urgent and needed in 6 hours
Technology Selection Study Recommendation Paper
For: University of Maryland Global Campus CSIA 459
By: Tyler Wilber
Due: 12/01/2020
Introduction
As the Mid-Atlantic’s largest regional power generation and distribution utility, we understand the critical and essential role our company has in providing efficient, reliable, and affordable electricity. Consequently, we have an obligation to ensure that the heat is on when customers wake up in the morning, the lights turn on and the refrigerator is working. We take this fiduciary responsibility seriously. Guaranteeing we can continue to provide this essential service means we must ensure our grid is protected. In the era of mobile smart devices with worldwide Internet interconnectivity, protecting our grid requires understanding and incorporating cybersecurity Best Practices, policies, and procedures, as well as tools throughout our energy generation and distribution network. Representing our company’s senior leadership and management, each of you understand the many facets of cybersecurity Best Practices and how our SCADA systems operate. Therefore, this paper strongly recommends our company conduct further Research & Development into the field of Artificial Intelligence and its subsequent application to protect our Supervisory Control and Data Acquisition systems.
But what is Artificial Intelligence? Defined by Lehto & Vähäkainu at the 14th International Conference on Cyber Warfare and Security (2019), Artificial Intelligence (AI) is when a computer demonstrates the ability to reach conclusions for itself. Generally, they state that “any system that perceives its environment and takes actions that maximize its chance of success at some goal may be defined as AI” (Lehto & Vähäkainu, 2019). More specifically, according to Alqahtani, Badsha, Kayes et al (2020), data science and Machine Learning (ML) parse large cybersecurity data sets, subsequently transforming this information into ML models which are then plugged into AI cybersecurity systems that are not only automated, but also intelligent (Alqahtani, Badsha, Kayes, et al, 2020). As stated by Reveron, & Savage (2020), AI offers significant strategic cybersecurity benefits to our energy grid with its immense computational power, combined with machine speed automation and machine precision (Reveron, & Savage, 2020). Unfortunately, AI does have weaknesses. Mainly, AI is susceptible to false-data injection or the intentional introduction of corrupted data. However, this potentially critical vulnerability can be mitigated by incorporating Security-Oriented Cyber-Physical State Estimation (SCPSE) which, according to Hawk & Kaushiva (2016), autonomously searches for and detects energy transmission, distribution and consumption data, within our grid, that has been intentionally corrupted with the intent of falsifying energy grid operations (Hawk & Kaushiva, 2016). Clearly, the SCPSE tool attempts to mitigate the dangers associated with automated Artificial Intelligence monitoring, detection, and response tools. If properly implemented, SCPSE will harden AI SCADA applications so our company can focus on applying all the benefits of AI to our SCADA systems. As a result, we can reduce brownouts, blackouts, power surges as well as any intermittent down-time caused by natural disasters.
Next, this Study Recommendation Paper outlines known vulnerabilities with SCADA systems and presents several AI based cybersecurity mitigation techniques. For instance, air gapped SCADA systems are susceptible to command Authentication errors, social engineering, and insider attacks. Other known SCADA systems cybersecurity vulnerabilities include Master center back-door access via deployed smart SCADA sensors. Finally, this paper evaluates how much it might cost to secure Artificial Intelligence against cyber-attacks.
Recommendation for Study
Advances in data science and machine learning have a direct impact on Artificial Intelligence (AI) and its subsequent application within SCADA systems. As Alqahtani, Badsha, Kayes, et. al. (2020) suggest, when combined with cybersecurity frameworks, AI can extract patterns from data sets of reported cybersecurity incidents. Consequently, AI can develop new insights for, or confirm an existing understanding of the cyber threat landscape. Consequently, this Paper recommends further research be conducted to develop robust data-driven cybersecurity-oriented models. The goal for this research is to be applied into AI cybersecurity applications proactively protecting our SCADA systems (Alqahtani, Badsha, Kayes, et. al., 2020).
