
The integration of smart grid technologies in energy infrastructures is a significant shift towards efficient, sustainable and reliable electricity management, but it also brings cyber security challenges to the forefront. This study delves into the cyber security vulnerabilities of key smart grid assets such as smart meters, advanced metering infrastructure systems and distributed energy resources such photovoltaic systems, virtual power plants and battery parks. A comprehensive threestep methodology is employed to identify attack vectors, analyze attack tactics and specify the appropriate mitigation strategies. The confidentiality, integrity and availability model and MITRE ATT&CK framework are employed to identify the four main attack vectors and specify the appropriate mitigation strategies based on established security principles. The results highlight the need to implement robust security measures to safeguard smart grid assets and offer strategic guidance for addressing the cyber security challenges. The study enriches the discourse on smart grid security by providing actionable insights for improving energy system reliability and resilience.
The widespread adoption of networked devices, sophisticated automation and data-driven processes in industry – also known as Industry 4.0 – has boosted the quantity and quality of manufacturing products. However, the benefits come with substantial increases in the attack surfaces of manufacturing processes and systems. In addition to affecting the quality and readiness of critical products, attacks against manufacturing processes and systems can have severe physical consequences, including human injury and death. This chapter presents the results of remote network-based control injection attacks on a computer numerical control mill. The focus is on the impacts of attacks during computer numerical control mill operation. A machine-agnostic, affordable and scalable solution for attack monitoring is developed by considering the physical effects of the attacks on wax workpieces. A simple threshold-based method for detecting attacks is demonstrated and its effectiveness is evaluated.
Cyber attacks on industrial control systems have increased dramatically due to the adoption of open, heterogeneous industrial protocols that enable remote connectivity to industrial plants. Of particular concern are attacks that impair physical processes, leading to production loss, service outages, equipment damage, human injury and environmental pollution. Given the plethora of consequences induced by cyber attacks on industrial control systems, it is vital to compute the risks associated with the attacks to enable operators to implement appropriate recovery measures. This chapter presents a probabilistic risk assessment methodology that leverages multiple Bayesian networks to measure the risks associated with cyber attacks on industrial control systems. The Bayesian networks are designed to compute the probabilities of detected cyber attacks propagating to cyber and physical assets that have not yet been compromised, thereby providing an estimate of the overall risk to the integrity of the entire industrial control system. The proposed risk assessment methodology is evaluated using a real hardware-in-the-loop case study involving a water distribution testbed.
The integrity of democratic elections relies heavily on the security of electronic voting systems. Dominion Voting Systems' ImageCast X and Election Systems & Software's ExpressVote System are among the most widely used electronic voting systems in the United States. This chapter describes efforts to verify reported vulnerabilities and identify new vulnerabilities in the two electronic voting systems at the hardware and software levels. The goal is to increase the understanding of voting system security and identify areas for improvement in order to safeguard upcoming elections.
The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.
Topological models of critical infrastructures such as power distribution networks (grids) enable the determination and validation of properties ranging from feasibility to susceptibility to attacks contingent on the placement of adversaries. Future distribution networks will require large numbers of sensors and actuators to be positioned efficiently. While it is possible to employ the same structures for power networks as information and control networks, this excessive constraint can reduce the robustness of power networks to attacks. This chapter extends previous work by incorporating a separate information layer that allows the incorporation of multiple hierarchical layers. The information layer facilitates the discovery of topological structures in which information and control aspects may still be retained, at least partially, in the presence of partial compromise of a power network structure by exploiting the limited redundancy in the information overlay hierarchy. The extended model also expresses the propagation of the effects of adversarial influence.
Subtractive manufacturing systems, specifically, computer numerical control machines, have revolutionized the manufacturing industry. Computer numerical control machining is the preferred method for producing finished parts due to its efficiency, speed and suitability for high-volume production. Securing computer numerical control machines is a priority. Compromises or disruptions of these machines can result in significant downtime, loss of productivity and financial loss. This study examines the vulnerabilities and risks associated with computer numerical control machines, in particular, systems utilizing the LBP16 protocol for controller-machine communications. The study reveals that an adversary can execute cyber-physical attacks such as sabotage and denial of service. The potential security threats emphasize the importance of implementing robust security measures to mitigate the cyber risks to computer numerical control machines.
