Data-Driven approaches based on machine learning models emerge as promising methods to detect and localize false data injection attacks (FDIAs) in power grids. However, generalizing machine learning models for various grid topologies and attack strategies faces tremendous obstacles. To overcome the research gaps, we introduce PING, a physics-informed graph neural network to generalize FDIA localization. We encode physical properties and measurements into node and edge features of a graph and leverage self-attention neural networks to generalize knowledge from various power grids. Furthermore, we introduce a mask variable into the node/edge features to explicitly indicate measurement availability that accidents or cyberattacks can disrupt. These original designs enable an inductive learning capability that makes PING automatically adaptive to various power grids and attack strategies without runtime retraining. Our evaluation integrating real operation data in eight IEEE test systems demonstrates that PING can accurately localize FDIAs, i.e., 97% accuracy on average with complete measurements and 88% accuracy even with 40% missing measurements. More importantly, its performance can maintain 95% accuracy when the model is tested in completely different power grids.
Phasor Measurement Units (PMUs) enable high-speed and high-precision power quality measurements, but their vulnerability to cyber-attacks poses substantial risks to the stability and reliability of power systems. This paper explores the application of programmable networks, specifically P4 switches, to enhance the cybersecurity of PMU systems. These switches can be programmed to enable the creation of custom forwarding and processing logic at the data plane level. We analyze PMU-specific attacks through attack trees, propose effective mitigation strategies using programmable switches, and present a case study demonstrating the recovery of missing synchrophasor data by implementing a matrix completion algorithm on the switch data plane. The recovery scheme is evaluated in a container-based P4 network emulator using real PMU data from a campus microgrid. For instance, in the 10% missing data scenario, the recovery scheme can achieve a mean absolute percentage error of 0.038% for voltage magnitude and a phase angle error discrepancy of around 0.08 degrees.
The escalating cyber-attacks targeting power infrastructure underscore the critical importance of smart grid security. However, existing solutions often struggle with the challenge of balancing security and performance overhead, leading to suboptimal protection or increased operational latency. To address this, we propose an intrusion detection system (IDS) designed to operate within P4-based programmable network devices, enabling real-time identification of critical attacks like distributed denial-of-service (DDoS) and false data injection (FDI). Central to our approach is a novel data structure optimized for time series data, capturing key information such as packet timing and data payload distribution. Leveraging decision trees, a robust machine learning technique, enables effective anomaly detection and prediction. Additionally, we integrate data compression techniques to reduce device memory usage while maintaining detection accuracy. Our evaluation results demonstrate minimal overhead in packet processing speed with 1 to 20 nanoseconds differences per packet, and enhanced data storage efficiency with compression ratios reaching up to 60.9%. Despite these optimizations, there is only a slight decrease in detection accuracy, such as a 2.81% drop in detecting false data injection attack (FDIA).
Co-simulation is a powerful technique integrating various simulation tools to create a unified simulation environment. It provides an in-depth understanding of the interplay between cyber and physical infrastructures in industrial control systems like smart grids. HELICS is a framework that facilitates co-simulation development by providing common interfaces to enhance simulators, synchronize their executions, and exchange information. In this paper, we propose HELICSAuto, a code instrumentation procedure that automates the integration of domain-specific simulators with HELICS APIs. HELICSAuto requires developers to label their source codes using a pre-defined syntax, after which an interpreter automatically instruments the code with minimal manual involvement. We demonstrate the effectiveness of HELICSAuto by successfully applying it to simulators based on PandaPower, PowerWorld, OPAL-RT, and PyDNP3 to create a transmission-distribution-communication co-simulation environment for complex smart grids.
There has been a growing concern regarding the security of industrial network protocols in Supervisory Control and Data Acquisition (SCADA) systems. These protocols are vulnerable to a plethora of security threats, including man-in-the-middle attacks, denial-of-service attacks, malformed packets, and other forms of abuse that exploit the vulnerabilities in protocol specifications. One of the widely used protocols is the Distributed Network Protocol 3 (DNP3), making it a crucial target for security enhancement efforts. In this paper, we explore programmable networks for security enhancement of SCADA systems, in particular, P4 switches that can be programmed to perform specified operations at the data plane level. We identify security needs and gaps in existing cyberattacks on DNP3-based SCADA systems and then explore various techniques on the P4 switches, such as packet header and payload inspection, filtering, hashing, and encryption, to combat security threats specific to the DNP3 protocol. We demonstrate that using programmable switches to improve DNP3 security can effectively detect, mitigate, and prevent various forms of attacks with three case studies that are specific to DNP3-based SCADA systems, including Length Overflow Attack (malformed packet), Event Buffer Flooding Attack (denial-of-service), and Config Corrupt Attack (man-in-the-middle attack).
Many details of cyber attacks occurred to Industrial Control Systems (ICS) such as power grids remain as a secret. To reveal those secrets and benefit a broad research community, we propose an original cyber-physical honeypot architecture that can seamlessly couple IT and OT components in an power grid. Specifically, we will provide high interaction with adversaries as physical processes of an ICS move forward, revealing attack strategies according to adversaries’ knowledge on physical trajectories of the target system. Our preliminary evaluations demonstrate that the proposed CPS honeypot can present realistic device fingerprints and application-layer payload that piggybacks meaningful measurements conforming to the physical model of a power grid. In addition, by leveraging runtime high-fidelity OPAL-RT simulator, our CPS honeypot causes small latency, at least one order of magnitude smaller compared to the existing work.
