Source-linked AI summary
Cyber-Physical Energy Systems Security: Threat Modeling, Risk Assessment, Resources, Metrics, and Case Studies
Ioannis Zografopoulos, Juan Ospina, XiaoRui Liu, Charalambos Konstantinou
TL;DR
Mission-critical CPES are exposed to attacks that can evade conventional fault detection, creating a need for structured security analysis. The paper combines adversary and attack modeling with testbed-oriented resources, metrics, simulation, and risk assessment, then illustrates the approach across four CPES attack scenarios. The resulting risk scores support comparison, ranking, and prioritization of attack severity, while the framework provides guidelines for rigorous CPS security analysis.
Problem
Intentional faults can alter system results congruently and evade detection, while CPES risk assessment is important for mission-critical operations.
Method
The paper constructs adversary and attack models, specifies CPS modeling resources and metrics, and evaluates CPES scenarios through simulation and risk assessment.
Results
Four CPES attack case studies produce relative risk scores that enable comparison, ranking, and prioritization of potential disruptions.
Takeaways & Limitations
The framework provides guidelines for modeling CPS threats and designing, simulating, and evaluating detailed CPS security analyses.
Takeaways & Limitations
Future work is needed to extend the framework for autonomous CPES operation and simulation-aided risk assessment.
Abstract
from arXiv · showhide
Cyber-physical systems (CPS) are interconnected architectures that employ analog, digital, and communication resources for their interaction with the physical environment. CPS are the backbone of enterprise, industrial, and critical infrastructure. Thus, their vital importance makes them prominent targets for malicious attacks aiming to disrupt their operations. Attacks targeting cyber-physical energy systems (CPES), given their mission-critical nature, can have disastrous consequences. The security of CPES can be enhanced leveraging testbed capabilities to replicate power system operations, discover vulnerabilities, develop security countermeasures, and evaluate grid operation under fault-induced or maliciously constructed scenarios. In this paper, we provide a comprehensive overview of the CPS security landscape with emphasis on CPES. Specifically, we demonstrate a threat modeling methodology to accurately represent the CPS elements, their interdependencies, as well as the possible attack entry points and system vulnerabilities. Leveraging the threat model formulation, we present a CPS framework designed to delineate the hardware, software, and modeling resources required to simulate the CPS and construct high-fidelity models which can be used to evaluate the system's performance under adverse scenarios. The system performance is assessed using scenario-specific metrics, while risk assessment enables system vulnerability prioritization factoring the impact on the system operation. The overarching framework for modeling, simulating, assessing, and mitigating attacks in a CPS is illustrated using four representative attack scenarios targeting CPES. The key objective of this paper is to demonstrate a step-by-step process that can be used to enact in-depth cybersecurity analyses, thus leading to more resilient and secure CPS.
I. INTRODUCTION
CPES integrate physical power infrastructure with digital, communication, and control resources, creating important security challenges for mission-critical operations. The paper addresses these challenges through threat modeling, risk assessment, testbed resources, and illustrative attack studies.
- A. Background and Motivation: CPES combine physical entities with human, digital, and networking components to modernize electric power system operation.
- A. Background and Motivation: CPES security must protect critical resources and exchanged information, including generation reserves, frequency controls, line protection, and SCADA signals.
- A. Background and Motivation: The paper motivates realistic CPES evaluation because attackers may target systems important to economic prosperity and public health, while risk quantification becomes more complex as interconnections expand.
- B. Research Contribution and Overview: Its methodology combines adversary and attack models to evaluate malicious strategies and identify relevant attack entry points, techniques, capabilities, and objectives.
- B. Research Contribution and Overview: The proposed risk assessment considers attack effectiveness, targeted components, and the criticality of the compromised cyber-physical process.
- B. Research Contribution and Overview: A CPS framework specifies modeling techniques, resources, and evaluation metrics, and four CPES attack case studies demonstrate its practical application.
A. CPES Testbeds
CPES testbeds combine simulation and physical resources to study system behavior, security, and mitigation without directly affecting the operational grid. Hardware, software, and hybrid architectures trade realism and fidelity against cost, flexibility, and scalability.
- A. CPES Testbeds: CPES testbeds support evaluation of new equipment, control strategies, mitigation methods, cyber metrics, and security mechanisms without impacting the actual power system.
- A. CPES Testbeds: Hardware-assisted testbeds enable practical studies, abnormal-scenario evaluation, and predeployment testing of attack or fault mitigation strategies.
- A. CPES Testbeds: Hardware-assisted testbeds are costly, difficult to modify or expand, and difficult to scale because they require field-equivalent equipment.
