Search arXivSearch

arXiv subjects

Martin Higgins

Publications and source records attributed to Martin Higgins.

10 recordsLinked to original sources

EduSOC: Lightweight Security Operations Center Simulator for Cybersecurity Education

This paper presents EduSOC, a lightweight web-based Security Operations Center (SOC) simulator designed for instructor-led cybersecurity education. SOC analysts must triage large volumes of alerts, separate genuine threats from false positives, and communicate decisions under time pressure. Recreating this environment in the classroom is difficult and often impractical for institutions without access to cyber ranges or enterprise security infrastructure. LITE-SOC was developed to provide a simpler alternative. The platform generates continuous streams of synthetic SOC events and offers separate student and instructor views with visualization tools, event annotation, and region-based chat. Instructors control the pacing of the exercise and can inject targeted incidents to guide the scenario. The goal is to give students a practical introduction to SOC workflows such as triage, prioritization, and decision-making without requiring a full operational SOC environment. The platform is intended for use in guided classroom exercises where students collaboratively investigate alerts and practice real-time triage and communication.

cs.CR

Security by Design Issues in Autonomous Vehicles

As autonomous vehicle (AV) technology advances towards maturity, it becomes imperative to examine the security vulnerabilities within these cyber-physical systems. While conventional cyber-security concerns are often at the forefront of discussions, it is essential to get deeper into the various layers of vulnerability that are often overlooked within mainstream frameworks. Our goal is to spotlight imminent challenges faced by AV operators and explore emerging technologies for comprehensive solutions. This research outlines the diverse security layers, spanning physical, cyber, coding, and communication aspects, in the context of AVs. Furthermore, we provide insights into potential solutions for each potential attack vector, ensuring that autonomous vehicles remain secure and resilient in an evolving threat landscape.

eess.SY

Incentive-weighted Anomaly Detection for False Data Injection Attacks Against Smart Meter Load Profiles

Spot pricing is often suggested as a method of increasing demand-side flexibility in electrical power load. However, few works have considered the vulnerability of spot pricing to financial fraud via false data injection (FDI) style attacks. In this paper, we consider attacks which aim to alter the consumer load profile to exploit intraday price dips. We examine an anomaly detection protocol for cyber-attacks that seek to leverage spot prices for financial gain. In this way we outline a methodology for detecting attacks on industrial load smart meters. We first create a feature clustering model of the underlying business, segregated by business type. We then use these clusters to create an incentive-weighted anomaly detection protocol for false data attacks against load profiles. This clustering-based methodology incorporates both the load profile and spot pricing considerations for the detection of injected load profiles. To reduce false positives, we model incentive-based detection, which includes knowledge of spot prices, into the anomaly tracking, enabling the methodology to account for changes in the load profile which are unlikely to be attacks.

eess.SY

Spatial-Temporal Anomaly Detection for Sensor Attacks in Autonomous Vehicles

Time-of-flight (ToF) distance measurement devices such as ultrasonics, LiDAR and radar are widely used in autonomous vehicles for environmental perception, navigation and assisted braking control. Despite their relative importance in making safer driving decisions, these devices are vulnerable to multiple attack types including spoofing, triggering and false data injection. When these attacks are successful they can compromise the security of autonomous vehicles leading to severe consequences for the driver, nearby vehicles and pedestrians. To handle these attacks and protect the measurement devices, we propose a spatial-temporal anomaly detection model \textit{STAnDS} which incorporates a residual error spatial detector, with a time-based expected change detection. This approach is evaluated using a simulated quantitative environment and the results show that \textit{STAnDS} is effective at detecting multiple attack types.

eess.SY

Blending Data and Physics Against False Data Injection Attack: An Event-Triggered Moving Target Defence Approach

Fast and accurate detection of cyberattacks is a key element for a cyber-resilient power system. Recently, data-driven detectors and physics-based Moving Target Defences (MTD) have been proposed to detect false data injection (FDI) attacks on state estimation. However, the uncontrollable false positive rate of the data-driven detector and the extra cost of frequent MTD usage limit their wide applications. Few works have explored the overlap between these two areas. To fill this gap, this paper proposes blending data-driven and physics-based approaches to enhance the detection performance. To start, a physics-informed data-driven attack detection and identification algorithm is proposed. Then, an MTD protocol is triggered by the positive alarm from the data-driven detector. The MTD is formulated as a bilevel optimisation to robustly guarantee its effectiveness against the worst-case attack around the identified attack vector. Meanwhile, MTD hiddenness is also improved so that the defence cannot be detected by the attacker. To guarantee feasibility and convergence, the convex two-stage reformulation is derived through duality and linear matrix inequality. The simulation results verify that blending data and physics can achieve extremely high detection rate while simultaneously reducing the false positive rate of the data-driven detector and the extra cost of MTD. All codes are available at https://github.com/xuwkk/DDET-MTD.

