Source-linked AI summary

Microgrid Resilience: A holistic approach for assessing threats, identifying vulnerabilities, and designing corresponding mitigation strategies

Sakshi Mishra, Kate Anderson, Brian Miller, Kyle Boyer, Adam Warren

arXiv:1910.01234v2eess.SYeess.SP

TL;DR

Microgrids can provide backup power during grid outages, but their resilience depends on addressing physical, cyber, communications, and interdependency threats. This paper reviews threats and vulnerabilities, develops risk-assessment and mitigation approaches, and proposes an iterative design process for selecting resilient microgrid features. Its example prioritizes flooding protection, storm preparedness, and cyber-defense software according to calculated risks.

  • Problem

    Microgrids may be vulnerable to physical, communications, cybersecurity, and interdependency threats despite supporting resilience during utility-grid outages.

  • Method

    The paper integrates threat categorization, vulnerability identification, quantitative risk modeling, and physical, cyber, communications, infrastructural, and operational mitigation strategies.

  • Results

    The example risk assessment prioritizes flooding protection, storm preparedness, and cyber-defense software features for the test microgrid.

  • Takeaways & Limitations

    Resilient microgrid design should use assessed threats, vulnerabilities, and consequences to select mitigation measures and repeatedly update them through validation and reassessment.

Abstract

from arXiv · show

Microgrids are being increasing deployed to improve the operational flexibility, resilience, coordinated-energy management capabilities, self-adequacy, and increased reliability of power systems. This strong market growth is also driven by advances in power electronics, improved control systems, and the rapidly falling price and increased adoption of distributed energy generation technologies, like solar photovoltaics and storage. In the event of grid outages, microgrids can provide a backup source of power; providing resilience to the critical loads; however, this requires that the microgrid itself is resilient to physical and cyber threats. Building highly resilient microgrids requires a methodological assessment of potential threats, identification of vulnerabilities, and design of mitigation strategies. This paper provides a comprehensive review of threats, vulnerabilities, and mitigation strategies and develops a definition for microgrid resilience. The paper also develops a methodology for designing resilient microgrids by considering how microgrid designers and site owners evaluate threats, vulnerabilities, and consequences and choose the microgrid features required to address these threats under different situations.

A. Motivation and Background

Microgrids support localized power resilience, but their design must account for diverse natural, human-induced, physical, cyber, and communications threats. A comprehensive evaluation links event severity, vulnerabilities, consequences, and mitigation choices.

  • Critical infrastructure and economic activity depend on continuous electricity, making reliable power supply essential for societal well-being and development.
  • Extreme weather, earthquakes, and human-induced attacks can cause widespread outages with cascading effects across interconnected infrastructure.Examples include Hurricane Sandy, snowstorms in Southern China, and the 2018 Hokkaido earthquake.
  • Resilience planning evaluates event types and severity, selects relevant metrics and assessment methods, estimates lost-load consequences, and combines hardening with operational strategies.
  • Microgrids can reduce exposure to utility-grid failures by operating locally and separating into island mode during disturbances.Their localized architecture uses fewer transmission and distribution lines than the utility grid.
  • Microgrids remain vulnerable to local weather impacts, communications failures, and cybersecurity events when improperly designed.

B. Literature Review

Prior work often addresses one dimension of microgrid resilience at a time. This paper instead integrates threat categorization, vulnerability assessment, quantitative risk modeling, and physical, cyber, communications, and operational mitigation strategies.

  • Risk assessment is presented as the starting point for systematically identifying threats and estimating the severity of associated vulnerabilities.
  • Existing studies address individual aspects of microgrid resilience, including windstorms, hurricanes, electric-spring controls, and cybersecurity threats.
  • The paper develops a holistic qualitative approach covering physical, controls, cyber, and communications dimensions of microgrid threats and vulnerabilities.
  • Its contributions include categorizing threats, presenting quantitative threat modeling, determining vulnerabilities, and proposing design and operational mitigation strategies.
  • The paper distinguishes resilience from reliability while also considering reliability aspects of microgrid performance.