- A. CPES Testbeds: Software-assisted testbeds use simulators such as Matlab/Simulink, PowerWorld, PSSE, Opal-RT, RTDS, Typhoon, and Speedgoat, offering greater flexibility and scalability than hardware-based systems.
- A. CPES Testbeds: Hybrid testbeds bridge hardware and software by combining physical transmission or distribution components with simulators and software suites representing real energy-system behavior.
- A. CPES Testbeds: HELICS integrates real-time simulators operating at different time steps and interconnects transmission and distribution components for cybersecurity assessment and impact analysis.
B. CPES Security Studies
Existing CPES security studies examine vulnerability exploitation, attack impacts, detection, and mitigation across increasingly decentralized and interconnected energy systems. Reported examples include attacks on dispatch, inverters, and network-connected loads.
- CPES security research is organized around vulnerability exploitation, attack-impact evaluation, attack detection, and mitigation or defense mechanisms.
- Decentralized CPES integrate distributed generation, storage, and geographically dispersed ICT equipment, increasing the interdependencies relevant to security studies.
- Coordinated load redistribution attacks can falsify load demand and line flows, misleading operators into increasing load curtailment.
- Stealthy attacks on grid-tied inverters can spoof Hall sensors and alter output voltage, active power, and reactive power.
- Network-coordinated attacks on high-wattage IoT loads can create unexpected power-use profiles and push the grid toward instability without strong adversarial knowledge or substantial resources.
2) Evaluation of Attack Impacts on CPES:
CPES security assessment combines attack-impact analysis, detection, mitigation, threat modeling, and risk-oriented methods to examine consequences across cyber and physical system components. The reviewed approaches emphasize critical assets, operational effects, and adversarial behavior before and after compromise.
- Attack-impact studies assess malicious effects on CPES operation to expose critical components, prioritize protection, and support contingency planning.
- Compromised IEDs, AMI, smart inverters, switching devices, and monitoring devices can produce adverse grid consequences or impede situational awareness.
- Open-source intelligence and contingency analysis can identify critical system paths that adversaries may exploit to maximize cyber-attack impact.
- Attack-impact assessment is intended to support CPES evaluation and should be used within a defense-in-depth portfolio for devising defense strategies.
- Detection mechanisms improve operator situational awareness so remediation actions can help avoid system and equipment failures and protect human safety.
- Hardware and software mitigation mechanisms include battery energy storage support, hardware security primitives, and real-time instrumentation-based defenses, although applicability varies by attack scenario.
- STRIDE, DREAD, and OCTAVE support pre-attack vulnerability and threat analysis, while MITRE ATT&CK addresses adversary behavior after initial access.
2) Risk Assessment:
CPES risk assessment must account for cyber-physical interdependencies, attack effects, and adversary behavior rather than evaluating isolated components. The proposed methodology combines detailed system representation, threat modeling, resource mapping, and impact-oriented risk scoring to prioritize mitigations.
- CPES risks arise across cyber and physical domains because interconnected ICT infrastructure supports components such as EVs and control devices.
- Probabilistic risk methods use Markov chains, Petri nets, Bayesian belief networks, or game theory to estimate adverse-event impacts on system operation.
- These methods can be computationally intensive and potentially inaccurate when CPES components, topology, and cyber interconnections are not modeled precisely.
- Segmented risk evaluations can mask cross-layer dependencies and fail to capture impacts propagating through the broader infrastructure.
- The proposed methodology combines attack Threat Probability with CPES objective priorities to calculate Risk scores and iteratively evaluate mitigation policies against Risk goals.
- Traditional fault detection may overlook intentional faults whose effects can evade detection without a threat model covering malicious adversaries and sophisticated attacks.
- The approach incorporates an adversary model, specifies attacks for CPS testbed implementation, and accounts for attacked components in impact-based Risk scores.
- The threat model comprises adversary and attack models, prioritizing threats according to the degradation they can potentially inflict on the CPS.
A. Adversary Model
The adversary model characterizes attackers by their knowledge, resources, access, and specificity, while the attack model captures how attacks target and compromise CPS components.
- Adversary knowledge: The knowledge hierarchy extends from no system-model information to knowledge of model characteristics, algorithmic details, and grid measurements.
- Access and specificity: Access represents the degree of interaction with system assets, while specificity captures the adversary’s objectives and goals.
- Adversary dimensions: The attacker model is decomposed into adversarial knowledge, resources, access, and specificity.
- Adversary knowledge: Adversary knowledge ranges from black-box ignorance through gray-box partial understanding to white-box knowledge of models, parameters, and states.