Cyber attacks on networked automated manufacturing systems can severely impact part quality. In fact, malicious modifications may be introduced at any point during the manufacturing lifecycle. Therefore, it is vital to verify and validate that manufactured parts conform to their designs. This chapter describes a formal, end-to-end framework that verifies and validates the design integrity of manufactured parts by considering all potential points of alteration during precision manufacturing processes. The framework prevents unauthorized changes to computer-aided designs, verifies the correctness of translations from CAD models to Gcode, maintains the integrity of G-code transferred to manufacturing machines, verifies the runtime execution of G-code and part geometry, and considers the contexts of manufacturing machine operations and how manufactured parts could be altered.
This chapter formalizes the security promise of channel tranquility, where an agent will not transmit messages unless it can verify that the communications channel has not been manipulated by an adversary. In the 5G standard, user equipment presumes that no manipulation can occur in the wireless channel with a radio node. However, analysis of international mobile subscriber identity/subscription permanent identifier catchers has revealed that an adversary denies service to all the legitimate radio nodes in an administrative area to exploit user equipment vulnerabilities. To limit the adversary's ability to compromise the 5G authentication and confidentiality promises, channel tranquility imposes an upper bound on the number of messages that the adversary can transmit. This work presents a verified challenge-response mechanism that detects channel tranquility violations and responds to prevent the adversary from compromising authentication and confidentiality. An applied pi calculus model of a 5G registration procedure augmented with the challengeresponse mechanism is presented. The mechanism builds a layer of defense in depth into the 5G registration procedure by incorporating an independent, redundant cryptographic system that must be undermined before other security promises can be attacked. Channel tranquility enables user equipment to quickly establish if a radio node has access to the public key infrastructure of the 5G control network. Specifically, user equipment can deduce whether an international mobile subscriber identity/subscription permanent identifier catcher has been deployed in an administrative area and then deny the adversary the ability to exploit any vulnerabilities. The challenge-response mechanism is verified using a secrecy proof that demonstrates that the adversary cannot learn the semantics of the challenge and response semantics if at least one legitimate session between user equipment and a radio node has been completed.
Data provenance describes the origins of a digital object. This information is particularly useful when analyzing distributed workflows because extant tools, such as debuggers and application profilers, do not support tracing through heterogeneous executions that span multiple hosts. In a decentralized system, each host maintains the authoritative record of its own activity in the form of a dependency graph. Reconstructing the provenance of an object may involve the assembly of subgraphs from multiple, independently-administered hosts. The collection of host-specific dependencies coupled with cross-host flows comprise the whole-network provenance, which can grow to terabytes for a small network. Critical infrastructure assets face constant attacks and despite best efforts, some attacks, such as those leveraging zero-day exploits, succeed. Whole-network provenance has become a common basis for post-attack forensic analyses with the creation of DARPA’s Transparent Computing Program. This chapter describes and analyzes aspects of distributed querying, caching and response discrepancy detection used in forensic analyses that are specific to provenance.
The privacy of information transmitted between user equipment and radio nodes in 5G networks is preserved using encrypted channels. However, this single point of failure would expose the identities and, potentially, locations of network users if a vulnerability were to be discovered and exploited. This chapter presents a consensus algorithm that adds an additional layer of defense in the 5G standard. The algorithm leverages access to the 5G control network by multiple radio nodes in an administrative area to control the mobility of agents that can connect with user equipment. The algorithm is designed to decrease the likelihood of privacy violations by an international mobile subscriber identity catcher should a vulnerability be found in the 5G-AKA protocol. The algorithm is formalized using the π -calculus to create a contextual integrity property, and is verified using π -calculus equivalence relations.