Another critical aspect of AI that warrants further research and development is its application to Facial Recognition for SCADA command Authentication. Discussed by Chen, L., Ning, H., Nugent, C., and Yu, Z. (2020), there are many other benefits of AI in terms of using powerful algorithms to extract data, identify cybersecurity data patterns and make predictive assessments of current or future cyber incidents. Interestingly Kanimozhi & Prem (2019) surmise the most important component to detect cyber incidents or other malicious behavior within our SCADA system is an Intrusion Detection System (IDS). While applying IDS to SCADA systems is not new, they stipulate that AI has a critical role to play in IDS in terms of detecting, adapting to new threats and rebuilding the IDS model accordingly. One aspect of their work that demands further Research & Development is the reconditioning our current SCADA systems into an Artificial Neural Network (ANN). Kanimozhi & Prem (2019) suggest that ANN’s have the potential to accurately track 99.97 percent of cyberattacks while boasting a meager .999 false positive rate. Clearly, deployed AI operating within an ANN can create an immensely robust and accurate cyber defense ecosystem.
Yet another aspect of AI that warrants further Research & Development is AI’s application to autonomous SCADA sensors. Kyrkou, C. et. al., (2020) suggest that proactively applying AI techniques can mitigate many of the cybersecurity risks of autonomous SCADA sensors. Specifically, in cybersecurity terms, they mention the need to harden autonomous sensors as these are vulnerable attack vectors. They theorize that by building cybersecurity Best Practices of Integrity, Authentication, and Non-Repudiation into data science models, these models can then be incorporated into AI applications. As a result, our autonomous SCADA sensors can in effect, in-and-of themselves become anti-hacking devices.
Another recommendation for additional Research & Development into AI applications for SCADA systems is its anomaly detection capabilities. As Lehto & Vähäkainu (2019) suggest, the more iterations an AI platform goes through, the more accurate its response will be. The authors identify AI’s ability to identify, predict and block cybersecurity threats before they exploit vulnerabilities. One of the most effective ways AI achieves this is through its anomaly detection. These tools are extremely helpful, not only in terms of identifying out-side network anomalies, but also inside-network anomalies. Clearly, this is quite useful in stopping insider attacks – a well-known SCADA cybersecurity vulnerability (Lehto & Vähäkainu, 2019). Another benefit to our SCADA systems cybersecurity posture is AI’s ability to detect internal as well as external network traffic volumes. Going further, AI can also generate extremely specific information in terms of personal idiosyncrasies and Authenticate the identify of someone attempting to access the SCADA system. Plainly, this application can provide excellent Confidentiality and Authentication capabilities for our grid.
Going further, Camacho, D., Del Ser, J., Gumaei, A., Hassan, R., Huda, S., and Fortino, G. (2020) present the many benefits of substantially reducing threat analysis features of deployed Threat Analysis Systems, in combination with introducing Correlation based Feature Selection (CFS) and instance-based learning (IBL) algorithms for AI cybersecurity applications. The promise of these tools necessitates further Research & Development. In essence, the simplification of threat analysis features combined with more effective applications and protections, AI algorithms make it possible for our company to continue utilizing the many automated monitoring, detection and reporting benefits of our deployed SCADA systems while substantively reducing their cyber threat vulnerabilities (Camacho, D., Del Ser, J., Gumaei, A., Hassan, R., Huda, S., and Fortino, G., 2020). These proposed cybersecurity recommendations illustrate how we can successfully apply new cyber security policies and procedures to our SCADA systems so that they can continue to operate safely.
Another cybersecurity solution for hardening SCADA applications that warrant further Research & Development is Structured Analysis Real-Time (SA-RT). According to Lakhoua, Salem, and Wertani (2020), SA-RT utilizes pattern recognition and other techniques to analyze and process SCADA alarms. Going further, the authors suggest a framework for analyzing and supervising command and control SCADA applications via the SA-RT method. Namely, the authors suggest that SCADA alarms, when analyzed by AI, can be attributed to specific actions. Additionally, when deploying SA-RT, SCADA systems can weed out extraneous alarms as well as alarms that indicate nefarious activity is taking place within our grid (Lakhoua, Salem, and Wertani, 2020). While not explicitly stated in their work, the authors are clearly attempting to create a framework that addresses key cybersecurity concerns within SCADA applications.