A. Reliability

Microgrid reliability concerns the dependable operation of components and communications, whereas resilience addresses adaptation, endurance, and recovery from disruptive events. The paper frames resilience analysis as an iterative process that updates designs as new vulnerabilities emerge.

  • A. Reliability: Reliability uses established industry metrics and concerns continuity and quality of electricity supply during shorter disturbances and outages.
  • A. Reliability: Microgrid reliability is constrained by limited generation and potentially uneconomic component redundancy, increasing the importance of testing and preventive maintenance.
  • A. Reliability: Reliability includes failures in utility-grid communications, internal controller-to-asset communications, and coordination among distributed controllers.
  • B. Resilience: Resilience encompasses adaptation, endurance, and recovery from low-probability, high-impact events affecting systems across larger regions and longer durations.
  • B. Resilience: Resilience analysis and deployment is iterative: designs are tested, performance is evaluated, and features are upgraded when disasters or cyberthreats reveal new vulnerabilities.

III. METHODOLOGY FOR ASSESSING THREATS AND ASSOCIATED VULNERABILITIES

The methodology distinguishes site-specific threats from controllable vulnerabilities, then quantifies risk by combining threat likelihood, vulnerability exploitation probability, and impact. It also aligns physical and cyber risk assessment while supporting geographically and temporally responsive decision-making.

  • A. Threats: Threats are identified from climate data, hazard assessments, and stakeholder interviews, with examples summarized in Table 1.
  • B. Vulnerabilities: Vulnerabilities are controllable weaknesses in infrastructure or processes identified through stakeholder interviews, contingency plans, and post-event reports.
  • C. Risk and its Assessment: Risk factor combines threat probability, vulnerability-exploitation probability, and vulnerability impact.The stated impact measure is the average of damage and affected users.
  • C. Risk and its Assessment: Threat likelihood, vulnerability probability, and impact scores are multiplied for each threat-vulnerability combination to produce a risk score.
  • C. Risk and its Assessment: Physical component failures without external threats are treated as reliability concerns, whereas system-level external-threat assessment gauges microgrid resilience.
  • C. Risk and its Assessment: STRIDE identifies cyber threat categories, while DREAD scores damage potential, reproducibility, exploitability, affected users, and discoverability.The physical and cyber models are loosely aligned by comparing threat probability with reproducibility and exploitability.

IV. THREATS TO MICRO (AND MACRO) GRIDS AND ASSOCIATED VULNERABILITIES

Microgrid threats and vulnerabilities span multiple resilience domains in a cyber-physical system. The paper distinguishes physical, cyber, and communications resilience as complementary dimensions.

  • Threat modeling for a complex microgrid begins by defining and diagramming the system, identifying failures, developing mitigations, and validating conclusions.
  • Physical resilience sustains infrastructure during disruption and restores operations rapidly afterward.
  • Cyber resilience defends against cyberattacks while maintaining safe performance during the event.
  • Communications resilience maintains safe and stable operations during communications failures.

A. Physical Threats

Physical and cyber threats can disrupt microgrid assets, controls, data, and power availability. Because microgrids combine infrastructure, electronic controls, sensors, networks, and supervisory systems, interfaces create attack surfaces requiring analysis.

  • Physical threats: Physical threats include natural hazards, climate-driven extremes, and human-induced attacks such as terrorist attacks against substations.
  • Physical threats: Flooding, wind, earthquakes, lightning, wildfires, heatwaves, and winter storms can damage equipment, overload systems, or trigger outages and load-shedding.
  • Cyber threats: Cyberattacks target availability, integrity, or confidentiality, including delayed messages, inaccurate controller inputs, and stolen operational or bidding data.
  • Cyber threats: A microgrid’s cyber-physical architecture links generation, storage, distribution, loads, controls, sensors, networks, and supervisory systems for real-time coordination.
  • Cyber threats: Each interface or trust boundary is a potential attack surface, and Table 4 summarizes vulnerable surfaces and threat types affecting operations.
  • Cyber threats: Advanced controls and analytics create cyber-reliability concerns because algorithmic complexity can produce unforeseen behavior and software sophistication can introduce bugs.These internally arising challenges are treated as reliability issues rather than external threats requiring resilience solutions.