- Attack dimensions: The attack model describes frequency, reproducibility and discoverability, functional level, targeted asset, techniques, and attack premise.
- Attack paths: Attack paths may begin at sensors or actuators and propagate toward supervisory equipment such as HMIs.
- Attack techniques: Module-firmware attacks upload modified code to embedded devices such as PLCs and smart inverters, altering control objectives or adding backdoors.
C. Risk Assessment Methodology
The risk methodology combines threat probability with application-aware damage, using system objectives and attack impacts to prioritize CPES risks. It is integrated with a broader framework of models, resources, and metrics for CPES studies.
- Motivation: Risk assessment is especially important for mission-critical CPS because operational disruptions can have disastrous impacts.
- Motivation: Existing IT-oriented risk methods may miss OT-specific concerns including operational loss, asset availability, communication latency, and contingency management.
- Hybrid assessment: The hybrid method assesses attack impacts qualitatively while quantitatively weighting objective priorities and threat probabilities.
- Hybrid assessment: Objective priorities and threat probabilities can change during real-time operation, allowing the risk model to adapt to system conditions.
- Risk formulation: Risk scores are prioritized according to affected CPS objectives, while vulnerable assets indicate attack feasibility.
- Risk formulation: Risk equals Threat Probability multiplied by Damage, with threat probability incorporating threat details and system-context likelihood.
- Damage calculation: Damage combines objective priority with qualitative attack impact, where impact values 1, 2, and 3 represent Low, Medium, and High impact.
- Damage calculation: In the example, P(4 + 9 + 6 + 2) = 21 gives the total potential damage score before applying a specific Threat Probability.
A. Modeling
The modeling framework represents both cyber and physical CPES layers, selecting techniques that reproduce component behavior and communication structure. Physical modeling emphasizes EMT, TS, and hybrid simulation, while cyber modeling represents network entities, links, protocols, and evaluation utilities.
- Physical-system modeling: CPES models reproduce components such as PV systems, wind systems, storage, transformers, lines, smart meters, PMUs, routers, and switches.
- Framework overview: The framework separates cyber-system and physical-system layers and identifies modeling factors needed for CPES investigations.
- Physical-system modeling: EMT simulation captures fast events occurring over tens of microseconds or less using nonlinear ordinary differential equations.
- Physical-system modeling: TS simulation captures slower dynamics, while hybrid TS+EMT simulation combines both tools for more comprehensive studies.
- Cyber-system modeling: Cyber-layer modeling covers communication infrastructure, protocols, information systems, and data storage processing.
- Cyber-system modeling: Network simulation and emulation identify nodes and links that constitute the modeled topology.
- Cyber-system modeling: Nodes represent connected computing devices, while interfaces, queues, and links model packet transmission and communication conditions.
- Cyber-system modeling: Protocol entities manage packet headers, and logging or helper utilities support network performance evaluation.
B. Resources
The resources framework distinguishes hardware and simulation or emulation systems for representing CPES cyber and physical layers. It includes offline simulation, network emulation, and performance metrics for evaluating modeled operation.
- Resource categories: Resources comprise hardware and software systems used to model and simulate CPES cyber and physical layers.
- Physical-layer resources: Physical-layer resources include EMT and TS simulation tools for investigating electric-power-system component behavior.
- Physical-layer resources: Offline simulation runs models slower or faster than real time on generic computing devices, without synchronizing computation to the real-time clock.
- Cyber-layer resources: Cyber-layer resources include simulation or emulation systems that respectively replicate modeled behavior or duplicate networking-component behavior.
- Cyber-layer resources: Network emulation configures parameters such as packet loss, delays, and jitter to mimic an external network.
- Evaluation metrics: Performance metrics quantitatively evaluate operation at both cyber and physical layers and their subsystems.
- Evaluation metrics: Physical-layer metrics include control-system measures such as steady-state response and rise time.
2) Cyber-System Layer:
The cyber-system layer is evaluated with communication-network metrics organized across OSI layers and tailored to study requirements. Researchers should select metrics that accurately represent the modeled cyber and physical layers.
- Cyber-system layer: Communication-network performance metrics are demonstrated across OSI layers, including transport through application layers.These layers cover shared communication protocols and node interfacing methods that provide end-user access to network infrastructure.
- Cyber-system layer: The listed metrics represent only a subset of available network and physical performance measures.Application-specific metrics can also be defined according to each study’s requirements.
- Cyber-system layer: Researchers should model systems carefully and select corresponding resources and metrics to represent CPES cyber and physical layers accurately.