Finally, this paper recommends that our company allocate funding for Researching methods to mitigate the air gap security fallacy of SCADA Master centers, which is a critical security vulnerability exploited by many cyber attackers. Examples of successful cyber-attacks on air gapped SG SCADA systems include the attack on Ukrainian Critical energy Infrastructure, and Stuxnet which disabled Iran’s main nuclear production facility in Natanz. To mitigate cyber-attacks on air gapped SCADA systems, the authors of this article suggest basic cybersecurity policies and procedures such as AI powered defense in depth protocols and command authentication systems. Other well-known cyber defenses the authors recommend include firewalls and IDS which was previously discussed. However, the authors explicitly state that proper command Authentication is vital to protecting SCADA systems deployed within our grid. One method for providing command Authentication is via AI powered facial recognition software. They suggest that the system must verify the person requesting access to SCADA command functionalities prior to getting access to it. This is critical because once someone is granted access to such a powerful, centralized automated system like SCADA, nefarious actors can potentially inflict irreparable harm on target infrastructure.
Potential or Known Vulnerabilities with Artificial Intelligence
Without question, Artificial Intelligence offers many cybersecurity benefits to our SCADA systems and autonomous grid sensors. These benefits range from dynamic Intrusion Detection Systems, Artificial Neural Networks, facial recognition Authentication to the basics of cybersecurity Confidentiality, Integrity and Availability of data. This Technology Study Recommendation Paper suggests several AI applications intended to predict, prevent, detect, and mitigate cyber threats to our grid. However, as previously suggested, AI in its current form does not achieve perfect security. So, what are AI’s vulnerabilities? First up is false-data injection. In short, this is when corrupted data is intentionally fed into the modeling used by AI software. Other known AI vulnerabilities are inclusion of old or inaccurate (unintentional) cyber data sets, incomplete cyber data sets, missing or incomplete signature/anomaly profiles, and others. As Troy Hiltbrand (2018), AI is only as good as the information that is put into a model and subsequently analyzed. Therefore, we must ensure the data we are using in our models are devoid of internal as well as external corruption. Interestingly, if conducted properly and combined with cyber Best Practices, data science can reduce the amount of garbage-in by identifying internal network weaknesses, and possible sources of corrupted data so they may be mitigated. As Hiltbrand (2018) indicates, data scientists study data/models to test and verify results. If a model indicates a random/one-off response, it could be an indication of internal data corruption and requires a cyber defense remediation (Hiltbrand, 2018). Clearly AI is not devoid of cybersecurity vulnerabilities. Importantly however, they can be mitigated by applying basic cybersecurity Best Practices.
Summary
Our clients entrust us with making sure they have the electricity they need to turn house lights on, pump gas at the station, keep their refrigerators running as well as power their Internet access 24 hours a day, 7 days a week. Achieving this herculean task requires the vigilant application of cybersecurity Best Practices as well as continuous grid monitoring. As a result, we can effectively ensure our grid is secure from internal and external cyber-attacks. This Paper makes several recommendations for Researching & Developing Artificial Intelligence applications for our SCADA systems. After this R&D period, this paper strongly recommends we immediately transition into a Pilot Implementation plan and subsequent full roll-out of this Papers recommended AI-SCADA applications. In doing so, we will achieve a robust, real-time defense in depth cyber defenses that can evolve faster than the cybersecurity threat landscape. Artificial Intelligence, if implemented and administered correctly, can provide us with beyond-the-horizon cybersecurity threat detection, prevention, and mitigation. As we know, our SCADA systems allow us to remotely manage our entire grid via regional Master centers. While our SCADA systems are immensely powerful and offer automated command and control functionality, they are also our weakest link. As such, and to keep our fiduciary promise to our loyal customers, we must Research, Develop, and implement the above recommended AI applications. Of note, it is almost impossible to generate an estimated cost of deployment for AI-SCADA applications in our grid. What we do know, however, is if we fail to adopt SCADA hardening technology, policies and procedures, our company will likely suffer a similar fate to Ukraine’s power grid in 2016 or even the Natanz nuclear center in Iran. We understand the very real likelihood of this occurring because we know that peer and near-peer adversaries have penetrated and continue to probe our electrical grid for weaknesses. If we want to protect our customers, our vital national institutions, and our daily way of life, we must act now to adopt AI applications for our SCADA systems. If we hesitate or waiver in this endeavor, we will be inviting tragedy upon our company and those who rely upon the services we provide.
