1,721,008 research outputs found

    Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

    No full text
    The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications

    Managing dynamic groups in QoS and overlay multicasting

    Get PDF
    Multicasting has been the most popular mechanism for supporting group communication, wherein group members communicate through a multicast data distribution tree that spans all the members of the group. In a dynamic multicast session, members join/leave the group using graft/prune mechanisms, based on locally optimal paths, which would eventually degenerate the quality of the multicast tree. Therefore, efficient mechanisms need to be invoked periodically to maintain the cost of the multicast tree near optimal. However, tree maintenance would result in service disruption for the session. Therefore, there exists a trade-off between minimizing tree cost and minimizing service disruption. The goal of this dissertation is to develop and analyze a set of efficient tree maintenance techniques that aim to balance this tradeoff in QoS and overlay multicasting. To achieve this goal, the dissertation makes three key contributions. First, the design of scalable protocols, viz. tree migration and tree evolution, for maintaining QoS multicast trees. Second, the design of an efficient strategy, called partial protection approach, and its implementation methods for member join problem with path reliability being a QoS constraint. Third, the design of an efficient tree maintenance algorithm, based on the idea of mesh-tree interactions, for end-system based overlay multicasting. The proposed tree maintenance solutions have been evaluated and analyzed through a combination of simulation and analytical studies. The studies show that the proposed solutions indeed achieve a good balance between tree cost and service disruption competitively.</p

    Design of Attack-Resilient System for Wide-Area Monitoring, Protection, and Control in Smart Grid

    Get PDF
    Can you imagine that a simple cyber-attack can turn your lights off? Do you know more than a dozen U.S. utilities have been constantly targeted through cyber-attacks within the past year? The solution - an attack-resilient grid infrastructure that can quickly detect stealthy cyber-attacks and provide an intelligent incident response to restore the normal grid condition.This is a manuscript of an article published as Singh, Vivek Kumar, and Manimaran Govindarasu. "Design of Attack-Resilient System for Wide-Area Monitoring, Protection, and Control in Smart Grid." IEEE Smart Grid (2020). Posted with permission.</p

    Anomaly Detection and Mitigation for Wide-Area Damping Control using Machine Learning

    Get PDF
    In an interconnected multi-area power system, wide-area measurement based damping controllers are used to damp out inter-area oscillations, which jeopardize grid stability and constrain the power flows below to their transmission capacity. The effect of wide-area damping control (WADC) significantly depends on both power and cyber systems. At the cyber system layer, an adversary can inflict the WADC process by compromising either measurement signals, control signals or both. Stealthy and coordinated cyber-attacks may bypass the conventional cybersecurity measures to disrupt the seamless operation of WADC. This paper proposes an anomaly detection (AD) algorithm using supervised Machine Learning and a model-based logic for mitigation. The proposed AD algorithm considers measurement signals (input of WADC) and control signals (output of WADC) as input to evaluate the type of activity such as normal, perturbation (small or large signal faults), attack and perturbation-and-attack. Upon anomaly detection, the mitigation module tunes the WADC signal and sets the control status mode as either wide-area mode or local mode. The proposed anomaly detection and mitigation (ADM) module works inline with the WADC at the control center for attack detection on both measurement and control signals and eliminates the need for ADMs at the geographically distributed actuators. We consider coordinated and primitive data-integrity attack vectors such as pulse, ramp, relay-trip and replay attacks. The performance of the proposed ADM algorithms was evaluated under these attack vector scenarios on a testbed environment for 2-area 4-machine power system. The ADM module shows effective performance with 96.5% accuracy to detect anomalies.This is a manuscript of an article published as Ravikumar, Gelli, and Manimaran Govindarasu. "Anomaly Detection and Mitigation for Wide-Area Damping Control using Machine Learning." IEEE Transactions on Smart Grid (2020). DOI: 10.1109/TSG.2020.2995313. Posted with permission.</p

    ML-based anomaly detection for IoT Devices

    Get PDF
    Most IoT devices today are not built with security in mind. With Internet of Things devices seeing widespread adoption in areas with high economic importance, there is a need for anomaly detection taking place locally in devices and at odes. Attacks such as deauthentication attacks disruptive because it prevents sensors from receiving instructions and sending responses back. Designing an intrusion detection system that uses machine learning models is an approach that can help improve the detection of anomalies but the machine learning models have to efficient in resources, accurate, and precise. In this project, two ensemble learning techniques are proposed for use on botnet infected data from IoT devices. The two ensemble techniques used are stacked generalization, a stacking ensemble machine learning technique and AdaBoost, a boosting ensemble machine learning technique. The models created using stacked generalization and AdaBoost made use of a training and test split of 60:40. During the training and testing of both techniques, AdaBoost model demonstrated both excellent accuracy and low latency during training and generating predictions

    CAN-ADS: Machine Learning-based Anomaly Detection System for CAN Bus Network in Agriculture Machinery

