1 of 29

Characterizing Intrinsic Destabilization Vulnerabilities with Respect to Dynamic Coordinated Attacks

Benjamin Francis

Chief Scientist

Achilles Heel Technologies

bfrancis@aht.ai

1

2 of 29

Abstract

  • Robust control techniques enable a clear way to quantify a system's vulnerability to destabilization attacks.  This talk will discuss how to measure a system's Intrinsic Destabilization Vulnerability with respect to dynamic coordinated or MIMO attacks.  Unlike the single link, or SISO case, MIMO attacks require an additional step of threat modeling, characterizing communication constraints that may or may not restrict an attacker's capabilities.  When certain types of communication constraints are part of the threat model, we show how measuring Intrinsic Destabilization Vulnerability relies on mu-analysis.  We illustrate these ideas on a power system model, the IEEE 14-Bus System, and we demonstrate the impact using a software tool designed to enable utility managers to study their system's vulnerabilities to destabilization attacks under various threat models.

2

3 of 29

Outline

  •  

3

4 of 29

Background: Industroyer (1 & 2)

  • December 23, 2015: Ukraine suffers a blackout caused by cyber attacks targeting the power grid (manual disruption).
  • December 17, 2016: Blackout in Kyiv caused by industrial malware targeting the power grid (Industroyer).
  • April 8, 2022: Industroyer 2 targets Ukraine power grid.
  • “… the first and only known malware samples specifically deployed by malicious actors to target the power grid.”
    • Detailed analysis: Salazar, L., Castro, S. R., Lozano, J., ... & Cardenas, A. A. (2024, May). A Tale of Two Industroyers: It was the Season of Darkness. In 2024 IEEE Symposium on Security and Privacy (SP) (pp. 312-330). IEEE.
  • All three targeted circuit breakers using open loop attacks, but could have used closed loop attacks.

4

5 of 29

Background: Robust control theory (80s & 90s)

  •  

5

 

 

6 of 29

Background: closed loop attacks

  •  

6

 

 

Measure/read

Perturb/write

7 of 29

Modeling IDVs

  •  

7

 

 

Measure/read

Perturb/write

8 of 29

System modeling

  •  

8

9 of 29

System modeling

  •  

9

 

 

 

10 of 29

Threat modeling

  •  

10

 

 

 

 

 

 

 

 

 

Attack scenario

11 of 29

Threat modeling

  •  

11

 

 

 

 

12 of 29

Threat modeling

  •  

12

 

 

 

 

 

 

 

 

 

13 of 29

Threat modeling

  •  

13

 

 

 

 

 

 

 

 

 

14 of 29

Quantifying IDVs

  •  

14

Small gain condition for instability

15 of 29

Quantifying IDVs

  •  

15

Structured singular value function

16 of 29

Quantifying IDVs

  •  

16

17 of 29

Software demonstration: power systems

17

18 of 29

1. System modeling

19 of 29

1. System modeling

20 of 29

1. System modeling

Access points:

Exposed inputs/outputs

21 of 29

1. System modeling

 

2. Threat modeling

22 of 29

 

2. Threat modeling

23 of 29

Attack footprint

(for each agent)

2. Threat modeling

24 of 29

3. Vulnerability analysis

Vulnerability scores

for each attack scenario

 

25 of 29

4. Attack simulation

26 of 29

Attacker’s view

4. Attack simulation

27 of 29

Attack surface view

4. Attack simulation

28 of 29

Global view

4. Attack simulation

29 of 29

Conclusions

  •  

29