References:
Alqahtani, H., Badsha, S., Kayes, et al (2020 July, 1). Cybersecurity data science: an overview from machine learning perspective. J Big Data 7, 41. https://doi.org/10.1186/s40537-020-00318-5
Camacho, D., Del Ser, J., Gumaei, A., Hassan, R., Huda, S., and Fortino, G. (2020 November). A Robust Cyberattack Detection Approach Using Optimal Features of SCADA Power Systems in Smart Grids. Applied Soft Computing. Vol. 96. 106658. ISSN 1568-4946. Retrieved https://doi.org/10.1016/j.asoc.2020.106658
Chen, L., Ning, H., Nugent, C., and Yu, Z. (2020 August). Hybrid Human-Artificial Intelligence. In Computer, vol. 53, no. 08, pp. 14-17. Retrieved https://doi.ieeecomputersociety.org/10.1109/MC.2020.2997573
Hawk, C. & Kaushiva, A. (2016 October). Cybersecurity and the Smarter Grid. The Electricity Journal. Vol. 27, Issue 8, pp. 84-95. ISSN 1040-6190. Retrieved https://doi.org/10.1016/j.tej.2014.08.008
Hiltbrand, T (2018 January 16). Cybersecurity Plus Data Science: The Career Path of the Future? Retrieved https://tdwi.org/articles/2018/01/16/adv-all-cybersecurity-plus-data-science-future-career-path.aspx
Kanimozhi, V. & Prem, J. (2019 April, 24). Artificial Intelligence based Network Intrusion Detection with hyper-parameter optimization tuning on the realistic cyber dataset CSE-CIC-IDS2018 using cloud computing. Volume 5, Issue 3, pp. 211-214. Retrieved https://doi.org/10.1016/j.icte.2019.03.003
Kyrkou, C. et al., (2020). Towards Artificial-Intelligence-Based Cybersecurity for Robustifying Automated Driving Systems Against Camera Sensor Attacks," in 2020 IEEE Computer Society Annual Symposium on VLSI (ISVLSI), Limassol, Cyprus, pp. 476-481. Retrieved https://doi.ieeecomputersociety.org/10.1109/ISVLSI49217.2020.00-11
Lakhoua, M.N., Salem, B., and Wertani, H. (2020 July). Analysis and Supervision of a Smart Grid System with a Systemic Tool. The Electricity Journal. Vol. 33, Issue 6, 106784. ISSN 1040-6190. Retrieved https://doi.org/10.1016/j.tej.2020.106784
Lehto, M. & Vähäkainu, P. (2019 December). Artificial intelligence in the cyber security environment Artificial intelligence in the cyber security environment. Retrieved https://www.researchgate.net/publication/338223306_Artificial_intelligence_in_the_cyber_security_environment_Artificial_intelligence_in_the_cyber_security_environment
Mashima, D. (2021). Securing Smart-Grid Infrastructure Against Emerging Threats. Solving Urban Infrastructure Problems Using Smart City Technologies. Ch. 16, pp. 359-382. ISBN 9780128168165. Retrieved https://doi.org/10.1016/B978-0-12-816816-5.00016-4
Reveron, D., & Savage, J. (2020 September). Cybersecurity Convergence: Digital Human and National Security. In Orbis Volume 64, Issue 4, pp. 555-570. Retrieved https://doi.org/10.1016/j.orbis.2020.08.005