V. EXPERIMENTAL SETUP & CASE STUDIES
The case studies apply a common CPES analysis process that combines threat modeling, mathematical plant formulations, modeling resources, and performance metrics. DIA modifies or fabricates measurements or controls, whereas DAA interrupts their acquisition or use.
- Framework application: Each case study is formalized through threat modeling, modeling layers, resources, evaluation metrics, and scenario-specific analysis.The framework is used to describe how each study is represented and evaluated.
- Attack formulation: The case studies characterize attacks as either deceptive integrity attacks or data availability attacks.
- Plant formulation: The CPS plant formulation represents system states, control variables, measurements, system matrices, and measurement noise.The state-space notation identifies x(k), u(k), y(k), G, B, C, and e for the physical system.
- Plant formulation: The cyber component is expressed with a control matrix H that links the cyber-side formulation to the control variables.
- Attack formulation: DIA compromises measurements or controls through modification or fabrication, while DAA compromises them through interruption or delayed acquisition or use.
A. Case Study 1: Cross-layer Firmware Attacks
The cross-layer firmware case study models malicious modification of a solar inverter’s embedded control logic and traces its effects from converter operation to microgrid stability. The study evaluates frequency and voltage stability while assessing attack risk and modeling assumptions.
- Background & formulation: Cross-layer firmware attacks target embedded-device firmware to propagate effects from the device layer across system layers.The case study focuses on a solar inverter controller and iterative, reproducible control-logic modification.
- Background & formulation: The attack is formulated as a combined DIA that modifies sensed measurements through multiplicative and additive attack terms during an attack period.β > 1 represents increasing attacks, whereas β < 1 represents decreasing attacks.
- Attack setup: Attackers can tamper with MPPT firmware subroutines controlling the inverter’s DC-DC boost and DC-AC conversion stages.The attack targets the MPPT controller and can disrupt nominal inverter operation.
- Results: Perturbing PV measurements can compromise MPPT operation and eventually disconnect the inverter-enabled power resource to protect other microgrid devices.
- Results: Malicious inverter behavior affects microgrid power, voltage, and frequency most strongly during significant load increases when solar generation is high.The study evaluates frequency and voltage stability as physical-system-layer metrics.
- Risk assessment: The study assumes physical-device compromise, so it does not model the cyber-system layer; an over-the-air extension would require communication-network modeling.
B. Case Study 2: Load-changing attacks
The load-changing case study models remote manipulation of IoT-connected loads and DERs in the IEEE-39 bus system and evaluates resulting generator-frequency changes. Increasing the number and magnitude of targeted loads produces broader and stronger frequency effects, with risk estimated at 28.
- Background & formulation: Load-changing attacks manipulate controllable high-wattage appliances or DERs to create sudden demand changes that can destabilize CPES operation.The attack is formulated as a DIA modifying load control variables and disturbing supply-demand balance.
- Background & formulation: The load-demand formulation represents altered demand as initial demand plus the attack-affected demand change and extends to multiple compromised loads.The notation also defines total demand, uncompromised and compromised load counts, and distribution-network losses.
- Attack setup & evaluation: The study targets buses 16, 23, and 29 in the IEEE-39 bus system and measures frequency variations at generator connections.The physical layer uses an EMT approach with real-time simulation and synchronous-machine generator models.
- Results: A 20% demand increase at bus 29 lowers nearby generator 9 to around 59.87 Hz and raises it to around 60.11 Hz after termination.The attack starts at t = 4 sec, lasts 0.5 sec, and the system begins at nominal 60 Hz.
- Results: A 50% increase at buses 29 and 16 drives multiple generators to approximately 59.85 Hz and 60.23 Hz at attack triggering and termination.Adding bus 23 to the 50% attack heavily affects every generator, with generators 9 and 6 most affected.
- Risk assessment: The estimated risk of the load-changing demand attacks is 28.Potential protection mechanisms are assumed to limit cascading effects while interruption and financial-profit impacts receive medium priority.
C. Case Study 3: Time-Delay Attacks
The TDA case study models delays on microgrid control communications and evaluates their effects through real-time cyber-physical co-simulation. Increasing delay durations progressively disrupt islanding-related load shedding, frequency stability, and generator behavior.
- Background & Formulation: TDAs delay sensor measurements or actuator commands, potentially destabilizing control systems through mechanisms such as network congestion.
- Background & Formulation: The TDA formulation applies a delay function to a compromised control variable or measurement during the attack period.Here, sr denotes the compromised signal, fD the delay function, and d a constant or time-varying delay.
- Testbed and Attack Setup: The real-time microgrid testbed maps physical components to virtual communication nodes connected through a router using DNP3 master–outstation communication.
