Tutorial: Cybersecurity of the Electric Power Transmission and Distribution System

Instructors Dr. Murty V.V.S. Yalla, Beckwith Electric Co., Inc.; Steven A. Kunsman, ABB; Dr. Nathan Wallace, Ampirical; Scott R. Mix, NERC; J. Matt Cole, Sargent and Lundy

Cyber-attack on an Electric Power T&D communications system can have a devastating impact and cause widespread power outages as evident from the Dec 2015 cyber-attack on a Ukrainian Electric Power Distribution System. Securing Electric Power System from cyber-attacks is of national importance and in North America NERC is spearheading the effort in developing and enforcing Critical Infrastructure Protection (CIP) Standards for Bulk Electric System (BES). Local and state regulating agencies are also looking at cybersecurity of the Electric Power Distribution Systems. Substation protection, automation and control systems along with distribution field devices have changed significantly in the past decade. These systems have become more interconnected and provide end users with much more information to allow for higher reliability and greater levels of control. Interoperability between different vendor products and systems has been achieved using open standards. This change in technology has not only brought huge benefits from an operational point of view, it also permits to address cyber security issues similar to other traditional, enterprise systems which have been facing the same industry challenges for years.

The tutorial discusses cybersecurity basics including passwords & access management, authentication, encryption, network security monitoring, techniques in cyber alarming, logging, and auditing. The tutorial also covers NERC CIP requirements applicable to T&D systems along with brief overview of IEEE and IEC standards. Cybersecurity implementation examples of substation protection, automation and controls systems including devices inside as well as outside the substations are also discussed. Utility perspective on Cybersecurity and NERC CIP compliance will be included.

Tuesday, July 18th, 8:00 AM-10:00 AM  Power System Communications & Cyber Security Transactions Paper Session

Tuesday, July 18 1:00 PM-5:00 PM
Summary:      Cyber and Physical Security NERC requirements and standards for Cyber and Physical security in the Bulk Electric System. IEEE PES collaboration with DOE, NERC, and FERC in developing reliability standards and policy. Recent changes to cyber and physical security requirements. Best practices for cyber and physical security in electric power systems.
Security Analysis and Control of Cyber-Physical Systems(CPS)
Time:  Thursday, July 20, 2017 1:00 PM-5:00 PM
Room: S-Chicago IX
Committee:    Power Systems Communications & Cyber Security
Summary:      The physical power system increasingly relies on the ICT infrastructure (the cyber system) for monitoring, control and optimal operation. Failures in the cyber system can have very large impact on the security and stability of physical power system. Security analysis and control of power systems should therefore incorporate such failures. The integrated cyber-physical system (CPS) is complex, featuring stochastic behavior and a mixture of discrete events and continuous processes. Currently, there is no comprehensive methodology to analyze the security status and generate control strategies for integrated cyber-physical power system, but novel analytical approaches are emerging. This panel will discuss the challenges involved in security analysis and control of CPSs. The panelists will share their experiences in security indices, security evaluation methods, control strategy decision-makings approaches, etc., for various cyber-physical sub-systems in the power grid.
Lessons Learned from Cyber Attack Incidents and How to Mitigate them?
Time: Thursday, July 20, 2017 3:00 PM-5:00 PM
Room: S-Arkansas
Committee: (AMPS) Computer Analytical Methods
Summary: The focus of this panel is to share knowledge and discuss the following issues in cyber security of the power grid: (i) growing number and sophistication of cyber attacks targeted towards energy delivery systems around the world; (ii) case studies of recent attacks on power systems and lessons learned from these incidents; (iii) R&D experiences and best practices to improve the security of the modern power grid. The panel will have experts drawn from academia, national lab, and industry.
