Purdue: As Ransomware Attacks Increase, New Algorithm May Help Prevent Power Blackouts


High Voltage Maintenance Training Online

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 12 hours Instructor-led
  • Group Training Available
Regular Price:
$599
Coupon Price:
$499
Reserve Your Seat Today

Infrastructure Security Algorithm prioritizes cyber defense for power grids and critical infrastructure, mitigating ransomware, blackout risks, and cascading failures by guiding utilities, regulators, and cyber insurers on optimal security investment allocation.

 

Key Points

An algorithm that optimizes security spending to cut ransomware and blackout risks across critical infrastructure.

✅ Guides utilities on optimal security allocation

✅ Uses incentives to correct human risk biases

✅ Prioritizes assets to prevent cascading outages

 

Millions of people could suddenly lose electricity if a ransomware attack just slightly tweaked energy flow onto the U.S. power grid, as past US utility intrusions have shown.

No single power utility company has enough resources to protect the entire grid, but maybe all 3,000 of the grid's utilities could fill in the most crucial security gaps if there were a map showing where to prioritize their security investments.

Purdue University researchers have developed an algorithm to create that map. Using this tool, regulatory authorities or cyber insurance companies could establish a framework for protecting the U.S. power grid that guides the security investments of power utility companies to parts of the grid at greatest risk of causing a blackout if hacked.

Power grids are a type of critical infrastructure, which is any network - whether physical like water systems or virtual like health care record keeping - considered essential to a country's function and safety. The biggest ransomware attacks in history have happened in the past year, affecting most sectors of critical infrastructure in the U.S. such as grain distribution systems in the food and agriculture sector and the Colonial Pipeline, which carries fuel throughout the East Coast, prompting increased military preparation for grid hacks in the U.S.

With this trend in mind, Purdue researchers evaluated the algorithm in the context of various types of critical infrastructure in addition to the power sector, including electricity-sector IoT devices that interface with grid operations. The goal is that the algorithm would help secure any large and complex infrastructure system against cyberattacks.

"Multiple companies own different parts of infrastructure. When ransomware hits, it affects lots of different pieces of technology owned by different providers, so that's what makes ransomware a problem at the state, national and even global level," said Saurabh Bagchi, a professor in the Elmore Family School of Electrical and Computer Engineering and Center for Education and Research in Information Assurance and Security at Purdue. "When you are investing security money on large-scale infrastructures, bad investment decisions can mean your power grid goes out, or your telecommunications network goes out for a few days."

Protecting infrastructure from hacks by improving security investment decisions

The researchers tested the algorithm in simulations of previously reported hacks to four infrastructure systems: a smart grid, industrial control system, e-commerce platform and web-based telecommunications network. They found that use of this algorithm results in the most optimal allocation of security investments for reducing the impact of a cyberattack.

The team's findings appear in a paper presented at this year's IEEE Symposium on Security and Privacy, the premier conference in the area of computer security. The team comprises Purdue professors Shreyas Sundaram and Timothy Cason and former PhD students Mustafa Abdallah and Daniel Woods.

"No one has an infinite security budget. You must decide how much to invest in each of your assets so that you gain a bump in the security of the overall system," Bagchi said.

The power grid, for example, is so interconnected that the security decisions of one power utility company can greatly impact the operations of other electrical plants. If the computers controlling one area's generators don't have adequate security protection, as seen when Russian hackers accessed control rooms at U.S. utilities, then a hack to those computers would disrupt energy flow to another area's generators, forcing them to shut down.

Since not all of the grid's utilities have the same security budget, it can be hard to ensure that critical points of entry to the grid's controls get the most investment in security protection.

The algorithm that Purdue researchers developed would incentivize each security decision maker to allocate security investments in a way that limits the cumulative damage a ransomware attack could cause. An attack on a single generator, for instance, would have less impact than an attack on the controls for a network of generators, which sophisticated grid-disruption malware can target at scale, rather than for the protection of a single generator.

Building an algorithm that considers the effects of human behavior

Bagchi's research shows how to increase cybersecurity in ways that address the interconnected nature of critical infrastructure but don't require an overhaul of the entire infrastructure system to be implemented.