C. Communications Failure Threats

Communications are integral to microgrid control and coordination, but failures can prevent commanded operation and contribute to cascading impacts. Interdependencies with other critical infrastructures add second- and third-order vulnerabilities.

  • C. Communications Failure Threats: Greater connectivity supports responsive operations and energy management but expands vulnerable cyber surfaces.
  • C. Communications Failure Threats: The 2013 Northeast blackout illustrates how a communication failure delayed an alarm and prevented timely redistribution of power flow.
  • C. Communications Failure Threats: During grid-connected operation, communication loss can prevent the controller from maintaining commanded power and power factor at the point of interconnection.
  • D. Threats Due to Interdependencies Between Various Systems: Microgrids depend on natural gas, oil, telecommunications, transportation, and water systems, while those systems also support microgrid operations.
  • D. Threats Due to Interdependencies Between Various Systems: These interdependencies expose microgrids to second-order and third-order threats because integrated gas, water, generation, and grid supplies are coordinated.
  • D. Threats Due to Interdependencies Between Various Systems: Interdependency risk uses the same multiplicative risk-factor method as physical threats: threat probability, vulnerability probability, and vulnerability impact.

V. CASE STUDY: EXAMPLE RISK SCORE CALCULATION

The case study integrates physical and cyber risk assessment because microgrids are cyber-physical systems. A coastal test site illustrates how threat likelihood, vulnerability probability, and impact combine into a risk score.

  • The example microgrid combines physical and cyber risk factors to evaluate resilience holistically and prioritize mitigation measures.The integrated assessment is intended to identify measures with the greatest effect on resilience.
  • A Florida coastal test site evaluates hurricane flooding of generators, including ground-mounted solar and battery storage.The scenario assumes a 90% hurricane probability and a 70% flooding probability if a hurricane reaches the site.
  • Risk factor calculation uses threat likelihood, vulnerability probability, and vulnerability impact for each threat-vulnerability combination.These three attributes are represented in the physical threat and vulnerability scoring framework.
  • The hurricane-flooding scenario produces a total risk score of 567, classified as high risk because likelihood and potential damage are high.The calculation is 9 x 7 x 9 = 567, using scores for threat probability, vulnerability probability, and impact.

B. Cyber

The cyber case study applies threat scoring to three attacks targeting an unencrypted wireless link. It contrasts low-priority eavesdropping with more severe jamming and data-injection threats.

  • The example system contains an inverter-based generator, loads with voltage and frequency sensors, and a supervisory controller connected through a wireless link.The system is deliberately insecure so cyber-vulnerability scoring remains simple.
  • Eavesdropping is a moderate but low-priority threat because its damage potential is very low and it requires substantial knowledge.The attack uses inexpensive equipment and can be conducted by an unauthenticated user, but analyzing the data requires significant knowledge.
  • Signal jamming is more severe than eavesdropping because it can reliably disrupt controller visibility, has higher impact, and requires little system knowledge.The example assumes it does not directly cause permanent damage or compromise normal stability.
  • Incorrect frequency or voltage feedback can damage loads or shut down generation, but its severity is moderated by low operating probability and substantial resource requirements.This tampering attack assumes the attacker already has detailed knowledge of the loads and network stability.
  • The three cyber attacks are assessed with DREAD across Damage Potential, Reproducibility, Exploitability, Affected Users, and Discoverability.The scores are averaged to produce a numerical risk score, while the attacks share the unencrypted wireless-link vulnerability.

C. Overall Risk Factor Calculation: Cyber-Physical System

The overall risk calculation combines physical and cyber threat-vulnerability assessments for the test microgrid. Its results prioritize flooding protection, storm preparedness, and software defenses according to calculated risk.

