attack Defense With High Penetration of DERs

With grid modernization, smart inverters are increasingly used to execute advanced controls for distribution network reliability. However, this also increases the cyber-attack space. Here this paper focuses on the defense approaches to restore the system to normal operation circumstances in the presence of cyber-attacks. A unique deep reinforcement learning (DRL) method is developed to minimize voltage violations and reduce power losses for impacted feeders. The defense problem is reformulated as a Markov decision-making process to dynamically control DERs while minimizing load shedding. This is achieved via an improved soft actor-critic (SAC)-based DRL algorithm, which can govern DER set points and load-shedding scenarios in discrete and continuous modes via the auto-tune entropy and Gaussian policy features. Numerical comparison results on the modified IEEE 123-node system with other control approaches, such as Volt-VAR (VV), Volt-Watt (VW), and model predictive control (MPC) show that the proposed method can eliminate voltage violations and provide feasible control actions that perform complete mitigation of cyber-threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Trust-Based Detection and Mitigation of Cyber Attacks in Distributed Cooperative Control of Islanded AC Microgrids

In this study, we address the challenge of detecting and mitigating cyber attacks in the distributed cooperative control of islanded AC microgrids, with a particular focus on detecting False Data Injection Attacks (FDIAs), a significant threat to the Smart Grid (SG). The SG integrates traditional power systems with communication networks, creating a complex system with numerous vulnerable links, making it a prime target for cyber attacks. These attacks can lead to the disclosure of private data, control network failures, and even blackouts. Unlike machine learning-based approaches that require extensive datasets and mathematical models dependent on accurate system modeling, our method is free from such dependencies. To enhance the microgrid’s resilience against these threats, we propose a resilient control algorithm by introducing a novel trustworthiness parameter into the traditional cooperative control algorithm. Our method evaluates the trustworthiness of distributed energy resources (DERs) based on their voltage measurements and exchanged information, using Kullback-Leibler (KL) divergence to dynamically adjust control actions. We validated our approach through simulations on both the IEEE-34 bus feeder system with eight DERs and a larger microgrid with twenty-two DERs. The results demonstrated a detection accuracy of around 100%, with millisecond range mitigation time, ensuring rapid system recovery. Additionally, our method improved system stability by up to almost 100% under attack scenarios, showcasing its effectiveness in promptly detecting attacks and maintaining system resilience. These findings highlight the potential of our approach to enhance the security and stability of microgrid systems in the face of cyber threats.

Computer Science↗

Advancing Cyber-Attack Detection in Power Systems: A Comparative Study of Machine Learning and Graph Neural Network Approaches

This paper explores the detection and localization of cyber-attacks on power systems, focusing on comparing conventional machine learning (ML) and deep learning methods, and graph neural network (GNN)-based techniques. We assess the detection accuracy of these approaches and their potential to pinpoint the locations of specific buses under attack. Given the demonstrated success of GNNs in other time series anomaly detection applications, we aim to evaluate their performance within the context of power systems cyber-attack. Utilizing the IEEE 68-bus system, we simulated four types of attacks to test the selected approaches. Our results indicate that GNN-based methods outperform conventional machine learning and deep learning models in detection. Additionally, GNNs show promise in accurately localizing attacks for simple scenarios, although they still face challenges in more complex cases.

artificial intelligence↗