The number of cyberattacks in the energy sector is increasing, and research efforts on security measures are accelerating accordingly. Scientists from Gdańsk Tech and the University of Strathclyde in Scotland have developed algorithms, models, and metrics that enable data sharing within the energy sector. The solutions were tested at a power plant in Livorno, Italy, and the platform is used by, among others, Polskie Sieci Elektroenergetyczne SA. Thanks to the developed solutions, power plants and transmission and distribution system operators can be more aware of threats and adequately protect themselves against them. The algorithms are being developed as part of the work of the European EE-ISAC centre.

The Colonial Pipeline fuel pipeline in the USA, the Ukrenergo transmission station in Ukraine, and the nuclear power plant in North Korea are just some examples of cyberattacks on critical infrastructure in the energy sector, i.e. facilities and systems essential for ensuring the country's energy security. According to the European Union Agency for Cybersecurity (ENISA), the European energy sector was attacked more than one hundred times in 2020, and the scale of this phenomenon is increasing year by year. Hackers most often aim for ransom, data acquisition, or disruption of energy supplies, which means consumers lose access to electricity, gas, or oil.

Researchers from Gdańsk Tech and the University of Strathclyde in Glasgow co-developed innovative solutions that serve to improve cybersecurity in the energy sector – the SAN network and the cyber incident information exchange system. The SAN network helps build situational awareness, i.e., the ability to detect events, analyze them, and determine their consequences (Situational Awareness Network). Meanwhile, the information exchange system supports sharing experiences related to past cyber incidents and helps protect against future threats. The work has been ongoing for 8 years and was described in the academic article “Developing novel solutions to realise the European Energy–Information Sharing & Analysis Centre” published in Decision Support Systems.

From numbers to security: building the network

The SAN network proposed by the researchers has three layers. The lowest layer consists of numerous sensors distributed within the IT systems of energy operators. These sensors monitor both energy production and transmission and office operations. In the second layer, data from the sensors are processed by Security Information and Event Management (SIEM) systems. The third layer is a specialized dashboard that helps receive thousands of pieces of information from various system elements and manage them.

Free data exchange is possible only with appropriate security measures. An important part of the system is data anonymization mechanisms. The researchers also developed special rules for grouping and combining data, which support processing the massive amounts of information reaching the platform.

– The project underwent detailed testing, including at the Livorno power plant in Italy. This way, we confirmed the selection of SAN network components, the operational capabilities of each, and the correctness of the entire network’s operation. This is an essential stage of the research, allowing us to be confident that our solutions will detect more cyber threats, thereby better protecting companies and consumers – says PhD Eng. habil. Rafał Leszczyna, co-author of the solutions from Gdańsk Tech.

 

 

EE-ISAC – How to Share Information

Research is conducted within the framework of the European Energy Information Sharing and Analysis Centre (EE-ISAC), a European centre for the exchange and analysis of information on incidents in the energy sector. This organization has been working since 2015 to improve the resilience and security of European energy infrastructure. It facilitates information exchange between various entities – energy companies, cybersecurity solution providers, research institutions, government, and non-profit organizations. The network includes about 30 organizations, such as Polskie Sieci Elektroenergetyczne SA, ENEL, SwissGrid, EDP, Siemens, and the European Union Agency for Cybersecurity (ENISA). Gdańsk Tech has been a member of EE-ISAC since July 2020.

– As shown by experience so far, intensive information exchange is essential for effective defense against cyberattacks. Energy infrastructure is a particularly critical target of attacks because the functioning of other economic sectors depends on it. For this reason, it can become an object of cyber wars and other pressures of a political and economic nature – comments PhD DSc Eng. Rafał Leszczyna. Initiatives like EE-ISAC serve to protect against situations similar to Colonial Pipeline, where hackers extorted ransom payments. Currently, numerous institutions of this type are being established at the European and global levels to protect various sectors – adds the expert.