State estimation plays a critical role in power dis-tribution systems. However, the conventional state estimation commonly used in transmission systems cannot be applied to the distribution systems because of insufficient measurements. Even though machine learning methods have begun to demonstrate their capabilities to overcome this challenge, they are not capa-ble of explicitly incorporating distribution systems' topological information. This paper proposes EleGNN, an electrical-model-guided graph neural network (GNN), to perform power distri-bution system state estimation (DSSE). By explicitly considering physical topology, EleGNN enhances GNN with original node and edge feature propagation methods, allowing us to obtain accurate estimation results despite insufficient measurements and various topologies. Evaluations of six different power systems demonstrate significant improvement in state estimation accuracy than the method relying on general neural networks. Specifically, node-level mean square errors introduced by EleGNN are at least one order of magnitude smaller, even with up to 50% of missing measurements.
Reconnaissance is critical for adversaries to prepare attacks causing physical damage in industrial control systems (ICS) like smart power grids. Disrupting reconnaissance is challenging. The state-of-the-art moving target defense (MTD) techniques based on mimicking and simulating system behaviors do not consider the physical infrastructure of power grids and can be easily identified. To overcome these challenges, we propose physical function virtualization (PFV) that “hooks” network interactions with real physical devices and uses these real devices to build lightweight virtual nodes that follow the actual implementation of network stacks, system invariants, and physical state variations in the real devices. On top of PFV, we propose DefRec, a defense mechanism that significantly increases the effort required for an adversary to infer the knowledge of power grids’ cyber-physical infrastructures. By randomizing communications and crafting decoy data for virtual nodes, DefRec can mislead adversaries into designing damage-free attacks. We implement PFV and DefRec in the ONOS network operating system and evaluate them in a cyber-physical testbed, using real devices from different vendors and HP physical switches to simulate six power grids. The experimental results show that with negligible overhead, PFV can accurately follow the behavior of real devices. DefRec can delay adversaries’ reconnaissance for more than 100 years by adding a number of virtual nodes less than or equal to 20% of the number of real devices.
Cyberphysical systems (CPSs) are increasingly used in various application domains and face the threat of cyberphysical attacks. In this article, we discuss challenges in detecting these attacks. We use power grids and surgical robots to clarify our analysis, and we use this analysis to identify ongoing challenges and future research directions.
processes, adversaries can determine “attack-concept” operations to cause devastating physical disruptions without raising alarms [17]. For the attack on a Ukrainian power plant that caused a blackout affecting 225,000 residents [31], [32], security analysis directly indicates that “the strongest capability of the attackers was ... to perform reconnaissance operations required to learn the environment.” Reconnaissance allows adversaries to design attack strategies that cause physical damage (e.g., compromising measurement data or maliciously turning off circuit breakers).
The Internet of Things (IoT) introduces new attack surfaces to power grids through Wi-Fi-enabled high-wattage appliances, rendering security mechanisms ineffective. We propose a data-centric edge-computing infrastructure to host defend mechanisms in IoT clouds by integrating physical states in decentralized power-grid regions.
Detecting cyber attacks in the network environments used by Internet-of-things (IoT) and preventing them from causing physical perturbations play an important role in delivering dependable services. To achieve this goal, we propose in-network Honeypot based on Software-Defined Networking (SDN) to disrupt and mislead adversaries into exposures while they are in an early stage of preparing an attack. Different from traditional Honeypot requiring dedicated hardware setup, the in-network Honeypot directly reroutes traffic from suspicious nodes and intelligently spoofs the network traffic to them by adding misleading information into normal traffic. Preliminary evaluations on real networks demonstrate that the in-network Honeypot can have little impacts on the performance of IoT networks.
Though attackers aim to introduce different physical perturbations on power grids, they need to rely on periodic data acquisitions performed by control centers to estimate the physical state of the grid and thus to prepare for destructive activities. In this paper, we present Raincoat, which randomizes data acquisitions to disrupt and mislead attackers’ preparations. We transform one data acquisition into multiple rounds. In each round, we dynamically manipulate network flows in the control networks so that randomly selected “online” devices respond with real measurements. Meanwhile, we intelligently spoof measurements for other “offline” devices to mislead attackers into designing ineffective strategies. Based on experiments using large-scale power systems and six real wide area networks, Raincoat is effective against false data injection and control-related attacks with small overhead. The probability of successful attacks can be reduced from 70% to 1%; attacks introduce little damage even if they are executed. Network latency of data acquisition increases on average by less than 6%.
