Behind Closed Doors: Process-Level Rootkit Attacks in Cyber-Physical Microgrid Systems

02/20/2022
by   Suman Rath, et al.
0

Embedded controllers, sensors, actuators, advanced metering infrastructure, etc. are cornerstone components of cyber-physical energy systems such as microgrids (MGs). Harnessing their monitoring and control functionalities, sophisticated schemes enhancing MG stability can be deployed. However, the deployment of `smart' assets increases the threat surface. Power systems possess mechanisms capable of detecting abnormal operations. Furthermore, the lack of sophistication in attack strategies can render them detectable since they blindly violate power system semantics. On the other hand, the recent increase of process-aware rootkits that can attain persistence and compromise operations in undetectable ways requires special attention. In this work, we investigate the steps followed by stealthy rootkits at the process level of control systems pre- and post-compromise. We investigate the rootkits' precompromise stage involving the deployment to multiple system locations and aggregation of system-specific information to build a neural network-based virtual data-driven model (VDDM) of the system. Then, during the weaponization phase, we demonstrate how the VDDM measurement predictions are paramount, first to orchestrate crippling attacks from multiple system standpoints, maximizing the impact, and second, impede detection blinding system operator situational awareness.

READ FULL TEXT
research
06/05/2019

Investigation of Cyber Attacks on a Water Distribution System

A Cyber Physical System (CPS) consists of cyber components for computati...
research
12/13/2018

Cyber-Physical Security and Safety of Autonomous Connected Vehicles: Optimal Control Meets Multi-Armed Bandit Learning

Autonomous connected vehicles (ACVs) rely on intra-vehicle sensors such ...
research
09/06/2021

Towards an Approach to Contextual Detection of Multi-Stage Cyber Attacks in Smart Grids

Electric power grids are at risk of being compromised by high-impact cyb...
research
06/16/2018

Attack Surface Metrics and Privilege-based Reduction Strategies for Cyber-Physical Systems

Cybersecurity risks are often managed by reducing the system's attack su...
research
03/16/2023

DeeBBAA: A benchmark Deep Black Box Adversarial Attack against Cyber-Physical Power Systems

An increased energy demand, and environmental pressure to accommodate hi...
research
07/06/2018

CoMID: Context-based Multi-Invariant Detection for Monitoring Cyber-Physical Software

Cyber-physical software continually interacts with its physical environm...
research
01/18/2021

Multi-Source Data Fusion for Cyberattack Detection in Power Systems

Cyberattacks can cause a severe impact on power systems unless detected ...

Please sign up or login with your details

Forgot password? Click here to reset