As director of Purdue's Center for Resilient Infrastructures, Systems, and Processes, Bagchi has worked with the U.S. Department of Defense, Northrop Grumman Corp., Intel Corp., Adobe Inc., Google LLC and IBM Corp. on adopting solutions from his research. Bagchi's work has revealed the advantages of establishing an automatic response to attacks, and analyses like Symantec's Dragonfly report highlight energy-sector risks, leading to key innovations against ransomware threats, such as more effective ways to make decisions about backing up data.

There's a compelling reason why incentivizing good security decisions would work, Bagchi said. He and his team designed the algorithm based on findings from the field of behavioral economics, which studies how people make decisions with money.

"Before our work, not much computer security research had been done on how behaviors and biases affect the best defense mechanisms in a system. That's partly because humans are terrible at evaluating risk and an algorithm doesn't have any human biases," Bagchi said. "But for any system of reasonable complexity, decisions about security investments are almost always made with humans in the loop. For our algorithm, we explicitly consider the fact that different participants in an infrastructure system have different biases."

To develop the algorithm, Bagchi's team started by playing a game. They ran a series of experiments analyzing how groups of students chose to protect fake assets with fake investments. As in past studies in behavioral economics, they found that most study participants guessed poorly which assets were the most valuable and should be protected from security attacks. Most study participants also tended to spread out their investments instead of allocating them to one asset even when they were told which asset is the most vulnerable to an attack.

Using these findings, the researchers designed an algorithm that could work two ways: Either security decision makers pay a tax or fine when they make decisions that are less than optimal for the overall security of the system, or security decision makers receive a payment for investing in the most optimal manner.

"Right now, fines are levied as a reactive measure if there is a security incident. Fines or taxes don't have any relationship to the security investments or data of the different operators in critical infrastructure," Bagchi said.

In the researchers' simulations of real-world infrastructure systems, the algorithm successfully minimized the likelihood of losing assets to an attack that would decrease the overall security of the infrastructure system.

Bagchi's research group is working to make the algorithm more scalable and able to adapt to an attacker who may make multiple attempts to hack into a system. The researchers' work on the algorithm is funded by the National Science Foundation, the Wabash Heartland Innovation Network and the Army Research Lab.

Cybersecurity is an area of focus through Purdue's Next Moves, a set of initiatives that works to address some of the greatest technology challenges facing the U.S. Purdue's cybersecurity experts offer insights and assistance to improve the protection of power plants, electrical grids and other critical infrastructure.

 

Related News

Related News

Perry presses ahead on advanced nuclear reactors

Advanced Nuclear Reactors drive U.S. clean energy with small modular reactors, a new test facility at Idaho National Laboratory, and public-private partnerships accelerating nuclear innovation, safety, and cost reductions through DOE-backed programs and university simulators.

 

Key Points

Advanced nuclear reactors are next-gen designs, including SMRs, offering safer, cheaper, low-carbon power.

✅ DOE test facility at Idaho National Laboratory

✅ Small modular reactors with passive safety systems

✅ University simulators train next-gen nuclear operators

 

Energy Secretary Rick Perry is advancing plans to shift the United States towards next-gen nuclear power reactors.

The Energy Department announced this week it has launched a new test facility at the Idaho National Laboratory where private companies can work on advanced nuclear technologies, as the first new U.S. reactor in nearly seven years starts up, to avoid the high costs and waste and safety concerns facing traditional nuclear power plants.

“[The National Reactor Innovation Center] will enable the demonstration and deployment of advanced reactors that will define the future of nuclear energy,” Perry said.

With climate change concerns growing and net-zero emissions targets emerging, some Republicans and Democrats are arguing for the need for more nuclear reactors to feed the nation’s electricity demand. But despite nuclear plants’ absence of carbon emissions, the high cost of construction, questions around what to do with the spent nuclear rods and the possibility of meltdown have stymied efforts.

A new generation of firms, including Microsoft founder Bill Gates’ Terra Power venture, are working on developing smaller, less expensive reactors that do not carry a risk of meltdown.