eess.SY

Cyber-Physical Risk Assessment for False Data Injection Attacks Considering Moving Target Defences

In this paper, we examine the factors that influence the success of false data injection (FDI) attacks in the context of both cyber and physical styles of reinforcement. Many works consider the FDI attack in the context of the ability to change a measurement in a static system only. However, successful attacks will require first intrusion into a system followed by construction of an attack vector that can bypass bad data detection (BDD). In this way, we develop a full service framework for FDI risk assessment. The framework considers both the costs of system intrusion via a weighted graph assessment in combination with a physical, line overload-based vulnerability assessment. We present our simulations on a IEEE 14-bus system with an overlain RTU network to model the true risk of intrusion. The cyber model considers multiple methods of entry for the FDI attack including meter intrusion, RTU intrusion and combined style attacks. Post-intrusion our physical reinforcement model analyses the required level of topology divergence to protect against a branch overload from an optimised attack vector.

eess.SY

Locational Marginal Pricing: Towards a Free Market in Power

Nothing has done more to empower the free market, enterprise, and meritocracy than the spread of electricity and power to everyone. The power system has been the precursor to the greatest period of innovation in our history and has meant that visionaries with revolutionary ideas can compete with those with capital, political power, and means. Electricity, therefore, has been the great equalising force of the last 150 years, enhancing the productivity of the masses and granting prosperity to whole swathes of our nation. Whilst electricity has been one of the single largest innovations in enhancing the power of free markets, it is somewhat ironic that the way power is sold to consumers is largely unfree. The market is highly regulated, centralised, and is often used for political football by cynical politicians on both sides of the political spectrum. Introducing Locational Marginal Pricing into the UK grid system will increase economic freedom in the consumer markets for power, reduce prices for the poorest in the UK, decrease transmission losses, increase the permeation of low carbon generation in the grid, and incentivise investment in the UK's Northern Powerhouse initiative.

q-fin.GN

Topology Learning Aided False Data Injection Attack without Prior Topology Information

False Data Injection (FDI) attacks against powersystem state estimation are a growing concern for operators.Previously, most works on FDI attacks have been performedunder the assumption of the attacker having full knowledge ofthe underlying system without clear justification. In this paper, wedevelop a topology-learning-aided FDI attack that allows stealthycyber-attacks against AC power system state estimation withoutprior knowledge of system information. The attack combinestopology learning technique, based only on branch and bus powerflows, and attacker-side pseudo-residual assessment to performstealthy FDI attacks with high confidence. This paper, for thefirst time, demonstrates how quickly the attacker can developfull-knowledge of the grid topology and parameters and validatesthe full knowledge assumptions in the previous work.

eess.SY

Enhanced Cyber-Physical Security Using Attack-resistant Cyber Nodes and Event-triggered Moving Target Defence

This paper outlines a cyber-physical authentication strategy to protect power system infrastructure against false data injection (FDI) attacks. We demonstrate that it is feasible to use small, low-cost, yet highly attack-resistant security chips as measurement nodes, enhanced with an event-triggered moving target defence (MTD), to offer effective cyber-physical security. At the cyber layer, the proposed solution is based on the MULTOS Trust-Anchor chip, using an authenticated encryption protocol, offering cryptographically protected and chained reports at up to 12/s. The availability of the trust-anchors, allows the grid controller to delegate aspects of passive anomaly detection, supporting local as well as central alarms. In this context, a distributed event-triggered MTD protocol is implemented at the physical layer to complement cyber side enhancement. This protocol applies a distributed anomaly detection scheme based on Holt-Winters seasonal forecasting in combination with MTD implemented via inductance perturbation. The scheme is shown to be effective at preventing or detecting a wide range of attacks against power system measurement system.

eess.SY

Stealthy MTD Against Unsupervised Learning-based Blind FDI Attacks in Power Systems

This paper examines how moving target defences (MTD) implemented in power systems can be countered by unsupervised learning-based false data injection (FDI) attack and how MTD can be combined with physical watermarking to enhance the system resilience. A novel intelligent attack, which incorporates density-based spatial clustering and dimensionality reduction, is developed and shown to be effective in maintaining stealth in the presence of traditional MTD strategies. In resisting this new type of attack, a novel implementation of MTD combining with physical watermarking is proposed by adding Gaussian watermark into physical plant parameters to drive detection of traditional and intelligent FDI attacks, while remaining hidden to the attackers and limiting the impact on system operation and stability.

eess.SY