In this paper, we analyze control-related attacks in supervisory control and data acquisition systems for power grids. This class of attacks introduces a serious threat to power systems, because attackers can directly change the system's physical configuration using malicious control commands crafted in a legitimate format. To detect such attacks, we propose a semantic analysis framework that integrates network intrusion detection systems with a power flow analysis capable of estimating the execution consequences of control commands. To balance detection accuracy and latency, the parameters of the power flow analysis algorithm are dynamically adapted according to real-time system dynamics. Our experiments on IEEE 24-bus, 30-bus, and 39-bus systems and a 2736-bus system demonstrate that by opening three transmission lines, an attacker can put the tested system into an insecure state, and the semantic analysis can complete detection in 200 ms for the large-scale 2736-bus system with about 0.78% false positives and 0.01% false negatives, which allow for timely responses to intrusions.
Control-related attacks can use malicious commands crafted in legitimate formats to initiate perturbations to power systems. Our previous work used the steady state of power systems (e.g., through power flow analysis) to estimate the consequences of such commands [1]. However, when power systems move from one steady state to another, their physical components go through a transient period, during which the system state can experience oscillations. An anomaly in an oscillation can make power systems lose synchronisms and experience catastrophic consequences. Analysis based on the steady state cannot understand and predict those harmful oscillations. In this paper, we study the impacts of control-related attacks on the dynamic responses of a power grid, by mapping malicious commands (e.g., that disconnect transmission lines) delivered via communication networks to power systems' electromechanical models. Based on theoretical analysis and numerical simulations, we find that it is challenging for attackers to destabilize a power system, but they can introduce large oscillations in the transient period and thereby cause physical damage.
Many modern scientific applications involve large volumes of multidimensional data and extensive computation. Although distributed systems and tools are becoming increasingly scalable, they are still far away to catch up the exponential growth rate exhibited by many of those scientific big-data applications. This paper presents our early effort on overcoming the exponential complexity of one widely deployed workload over multidimensional scientific data—the n×n numerical analysis on two-dimensional arrays. More specifically, we propose a new approach to reduce the exponentially-grown data into a semantically-equivalent polynomial form in the context of two-dimensional electrode arrays, which are widely used in biomedical engineering, electrical engineering, and mechanical engineering. We have implemented a system prototype in Python, preliminary results show that the proposed approach outperforms the state-of-the-practice in various metrics: (i) the consumed space is six orders of magnitude smaller; (ii) the execution time is three orders of magnitude faster; and (iii) the scalability is improved by two orders of magnitude—from 6×6 to 100 × 100—on mainstream servers in reasonable time.
In this paper, we propose a self-healing phasor measurement unit (PMU) network that exploits the features of dynamic and programmable configuration in a software-defined networking infrastructure to achieve resiliency against cyber-attacks. After a cyber-attack, the configuration of network switches is changed to isolate the compromised PMUs/phasor data concentrators to prevent further propagation of the attack; meanwhile, the disconnected yet uncompromised PMUs will be reconnected to the network to “self-heal” and thus restore the observability of the power system. Specifically, we formulate an integer linear programming model to minimize the overhead of the self-healing process (e.g., the recovery latency), while considering the constraints of power system observability, hardware resources, and network topology. We also propose a heuristic algorithm to decrease the computational complexity. Case studies of a PMU network based on the IEEE 30-bus and 118-bus systems are used to validate the effectiveness of the self-healing mechanism.
In recent years, adversaries show the high intelligence to perform attacks against cyber-physical systems, such as power grids. They stay stealthily for a long period, learn physics about control systems, and use malicious commands crafted in legitimate formats to cause physical damage. Different from previous work, my research combines the knowledge of both cyber and physical infrastructures to detect the attacks and prevent the damage from happening. I designed network intrusion detection systems that use the physical model of power systems to detect malicious commands and a self-healing network to restore measurements from compromised power grid devices. In my current work, I propose Raincoat, which randomizes data acquisitions to disrupt attackers’ knowledge. Meanwhile, we intelligently spoof measurements to mislead attackers into designing ineffective strategies. Based on experiments using large-scale power systems and six real wide area networks, Raincoat is effective against false data injection and control-related attacks with small overhead. At the end of this presentation, I will present my future work that targets different attack model and uses the “big volume of small data” model to increase the resilience design. Bio: Hui Lin earned his B.S. degree from Huazhong University of Science and Technology in 2006 and his M.S. degree from the University of Illinois at Chicago in 2010, both in electrical and computer engineering. He is currently working toward his Ph.D. degree at the University of Illinois at Urbana-Champaign. His research interests include cyber security, intrusion detection systems, and software-defined networking (SDN). His Ph.D. research explores applying intrusion detection systems and SDN in critical cyber-physical systems, such as power grids, to increase their resilience against cyber attacks and accidental failures. He has successfully adapted Bro, a runtime network traffic analyzer, to support network protocols (e.g., DNP3) commonly used in power grid infrastructure. The DNP3 analyzer that he developed has been included in Bro and can be downloaded freely by utility companies. His current work focuses on applying SDN in cyber-physical systems; he intends to use SDN’s network programmability to design flexible cyber-physical systems which can preemptively prevent cyberattacks from introducing physical damage. Tuesday, April 4, 2017 @ 11:00 am McAdams Hall, Room 110E For more information on all upcoming School of Computing Spring 2017 Seminars, please visit www.cs.clemson.edu/socseminar/s2017/