  • Table 10 calculates example risk scores as a function of threat probability, vulnerability probability, and vulnerability impact.The combinations cover input threats and vulnerabilities for the example test microgrid.
  • The example risk values are approximate and intended for illustration rather than use as risk factors for actual microgrid design.The paper explicitly limits these numbers to demonstration purposes.
  • Figure 7 visualizes risk scores in a 3D bar plot, using bar colors to represent threat probability qualitatively.The plot shows relative differences among physical and cyber threats while retaining risk score as the dependent variable.
  • The mitigation strategy prioritizes elevating generators for flood protection and maintaining spare-parts inventories for storm preparedness over seismic design.This prioritization is based on calculated risk factors for the example microgrid and its hurricane scenario.
  • Cyber risks are relatively higher for the test microgrid, prompting priority for software features that defend against cyber threats.The recommendation concerns this test microgrid system rather than a general quantitative ranking.

VI. MITIGATION STRATEGIES

The paper proposes mitigation strategies that reduce vulnerability risk while balancing adoption complexity and cost. Measures span infrastructure and operations before, during, and after disasters.

  • Mitigation options are evaluated by their potential to reduce risk relative to the complexity and cost of adoption.Strategies that reduce risk through multiple pathways should receive consideration.
  • VI. MITIGATION STRATEGIES: The framework organizes mitigation into pre-disaster planning, during-disaster measures, and post-disaster recovery and restoration.It combines infrastructural and operational measures across all three phases.
  • VI. MITIGATION STRATEGIES: Pre-disaster planning assesses threats and vulnerabilities and implements physical hardening and cyber strengthening to reduce damage probability.Preparation may also include restocking supplies and relocating vehicles before extreme weather or elevated threat levels.
  • VI. MITIGATION STRATEGIES: During disasters, operators may deliberately de-energize systems, isolate damaged lines, and verify the availability of essential staff.These actions are intended to limit damage and maintain supply to critical loads where possible.
  • VI. MITIGATION STRATEGIES: System hardening includes diversified generation, renewable resources, storage, and UPS equipment for critical-service microgrids.Diversification can also reduce operating costs for island microgrids when transported generator fuel is expensive or risky.
  • VI. MITIGATION STRATEGIES: Cyber resilience measures include more sophisticated controls and analytics, default node behavior during communication loss, firewalls, redundant links, encryption, and signed communications.These measures target denial of service, intrusion, eavesdropping, tampering, spoofing, and total communication loss.
  • VI. MITIGATION STRATEGIES: Routine resilience operations include asset monitoring, predictive and condition-based maintenance, and checklist-driven maintenance schedules.Analytics can flag fault-prone equipment for repair or replacement and support component reliability.

B. Response During-Disaster Event

During disruptive events, microgrids should preserve critical loads through coordinated demand reduction, backup activation, and generation scheduling, then restore operations rapidly after the event.

  • Predictable disruptive events require operational steps that enable microgrids to serve critical loads at minimum.
  • Demand-side load shedding turns off non-critical loads while activating uninterruptible power supply resources.
  • For grid-connected microgrids, on-site generation can be rescheduled to dispatch later because a utility outage is a probable post-disaster threat.
  • After an event, proactive response and faster recovery require sufficient redundancy and operational plans for rapid restoration.
  • Rapid restoration can be supported by spare-parts inventories, commercial off-the-shelf equipment, and modularized circuit designs.
  • Operational plans should document and train staff for black starts, provide controlled equipment cool-down, and coordinate grid resynchronization.

D. Deployment Considerations

Deployment considerations combine holistic threat assessment with prioritized mitigation, iterative validation, and practical attention to investment constraints and future resilience metrics.

  • Capital-investment justification remains difficult, and inadequate utility-owner information sharing can limit cyber defense visibility into utility conditions.
  • Because resources and budgets are constrained, mitigation priorities should consider risk reduction, deployment difficulty, and capital investment cost.
  • The deployment process iterates through action-plan development, implementation, validation before disasters, and reassessment as external circumstances change.
  • The approach identifies physical, cyber, communications, and critical-infrastructure interdependency threats and determines vulnerabilities for grid-connected and islanded operation.
  • Mitigation strategies span pre-disaster, during-disaster, and post-disaster recovery modes, including system hardening and operational effectiveness measures.
  • Mitigations are classified by the microgrid attributes they enhance: robustness, redundancy, resourcefulness, response, and recovery.
  • Future work will develop resilience metrics to support economic feasibility assessments of technology and operational options.
Loading 1910.01234v2…