    Get PDF
    The integration of advanced automation, Internet of Things (IoT), and next-generation communication technologies has accelerated the evolution of the food and agriculture sector, leading to enhanced productivity, precision, and efficiency in modern agricultural machinery. However, this rapid digitization also increases the vulnerability of these systems to cyber threats, particularly within the Controller Area Network (CAN), a core protocol that facilitates communication between Electronic Control Units (ECUs) in farm equipment. Despite its widespread use, CAN lacks native security features, rendering it susceptible to a wide array of cyber-attacks such as denial-of-service (DoS), spoofing, false data injection (FDI), and replay attacks. These attacks pose significant risks to the operational integrity, safety, and economic resilience of agricultural infrastructure. In this work, we introduce CAN-ADS, a robust, supervised machine learning (ML)-based anomaly detection system (ADS) designed to identify and classify cyber intrusions targeting CAN-based communication in agricultural machinery. CAN-ADS addresses the growing need for intelligent, real-time threat detection solutions tailored specifically for the operational context of smart farming and precision agriculture. The system is built on a hybrid dataset, meticulously curated from two sources: experimental CAN traffic collected from a Hardware-in-the-Loop (HIL) testbed environment at Iowa State University (ISU), and publicly available open-source datasets featuring diverse cyber-attack scenarios. The inclusion of HIL-based data enables the system to model real-world operating conditions and network dynamics within agricultural machinery, while the augmented datasets introduce broader attack variability and contextual diversity. To enhance the quality and representativeness of training data, the hybrid dataset undergoes preprocessing using advanced data augmentation techniques. Specifically, we employ the Synthetic Minority Oversampling Technique (SMOTE) to artificially generate new instances of underrepresented attack classes, thereby mitigating the skewed distribution typically found in intrusion detection datasets. This is complemented by Random Undersampling (RUS) of overrepresented classes to ensure a balanced learning environment. Together, these techniques help address the class imbalance problem that can compromise the generalization capability of ML models. The CAN-ADS framework is evaluated using five ML algorithms, Decision Trees, Random Forest, K-Nearest Neighbor, XGBoost, and Artificial Neural Networks, across baseline and augmented datasets. XGBoost achieves the highest testing accuracy (approx 97.7%), with low false negative rates (approx 1%), confirming the system’s effectiveness in identifying both overt and stealthy attack vectors. Additionally, experimental results highlight the real-time viability of the approach, with Decision Trees yielding the lowest inference latency (approx 0.1 seconds). This research lays the foundation for a deployable, real-time cybersecurity solution for smart farming, enhancing the security of agricultural machinery against an evolving threat landscape

    A Case for Mesh-Tree-Interaction in End System Multicasting

    Get PDF
    Abstract. End System Multicasting (ESM) is fast becoming a feasible alternative to IP multicasting. ESM approaches can be broadly classified into two main categories: (i) Tree first approaches, where an overlay tree is constructed on the physical network, (ii) Mesh first approaches, where a mesh is constructed on the physical network and then a tree is created on the constructed mesh. In this paper, we propose a generic Mesh Tree Interaction (MTI) mechanism, which combines the management efficiency of the mesh first approaches and the performance benefits of the tree first approaches. To achieve this, MTI uses the concept of mesh and enables interactions between the mesh and the underlying multicast tree. Our simulation studies show that MTI results in significant improvement in the quality (average delay metric) of the multicast tree

    A Novel Methodology for Cybersecurity Investment Optimization in Smart Grids using Attack-Defense Trees and Game Theory

    Get PDF
    Securing cyber-physical systems (CPS) like the Smart Grid against cyber attacks is making it imperative for the system defenders to plan for investing in the cybersecurity resources of cyber-physical critical infrastructure. Given the constraint of limited resources that can be invested in the cyber layer of the cyber-physical smart grid, optimal allocation of these resources has become a priority for the defenders of the grid. This paper proposes a methdology for optimizing the allocation of resources for the cybersecurity infrastructure in a smart grid using attack-defense trees and game theory. The proposed methodology uses attack-defense trees (ADTs) for analysing the cyber-attack paths (attacker strategies) within the grid and possible defense strategies to prevent those attacks. The attack-defense strategy space (ADSS) provides a comprehensive list of interactions between the attacker and the defender of the grid. The proposed methodology uses the ADSS from the ADT analysis for a game-theoretic formulation (GTF) of attacker-defender interaction. The GTF allows us to obtain strategies for the defender in order to optimize cybersecurity resource allocation in the smart grid. The implementation of the proposed methodology is validated using a synthetic smart grid model equipped with cyber and physical components depicting the feasibility of the methodology for real-world implementation.This proceeding is published as Hyder, Burhan, and Manimaran Govindarasu. "A Novel Methodology for Cybersecurity Investment Optimization in Smart Grids using Attack-Defense Trees and Game Theory." In 2022 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT), pp. 1-5. IEEE, 2022. DOI: 10.1109/ISGT50606.2022.9817467. Copyright 2022 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. Posted with permission
    corecore