“The U.S. is on the verge of commercializing groundbreaking nuclear innovation, and we must keep advancing the public-private partnerships needed to traverse the dreaded valley of death that all too often stifles progress,” said Rich Powell, executive director of ClearPath, a non-profit advocating for clean energy and green industrial strategies worldwide.

The new Idaho facility is budgeted at $5 million under next year’s federal budget, even as the cost of U.S. nuclear generation has fallen to a ten-year low, which remains under negotiation in Congress.

On Thursday another advanced nuclear developer working on small modular systems, Oregon-based NuScale Power, announced it was building three virtual nuclear control rooms at Texas A&M University, Oregon State University and the University of Idaho, with funding from the Energy Department.

The simulators will be open to researchers and students, to train on the operation of smaller, modular reactors, as well as the general public.

NuScale CEO John Hopkins said the simulators would “help ensure that we educate future generations about the important role nuclear power and small modular reactor technology will play in attaining a safe, clean and secure energy future for our country.”

 

Related News

View more

Community-generated green electricity to be offered to all in UK

Community Power Tariff UK delivers clean electricity from community energy projects, sourcing renewable energy from local wind and solar farms, with carbon offset gas, transparent provenance, fair pricing, and reinvestment in local generators across Britain.

 

Key Points

UK energy plan delivering 100% community renewable power with carbon-offset gas, sourced from local wind and solar.

✅ 100% community-generated electricity from UK wind and solar

✅ Fair prices with profits reinvested in local projects

✅ Carbon-offset gas and verified, transparent provenance

 

UK homes will soon be able to plug into community wind and solar farms from anywhere in the country through the first energy tariff to offer clean electricity exclusively from community projects.

The deal from Co-op Energy comes as green energy suppliers race to prove their sustainability credentials amid rising competition for eco-conscious customers and “greenwashing” in the market.

The energy supplier will charge an extra £5 a month over Co-op’s regular tariff to provide electricity from community energy projects and gas which includes a carbon offset in the price.

Co-op, which is operated by Octopus Energy after it bought the business from the Midcounties Co-operative last year, will source the clean electricity for its new tariff directly from 90 local renewable energy generation projects across the UK, including the Westmill wind and solar farms in Oxfordshire. It plans to use all profits to reinvest in maintaining the community projects and building new ones.

Phil Ponsonby, the chief executive of Midcounties Co-operative, said the tariff is the UK’s only one to be powered by 100% community-generated electricity and would ensure a fair price is paid to community generators too, amid a renewable energy auction boost that supports wider deployment.

Customers on the Community Power tariff will be able to “see exactly where it is being generated at small scale sites across the UK, and, with new rights to sell solar power back to energy firms, they know it is benefiting local communities”, he said.

Co-op, which has about 300,000 customers, has set itself apart from a rising number of energy supply deals which are marked as 100% renewable, but are not as green as they seem, even as many renewable projects are on hold due to grid constraints.

Consumer group Which? has found that many suppliers offer renewable energy tariffs but do not generate renewable electricity themselves or have contracts to buy any renewable electricity directly from generators.

Instead, the “pale green” suppliers exploit a loophole in the energy market by snapping up cheap renewable energy certificates, without necessarily buying energy from renewables projects.

The certificates are issued by the regulator to renewable energy developers for each megawatt generated, but these can be sold separately from the electricity for a fraction of the price.

A survey conducted last year found that one in 10 people believe that a renewables tariff means that the supplier generates at least some of its electricity from its own renewable energy projects.

Ponsonby said the wind and solar schemes that generate electricity for the Community Power tariff “plough the profits they make back into their neighbourhoods or into helping other similar projects get off the ground”.

Greg Jackson, the chief executive of Octopus Energy, said being able to buy locally-sourced clean, green energy is “a massive jump in the right direction” which will help grow the UK’s green electricity capacity nationwide.

“Investing in more local energy infrastructure and getting Britain’s homes run by the sun when it’s shining and wind energy when it’s blowing can end our reliance on dirty fossil fuels sooner than we hoped,” he said.