- Testbed and Attack Setup: Three attack cases delay the load-shedding command after intentional islanding by approximately 0.5, 5, and 15 seconds.The attacker compromises the communication link between the microgrid controller and the IED controlling a 300 kW sheddable load.
- Results: A 5-second TDA drives microgrid frequency between 60.52 Hz and 55.75 Hz, requiring load curtailment and generator tripping to protect equipment.
- Results: A 15-second TDA reduces frequency to 15.31 Hz and produces large generator-power oscillations, enabling worst-case and coordinated-attack analysis without endangering grid operation.
- Results: The evaluation also measures average network end-to-end delay and the number of packets delayed by the TDA.
D. Case Study 4: Propagating Attacks in Integrated Transmission and Distribution (T&D) CPES
The integrated T&D case study addresses the need to simulate coupled transmission and distribution behavior in real time. It uses coordinated models and attack scenarios to evaluate disturbance propagation across both domains.
- Background & Formulation: Transmission-only or distribution-only real-time simulations often abstract the other domain because modeling the entire EPS requires substantial computational power.
- Background & Formulation: Accurate integrated T&D assessment requires clock-synchronized parallel communication between transmission and distribution models to match boundary conditions.
- Modeling Approach: A nodal boundary solution for shared voltages, currents, and admittances improves solution accuracy and execution time, making real-time integrated T&D simulation feasible.
- Attack Setup: The real-time model integrates the IEEE-9 bus transmission system with the IEEE-13 bus distribution system.
- Attack Setup: One scenario alters T&D topology by opening the point-of-common-coupling switch, while another disconnects transmission generators to examine propagation into distribution voltage.
- Results: Opening a coupling circuit breaker produces a transmission-frequency peak around 60.23 Hz, followed by fluctuations that may affect frequency-sensitive components and controls.
- Results: During generator-disconnection contingencies, distribution bus 632 voltage drops from 1 p.u. to 0.5 p.u., then to 0.2 p.u. when both generators disconnect consecutively.
- Risk Assessment: The risk assessment assigns high threat probability to T&D attacks because successful compromise requires strong architectural knowledge and ample resources.
E. Post-risk assessment discussion
After calculating risk scores, the paper ranks diverse CPES attacks and assigns them to mitigation pools. This ranking supports comparative prioritization and differentiated risk handling.
- Risk Ranking: The four attack cases receive risk scores of 22 for cross-layer firmware attacks, 28 for load-changing attacks, 51 for TDAs, and 84 for integrated T&D propagation attacks.
- Risk Ranking: Higher risk scores correspond to attacks expected to have greater impact, with score variation determined by threat probability, objective priorities, and operational impact.
- Risk Prioritization: Risk ranking places attacks into pools, where pool 1 contains the most devastating attacks and lower pools contain progressively smaller risk scores.
- Risk Prioritization: Pool-specific strategies support mitigating, deferring, transferring, or accepting risks according to their operational significance and mitigation cost.
VI. CONCLUSIONS
The paper presents a holistic CPES security methodology combining threat modeling, CPS resources and metrics, risk assessment, and four attack case studies. It provides guidance for rigorous modeling, simulation, evaluation, and future extensions toward resilient and adaptive CPES operation.
- Conclusions: The methodology combines adversary and attack models, CPS resources, metrics, and risk assessment to analyze CPES security.The threat models characterize attackers, entry points, techniques, and goals, while the framework supports high-fidelity CPS studies and system-risk characterization.
- Conclusions: Four attack case studies illustrate the methodology through mathematical formulations, threat models, attack setups, and simulations under nominal and abnormal conditions.The resulting scores support disruption ranking, prioritization, and selection of risk-mitigation strategies.
- Conclusions: The framework provides guidelines for modeling CPS threats and designing, simulating, and evaluating detailed CPS models.The authors state that this holistic approach can promote rigorous CPS security analysis.
- Secure and resilient CPES operation: Future work will add resiliency methodologies and metrics to assess CPES posture and classify systems by their ability to withstand attacks.The proposed metrics are intended to indicate how effectively systems handle adverse circumstances.
- Autonomous CPES operation and simulation-aided risk assessments: Future extensions will support autonomous operation and simulation-aided risk assessment using digital-twin configurations and automated incident response.The planned testbed would evaluate mitigation strategies in real time and help prevent adverse situations.
- Dynamic reconfiguration and self-healing capabilities: Future extensions will address post-compromise response through dynamic reconfiguration and self-healing crisis-handling plans tailored to CPES state and scenario characteristics.An example is alternative power dispatch during a transmission contingency.