A building management system is an infrastructure asset that operates critical building components such as water supply management, electric power monitoring and heating, ventilation and air conditioning systems. Internet of Things devices are increasingly employed in building management systems for efficient operations. The Message Queuing Telemetry Transport protocol is commonly used for communications when integrating these devices. However, each device is typically isolated and has its own platform and management dashboard. The isolation and heterogeneity hinder device visibility and render it challenging to monitor and respond to abnormal conditions, including those induced by cyber attacks. This chapter describes a security-enhanced orchestration platform for building management systems. The orchestration platform receives a variety of data from building systems and Internet of Things devices to provide situation awareness and support efficient operation. The integration of novel device auto-recovery and auto-isolation functionality in the orchestration platform enables the monitoring and mitigation of cyber attacks.
Definitions are important, especially in the U.S. federal government. They are the basis of laws that justify budgets, fund programs and determine capabilities. However, definitions are notoriously difficult to cast because they must contend with exceptions and changing circumstances. This is the case with the U.S. definition of homeland security. Despite its importance, the definition of homeland security has languished for years. The definition posted on the U.S. Department of Homeland Security website is a throwback to the original 2002 definition and apparently ignores the lessons of history that demonstrate it is deficient. In 2007, the U.S. Congress passed a law mandating a Quadrennial Homeland Security Review to prevent future lapses in homeland security. However, the definition that emerged from the first review in 2010 persists. Although it improves on the original 2002 definition, it does not adequately consider new and resurgent threats that face the nation. This chapter examines various definitions of homeland security, discusses why they are inadequate and proposes a new definition that is accurate and concise. A good definition is important to help shape the U.S. Department of Homeland Security mission, set priorities, justify budgets and ensure that programs are successful.
The introduction of smart metering systems is a paradigm shift for the power grid. New business cases such as virtual power plants and local flexibility markets are evolving. Security risks and the potential consequences of smart-grid-enabled business cases have been assessed by researchers. However, the research efforts have not ranked the business cases according to their potential disruptive consequences, which makes it difficult to prioritize risk reduction measures. This chapter describes the results of a survey of market players that sought to rank smart-grid-enabled business cases based on their perceptions of cyber attack consequences. As expected, the consequence perceptions of the market players vary considerably between the business cases. Consequence scenarios suggested by the market players are employed to explain the highest-ranked business cases, which include digital twins, remote access to smart meter circuit breakers, and grid flexibility and balance management. The survey results can support governments and market players in assessing power grid risk and prioritizing risk reduction measures.
Modern automobiles incorporate numerous sensors, actuators and electronic control units that work in concert to provide safe, efficient and comfortable driving experiences. Automobile convenience features introduce network connectivity via short-range wireless communications protocols and the Internet, potentially exposing the automobile electronics to remote attacks in addition to physical attacks. New attacks on modern automobiles are constantly being developed; their potential impacts range from inconvenience to severe injury and death. This chapter describes a security analysis methodology for rapidly evaluating the risk exposures of modern automobiles. The methodology considers the automobile attack surfaces comprising the attack vectors that provide access to automobile targets and the potential impacts resulting from successful attacks on the accessed targets. Key features of the security analysis methodology are that it is holistic and rapid, and can be applied by individuals with limited expertise in automobile technologies and cyber security.
Power outages are a well-known threat to Internet communications systems. While Internet service providers address this threat via backup power systems in datacenters and points-of-presence, office buildings and private homes may not have similar capabilities. This chapter describes an empirical study that assesses how power outages in the United States impact end-host access to the Internet. To conduct this study, the PowerPing system was created to monitor a power outage reporting website and measure end-host responsiveness in the impacted areas. PowerPing collected power outage and end-host responsiveness data over 14 months from June 2020 through July 2021. The results reveal that power outages affecting 10% or more customers in U.S. counties occur at a rate of about 50 events/day. The outages typically impact about 3,000 customers and services are restored in just under two hours. The end-host responsiveness characteristics for typical power outage events are also reported. Surprisingly, only a weak correlation exists between power outage impacts and service restoration periods versus end-host responsiveness. This suggests that improving backup power for network devices in office buildings and private homes may enable end-hosts to maintain access to Internet service during typical power outages.