 

Related News

View more

Energy crisis is a 'wake up call' for Europe to ditch fossil fuels

EU Clean Energy Transition underscores the shift from fossil fuels to renewable energy, decarbonization, and hydrogen, as soaring gas prices and electricity volatility spur resilience, storage, and joint procurement across the single market.

 

Key Points

EU Clean Energy Transition shifts from fossil fuels to renewables, enhancing resilience and reducing price volatility.

✅ Cuts reliance on Russian gas and fossil imports

✅ Scales renewables, hydrogen, and energy storage

✅ Stabilizes electricity prices via market resilience

 

Soaring energy prices, described as Europe's energy nightmare, are a stark reminder of how dependent Europe is on fossil fuels and should serve to accelerate the shift towards renewable forms of energy.

"This experience today of the rising energy prices is a clear wake up call... that we should accelerate the transition to clean energy, wean ourselves off the fossil fuel dependency," a senior EU official told reporters as the European Commission unveiled a series of emergency electricity measures aimed at tackling the crisis.

The European Union is facing a sharp spike in energy prices, driven by increased global demand as the world recovers from the pandemic and lower-than-expected natural gas deliveries from Russia. Wholesale electricity prices have increased by 200% compared to the 2019 average, underscoring why rolling back electricity prices is tougher than it appears, according to the European Commission.

"Winter is coming and for many electricity costs are larger than they have been for a decade," Energy Commissioner Kadri Simson told reporters on Wednesday.

80 million European households struggle to stay warm
Wholesale gas prices — which have surged to record highs in France, Spain, Germany and Italy, amid reports of Germany's local utilities crying for help — are expected to remain high through the winter.

Prices are expected to fall in the spring, but remain higher than the average of past years, according to the Commission. Most EU countries rely on gas-fired power stations to meet electricity demand, and about 40% of that gas comes from Russia, with the EU outlining a plan to dump Russian energy to reduce this reliance, according to Eurostat.

Simson said that the Commission's initial assessment indicates that Russia's Gazprom has been fulfilling its long-term contracts "while providing little or no additional supply."
Kremlin spokesman Dmitry Peskov told journalists on Wednesday that Russia has increased gas supplies to Europe to the maximum possible level under existing contracts, but could not exceed those thresholds. "We can say that Russia is flawlessly fulfilling all contractual obligations," he said.

Measures EU states can take to help consumers and businesses cope with soaring electricity costs include emergency income support to households to help them pay their energy bills, alongside potential gas price cap strategies, state aid for companies, and targeted tax reductions. Member states can also temporarily delay bill payments and put in place processes to ensure that no one is disconnected from the grid.

Green energy the solution
The Commission also published a series of longer term measures the bloc should consider to reduce its dependence on fossil fuels and tackle energy price volatility, despite opposition from nine countries to electricity market reforms.

"Our immediate priority is to protect Europe's consumers, especially the most vulnerable," Simson said. "Second, we want to make our energy system better prepared and more resilient, so we don't have to face a similar situation in the future," she added.

Energy crisis could force more UK factories to close
This would require speeding up the green energy transition rather than slowing it down, Simson said. "We are not facing an energy price surge because of our climate policy or because renewable energy is expensive. We are facing it because the fossil fuel prices are spiking," she continued.

"The only long term remedy against demand shocks and price volatility is a transition to a green energy system."

Simson said she will propose to EU leaders a package of measures to decarbonize Europe's gas and hydrogen markets by 2050. Other measures to improve energy market stability could include increasing gas storage capacity and buying gas jointly at an EU level.

 

Related News

View more

Environmentalist calls for reduction in biomass use to generate electricity

Nova Scotia Biomass Energy faces scrutiny as hydropower from Muskrat Falls via the Maritime Link increases, raising concerns over carbon emissions, biodiversity, ratepayer costs, and efficiency versus district heating in the province's renewable mix.

 

Key Points

Electricity from wood chips and waste wood in Nova Scotia, increasingly questioned as hydropower from the Maritime Link grows.

✅ Hydropower deliveries reduce need for biomass on the grid

✅ Biomass is inefficient, costly, and impacts biodiversity

✅ District heating offers better use of forestry residuals

 

The Ecology Action Centre's senior wilderness coordinator is calling on the Nova Scotia government to reduce the use of biomass to generate electricity now that more hydroelectric power is flowing into the province.

