Cyber-Physical Energy Systems Security: Threat Modeling, Risk Assessment, Resources, Metrics, and Case Studies
Cyber-physical systems (CPS) are interconnected architectures that employ\nanalog, digital, and communication resources for their interaction with the\nphysical environment. CPS are the backbone of enterprise, industrial, and\ncritical infrastructure. Thus, their vital importance makes them prominent\ntargets for malicious attacks aiming to disrupt their operations. Attacks\ntargeting cyber-physical energy systems (CPES), given their mission-critical\nnature, can have disastrous consequences. The security of CPES can be enhanced\nleveraging testbed capabilities to replicate power system operations, discover\nvulnerabilities, develop security countermeasures, and evaluate grid operation\nunder fault-induced or maliciously constructed scenarios. In this paper, we\nprovide a comprehensive overview of the CPS security landscape with emphasis on\nCPES. Specifically, we demonstrate a threat modeling methodology to accurately\nrepresent the CPS elements, their interdependencies, as well as the possible\nattack entry points and system vulnerabilities. Leveraging the threat model\nformulation, we present a CPS framework designed to delineate the hardware,\nsoftware, and modeling resources required to simulate the CPS and construct\nhigh-fidelity models which can be used to evaluate the system's performance\nunder adverse scenarios. The system performance is assessed using\nscenario-specific metrics, while risk assessment enables system vulnerability\nprioritization factoring the impact on the system operation. The overarching\nframework for modeling, simulating, assessing, and mitigating attacks in a CPS\nis illustrated using four representative attack scenarios targeting CPES. The\nkey objective of this paper is to demonstrate a step-by-step process that can\nbe used to enact in-depth cybersecurity analyses, thus leading to more\nresilient and secure CPS.\n