The digitization and decentralization of the electric power grid are key thrusts for an economically and environmentally sustainable future. Towards this goal, distributed energy resources (DER), including rooftop solar panels, battery storage, electric vehicles, etc., are becoming ubiquitous in power systems. Power utilities benefit from DERs as they minimize operational costs; at the same time, DERs grant users and aggregators control over the power they produce and consume. DERs are interconnected, interoperable, and support remotely controllable features, thus, their cybersecurity is of cardinal importance. DER communication dependencies and the diversity of DER architectures widen the threat surface and aggravate the cybersecurity posture of power systems. In this work, we focus on security oversights that reside in the cyber and physical layers of DERs and can jeopardize grid operations. Existing works have underlined the impact of cyberattacks targeting DER assets, however, they either focus on specific system components (e.g., communication protocols), do not consider the mission-critical objectives of DERs, or neglect the adversarial perspective (e.g., adversary/attack models) altogether. To address these omissions, we comprehensively analyze adversarial capabilities and objectives when manipulating DER assets, and then present how protocol and device-level vulnerabilities can materialize into cyberattacks impacting power system operations. Finally, we provide mitigation strategies to thwart adversaries and directions for future DER cybersecurity research.
翻译:电力系统的数字化与去中心化是实现经济和环境可持续未来的关键推动力。为此,分布式能源资源(DER),包括屋顶太阳能电池板、电池储能、电动汽车等,正在电力系统中变得无处不在。电力公用事业公司受益于DER,因为它们能最小化运营成本;同时,DER赋予用户和聚合商对其生产和消耗的电力进行控制的能力。DER具有互联互通、互操作性,并支持远程可控功能,因此其网络安全至关重要。DER通信依赖性和DER架构的多样性扩大了威胁面,并加剧了电力系统的网络安全态势。在本工作中,我们聚焦于DER网络层和物理层中可能危及电网运行的安全疏漏。现有工作已强调针对DER资产的网络攻击的影响,但它们要么专注于特定系统组件(如通信协议),未考虑DER的关键任务目标,要么完全忽略对抗性视角(如对手/攻击模型)。为弥补这些不足,我们全面分析了对手在操纵DER资产时的能力与目标,随后展示了协议和设备级漏洞如何具体化为影响电力系统运行的网络攻击。最后,我们提供了抵御对手的缓解策略以及未来DER网络安全研究的方向。