In 2020, the government of the day signed a directive for Nova Scotia Power to increase its use of biomass to generate electricity, including burning more wood chips, waste wood and other residuals from the forest industry. At the time, power from Muskrat Falls hydroelectric project in Labrador was not flowing into the province at high enough levels to reach provincial targets for electricity generated by renewable resources.

In recent months, however, the Maritime Link from Muskrat Falls has delivered Nova Scotia's full share of electricity, and, in some cases, even more, as the province also pursues Bay of Fundy tides projects to diversify supply.

Ray Plourde with the Ecology Action Centre said that should be enough to end the 2020 directive.

Ray Plourde is senior wilderness coordinator for the Ecology Action Centre. (CBC)
Biomass is "bad on a whole lot of levels," said Plourde, including its affects on biodiversity and the release of carbon into the atmosphere, he said. The province's reliance on waste wood as a source of fuel for electricity should be curbed, said Plourde.

"It's highly inefficient," he said. "It's the most expensive electricity on the power grid for ratepayers."

A spokesperson for the provincial Natural Resources and Renewables Department said that although the Maritime Link has "at times" delivered adequate electricity to Nova Scotia, "it hasn't done so consistently," a context that has led some to propose an independent planning body for long-term decisions.

"These delays and high fossil fuel prices mean that biomass remains a small but important component of our renewable energy mix," Patricia Jreiga said in an email, even as the province plans to increase wind and solar projects in the years ahead.

But to Plourde, that explanation doesn't wash.

The Nova Scotia Utility and Review Board recently ruled that Nova Scotia Power could begin recouping costs of the Maritime Link project from ratepayers. As for the rising cost of fossil fuels, Ploude noted that the inefficiency of biomass means there's no deal to be had using it as a fuel source.

"Honestly, that sounds like a lot of obfuscation," he said of the government's position.

No update on district heating plans
At the time of the directive, government officials said the increased use of forestry byproducts at biomass plants in Point Tupper and Brooklyn, N.S., including the nearby Port Hawkesbury Paper mill, would provide a market for businesses struggling to replace the loss of Northern Pulp as a customer. Brooklyn Power has been offline since a windstorm damaged that plant in February, however. Repairs are expected to be complete by the end of the year or early 2023.

Ploude said a better use for waste wood products would be small-scale district heating projects, while others advocate using more electricity for heat in cold regions.

Although the former Liberal government announced six public buildings to serve as pilot sites for district heating in 2020, and a list of 100 other possible buildings that could be converted to wood heat, there have been no updates.

"Currently, we're working with several other departments to complete technical assessments for additional sites and looking at opportunities for district heating, but no decisions have been made yet," provincial spokesperson Steven Stewart said in an email.

 

Related News

View more

Multi-billion-dollar hydro generation project proposed for Meaford military base

Meaford Pumped Storage Project aims to balance the grid with hydro-electric generation, a hilltop reservoir, and transmission lines near Georgian Bay, pending environmental assessment, permitting, and federal review of impacts on fish and drinking water.

 

Key Points

TC Energy proposal to pump water uphill off-peak and generate 1,000 MW at peak, pending studies and approvals.

✅ Balances grid by storing off-peak energy and generating at peak.

✅ Requires reservoir, break wall, transmission lines, generating station.

✅ Environmental studies and federal review underway before approvals.

 

Plans for a $3.3 billion hydro-electric project in Meaford are still in the early study stages, but some residents have concerns about what it might mean for the environment, as past Site C stability issues have illustrated for large hydro projects.

A one-year permit was granted for TC Energy Corporation (TC Energy) to begin studies on the proposed location back in May, and cross-border projects like the New England Clean Power Link require federal permits as well to proceed. Local municipalities were informed of the project in June.

TC Energy is proposing to have a pumped storage project at the 4th Canadian Division Training (4CDTC) Meaford property, which is on federal lands.

A letter sent to local municipalities explains that the plan is to balance supply and demand on the electrical grid by pumping water uphill during off-peak hours. It would then release the water back into Georgian Bay during peak periods, generating up to 1,000 megawatts of electricity.