Trusted computing, often referred to as confidential computing, is an attempt to enhance the trust of modern computer systems through a combination of software and hardware mechanisms. The area increased in popularity after the release of the Intel Software Guard Extensions software development kit, enabling industry actors to create applications compatible with the interfaces required to leverage secure enclaves. However, the prime choices of users are still libraries and solutions that facilitate code portability to Software Guard Extension environments without any modifications to native applications. While these have proved effective at eliminating additional development costs, they inherit all the security concerns for which Software Guard Extensions has been criticized. This chapter proposes a split computing method to enhance the privacy of deep neural network models outsourced to trusted execution environments. The key metric that guides the approach is split computing performance that does not involve architectural modifications to deep neural network models. The model partitioning method enables stricter security guarantees while producing negligible levels of overhead. This chapter also discusses the challenges involved in developing a pragmatic solution against established Intel Software Guard Extensions attacks. The results demonstrate that the method introduces negligible performance overhead and reliably secures the outsourcing of deep neural network models.
The transformation of conventional power grids to smart grids over the past decade has led to increased exposure to cyber attacks. Understanding the impacts of cyber attacks is essential to selecting appropriate mitigation strategies. This research examines the evolution in the understanding of the consequences of cyber attacks on smart grids. It has explored the literature on consequence verification during risk assessments of smart grids from 2009 to 2023. A total of 839 articles were collected. After filtering duplicate and irrelevant articles, deep content analysis yielded 125 articles that assessed cyber risks to smart grids, with 67 of them also focusing on real consequence verification. Further study identified 23 smart-grid-enabled business areas impacted by cyber risks and six methods for verifying the real consequences of cyber attacks on smart grids. Real consequence verification is important because it helps identify the most critical smart grid vulnerabilities and prioritizes efforts for mitigating cyber attacks and their negative impacts.
Critical infrastructures are complex networks with physical, geographical, logical and cyber interdependencies whose disruption can cause serious impacts to citizenry and society. Meanwhile, the use of information and communications technology to manage physical processes in critical infrastructure assets has significantly increased their cyber attack surfaces. The increased threats have led to the creation of national and international cyber security agencies to promote awareness of cyber threats and coordinate responses to cyber attacks. In 2019, Italy set up the National Security Perimeter for Cyber, a regulatory construct that stipulates measures for guaranteeing the safety and security of public and private entities that provide essential functions and services. The law associated with the regulatory construct requires the covered entities to accurately describe their networks, information and communications technology systems and related services. The 2021 Italian legislation that established the National Cybersecurity Agency requires all National Security Perimeter for Cyber entities to inform the national agency about their assets. The National Cybersecurity Agency also collects detailed infrastructure information as well as reports about cyber attacks from the entities. This chapter describes an ongoing research effort that supports Italian legislative requirements. In particular, it demonstrates how the consequences of cyber threats can be assessed in complex scenarios using an agent-based simulator that evaluates the National Cybersecurity Agency model under ransomware and distributed-denial-of-service attacks on interconnected Italian infrastructures.
Modern automobiles have numerous sensors, actuators and electronic systems interconnected via internal sub-networks that are not designed with security in mind. This chapter describes a novel real-time system that employs long short-term memory networks to monitor automobile controller area networks, detect attacks and raise alerts. A repeatable design framework is employed to construct and train multiple long short-term memory networks to recognize normal controller area network message timing patterns. The framework lays out the computational resources as well as the data collection and preprocessing and long short-term memory network model development and training steps. Also, it enables new long short-term memory network models to be trained and updated for automobiles of different makes, models and years. The attack detection system leverages a server-client configuration to monitor an automobile controller area network bus. The server is an inexpensive Raspberry Pi device connected directly to the automobile controller area network bus that captures, logs and transmits controller area network message traffic to a client via a Wi-Fi network. The client, a workstation located outside the automobile, provides the computational resources for real-time attack detection. Trained long short-term memory models executing on the client workstation analyze the received controller area network messages, identify attacks and send alerts via the Wi-Fi network. Experimental results using a 2010 Toyota Prius testbed and a fully-operational 2014 Toyota Prius automobile demonstrate the effectiveness of the real-time attack detection system.