The project is expected to create 800 jobs over four years of construction, in addition to long-term operational positions.


 

According to the company's website, the proposed pump station would require a large reservoir on the military base, a generating station, transmission lines infrastructure, and a break wall 850 metres from shore.

Some residents fear the project will threaten the bay and the fish, echoing Site C dam concerns shared with northerners, and the region's drinking water.

Meaford's mayor says the town has no jurisdiction on federal lands, but that a list of concerns has been forwarded to the company, while Ontario First Nations have urged government action on urgent transmission needs elsewhere.

TC Energy will tackle preliminary engineering and environmental studies to determine the feasibility of the proposed location, which could take up to two years.

Once the assessments are done, they need to be presented to the government for further review and approval, as seen when Ottawa's Site C stance left work paused pending a treaty rights challenge.

TC Energy's website states that the company anticipates construction to begin in 2022 if it gets all the go-ahead, with the plant to begin operations four years later.

Input from residents is being collected until April 2020, similar to when the National Energy Board heard oral traditional evidence on the Manitoba-Minnesota transmission line.

 

Related News

View more

New England takes key step to 1.2 GW of Quebec hydro as Maine approves transmission line

NECEC Clean Energy Connect advances with Maine DEP permits, Hydro-Québec contracts, and rigorous transmission line mitigation, including tapered vegetation, culvert upgrades, and forest conservation, delivering low-carbon power, broadband fiber, and projected ratepayer savings.

 

Key Points

A Maine transmission project delivering Hydro-Québec power with strict DEP mitigation, lower bills, and added broadband.

✅ DEP permits mandate tapered vegetation, culvert upgrades, land conservation

✅ Hydro-Québec to supply 9.55 TWh/yr via MA contracts; bill savings 2-4%

✅ Added broadband fiber in Somerset and Franklin; local tax benefits

 

The Maine DEP reviewed the Clean Energy Connect project for more than two years, while regional interest in cross-border transmission continued to grow, before issuing permits that included additional environmental mitigation elements.

"Collectively, the requirements of the permit require an unprecedented level of environmental protection and compensatory land conservation for the construction of a transmission line in the state of Maine," DEP said in a May 11 statement.

Requirements include limits on transmission corridor width, forest preservation, culvert replacement and vegetation management projects, while broader grid programs like vehicle-to-grid integration enhance clean energy utilization across the region.

"In our original proposal we worked hard to develop a project that provided robust mitigation measures to protect the environment," NECEC Transmission CEO Thorn Dickinson said in a statement. "And through this permitting process, we now have made an exceedingly good project even better for Maine."

NECEC will be built on land owned or controlled by Central Maine Power. The 53 miles of new corridor on working forest land will use a new clearing technique for tapered vegetation, while the remainder of the project follows existing power lines.

Environmentalists said they agreed with the decision, and the mitigation measures state regulators took, noting similar momentum behind new wind investments in other parts of Canada.

"Building new ways to deliver low-carbon energy to our region is a critical piece of tackling the climate crisis," CLF Senior Attorney Phelps Turner said in a statement. "DEP was absolutely right to impose significant environmental conditions on this project and ensure that it does not harm critical wildlife areas."

Once complete, Turner said the transmission line will allow the region "to retire dirty fossil fuel plants in the coming years, which is a win for our health and our climate."

The Massachusetts Department of Public Utilities in June 2019 advanced the project by approving contracts for the state's utilities to purchase 9,554,940 MWh annually from Hydro-Quebec. Officials said the project is expected to provide approximately 2% to 4% savings on monthly energy bills.

Total net benefits to Massachusetts ratepayers over the 20-year contract, including both direct and indirect benefits, are expected to be approximately $4 billion, according to the state's estimates.

NECEC "will also deliver significant economic benefits to Maine and the region, including lower electricity prices, increased local real estate taxes and reduced energy costs with examples like battery-backed community microgrids demonstrating local resilience, expanded fiber optic cable for broadband service in Somerset and Franklin counties and funding of economic development for Western Maine," project developers said in a statement.​

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.