IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 8329 A Real-Time Cyber-Physical Simulation Testbed for Cybersecurity Assessment of Large-Scale Power Systems Thai-Thanh Nguyen , Senior Member, IEEE, Rahul Kadavil, Senior Member, IEEE, and Hossein Hooshyar , Senior Member, IEEE Abstract—In this paper, a real-time cyber-physical simulation (RTCPS) testbed is developed to assess the cybersecurity of largescale power systems. The simulation testbed includes real-time simulations of power grids and communication networks, allowing for the integration of physical hardware and providing a realistic representation of power system operations. Real-time simulators from OPAL-RT and RTDS technologies are used to simulate power grids, whereas EXata network modeling is used to emulate the communication network in real time. The communication network within the testbed includes information technology (IT) and operational technology (OT) systems, which enable a comprehensive assessment of the impact of cybersecurity issues on power systems. Since the developed simulation testbed comprises various simulation tools, multiple scripts are developed to automate the simulation and launch cyber attacks on communication networks. These scripts allow the testbed to simulate a large number of scenarios with minimal effort, which is crucial in collecting data for training machine learning models. Various realistic attacks on the IT and OT networks, including phishing email attack, steal credentials, denial of service, remote access attack, and man-in-the-middle attack will be presented. The setup of the RTCPS testbed for a simple scenario is described, allowing researchers to understand and reproduce the simulation. Furthermore, an additional setup for a large-scale cyber-physical simulation scenario is presented to demonstrate the capabilities of the RTCPS testbed. Index Terms—Cybersecurity, large-scale cyber-physical power systems, real-time simulation testbed, cyber attacks. I. INTRODUCTION CYBER-PHYSICAL power system combines physical electric power components, like generators, transformers, and transmission lines, along with cyber components, including communication networks, data management systems, and A Received 15 February 2024; revised 29 May 2024; accepted 26 July 2024. Date of publication 10 September 2024; date of current version 15 November 2024. Paper 2023-PSEC-1591.R1, presented at the 2023 IEEE Industry Applications Society Annual Meeting, Nashville, TN, USA, 29 Oct.–Nov. 02, and approved for publication in the IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS by the Power Systems Engineering Committee of the IEEE Industry Applications Society [DOI:10.1109/IAS54024.2023.10406799.] (Corresponding author: Thai-Thanh Nguyen.) The authors are with the Advanced Grid Innovation Laboratory for Energy (AGILe), New York Power Authority, Albany, NY 12203 USA (e-mail: thaithanh.nguyen@nypa.gov; rahul.kadavil@nypa.gov; hossein.hooshyar@ nypa.gov). Color versions of one or more figures in this article are available at https://doi.org/10.1109/TIA.2024.3457877. Digital Object Identifier 10.1109/TIA.2024.3457877 control systems. The increasing reliance on communication networks and the public internet makes power systems more vulnerable to cyber-attacks, which can significantly impact the stability and reliability of the grid. A simulation testbed of cyberphysical power systems, which provides a realistic environment, enables power system operators and cybersecurity researchers to simulate a wide range of scenarios, including cyber attacks, and test the effectiveness of cybersecurity measures before implementation. The cyber-physical simulation testbed for industry utility users needs to be accurate and scalable in order to comprehensively model large utility networks. It should incorporate robust security features to simulate vulnerabilities and attacks, advanced visualization tools for interpreting results, and interoperability with existing utility systems. User-friendly interfaces are essential for accessibility, while comprehensive training and support ensure effective utilization of the tool. Meeting these requirements allows utility users to simulate and optimize their cyber-physical power systems, ensuring reliability, resilience, and security across critical infrastructure networks. However, existing cyber-physical simulation testbeds require improvement to meet these requirements. The use of real communication networks in previous studies [1], [2], [6], [8], [12], [13], [14] limits the scalability of these testbeds. Communication network emulations used in existing testbeds, such as NS-3 [5], CORE [4], OPNET [7], [9], [10], and Mininet [11] rely on scripting and a command-line interface. This shortcoming makes them less accessible to a wide range of users, esppecially for those without extensive programming skills. Automation for cyber-physical simulation testbeds, including cyber and power systems, allows users to focus on higher-level analysis. It enables rapid exploration of various scenarios, replication of cyber attack scenarios, and testing of adaptive defense mechanisms. However, this feature has not been discussed in previous studies. Realistic power grid models are essential in cybersecurity for the industry utilities as they enable accurate simulation of cyber threats and their impacts, providing a realistic environment to develop and validate the practical mitigation strategies. However, existing testbeds are developed using synthetic power grid models like the IEEE test systems. Numerous studies have been conducted to review existing cyber-physical simulation testbeds [15], [16], [17], [18], [19]. However, none of these studies focus on real-time simulation 0093-9994 © 2024 IEEE. Personal use is permitted, but republication/redistribution requires IEEE permission. See https://www.ieee.org/publications/rights/index.html for more information. Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8330 IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 TABLE I REAL-TIME CYBER-PHYSICAL SIMULATION TESTBEDS* testbeds. The real-time simulation testbed is expected to play a crucial role in future industrial practice as it is designed to simulate real-world scenarios in real-time. Developing such testbeds can provide researchers and power system operators with a platform to assess cybersecurity in a safe and controlled environment. This approach can reduce the risks associated with deploying new technologies or solutions in the field. Table I summarizes the existing real-time cyber-physical simulation testbed, as well as the proposed real-time cyber-physical simulation (RTCPS) testbed. The comparison of the existing testbeds with the RTCPS testbed is based on three key metrics that are essential for evaluating the effectiveness and efficiency of the real-time cyber-physical simulation testbed. These metrics are: the simulator used for simulating power and cyber systems, the size of the power and cyber systems, and the implemented capabilities. The following parts will elaborate on these metrics. As given in Table I, real-time simulators, such as those offered by OPAL-RT or RTDS technologies, are commonly used for power system simulation. Some testbeds utilize a pair of real-time simulators, like PowerCyber [1], cyber-physical federated co-simulation [11], cyber-physical co-simulation [12], and RTCPS testbed. By using different real-time simulators for Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. NGUYEN et al.: REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED FOR CYBERSECURITY ASSESSMENT OF LARGE-SCALE POWER SYSTEMS power systems, these testbeds offer the advantages of flexibility and the ability to simulate large-scale power systems. To enable the real-time simulation capability of the testbeds, the cyber system in these testbeds is represented by either the real communication network or the real-time communication network emulators. While most testbeds rely on real communication networks, various communication network emulators are also used, such as QualNet network simulator (QualNet), common open research emulator (CORE), NS-3 network simulator (NS3), OPNET network simulator (OPNET), and Mininet. Using communication network emulators brings scalability benefits to the simulation testbed. This paper presents an alternative use of communication network emulation called EXata network modeling (EXata). One advantage of EXata over its open-source alternatives is that it’s fault-tolerant and battle-tested in an IT/OT environment, which is the norm in the utility landscape. The use of EXata network emulation enables real-time integration with live networks, allowing the creation of digital twins of electric power grids and their associated critical infrastructure networks. This feature, along with its user-friendly graphical interface, advanced visualization tools, and scalability for large-scale network emulation, make EXata particularly advantageous to industry professionals. The intuitive interface simplifies network design, simulation, and analysis, making it accessible to a wide range of users, including those without extensive programming skills. This ease of use reduces the learning curve and speeds up simulation setup, benefiting both researchers and industry professionals. These features make EXata particularly suitable for practical applications in utility critical infrastructure networks. The sizes of simulated power systems vary from ten to thousands of buses. Most of the existing testbeds rely on IEEE test systems, such as IEEE 9-bus system [1], [6], [8], [12], [13], IEEE 13-bus feeder [2], [11], IEEE 14-bus system [5], and IEEE 37-bus feeder [14]. Only a few testbeds have the capability to simulate large-scale transmission power systems. Among these, there are the cyber-physical federated co-simulation testbed [11] and RTCPS testbed. While the former use the WECC 179-bus transmission system, we utilize one of our developed models of the New York State (NYS) power grid. The NYS power grid model presented in [20] is used in this study, which includes transmission systems with voltage levels ranging from 230 kV to 765 kV. It is worth noting that the developed RTCPS testbed can include different models of the NYS power grid, such as full EMT models presented in [21], Phasor models, and hybrid EMT-Phasor models [22]. The size of the cyber system refers to whether the cyber system includes information technology (IT) and/or operational technology (OT) systems. The vast majority of testbeds focus on the OT system, where the control and management systems interact with the physical power systems. The cyber-physical federated co-simulation testbed [11] and RTCPS testbed consist of IT and OT systems. These testbeds offer a more holistic perspective and a comprehensive simulation environment for cyber-physical systems. The simulation testbeds listed in Table I support various industrial control system (ICS) protocols, such as Modbus, DNP3, IEC 61850, and IEEE C37.118. Additionally, these testbeds have the capability of hardware-in-the-loop (HIL) simulation. 8331 However, while some testbeds implement various ICS protocols and HIL capability, others do not. Existing testbeds including cyber-physical federated co-simulation testbed [11] only implement cyber attacks on the OT network, such as denial-of-service (DoS), man-in-the-middle (MiTM), false command injection (FCI), and false data injection (FDI). On the other hand, the proposed RTCPS testbed implements cyber attacks on both the OT and IT networks, such as phishing attack, steal credentials, remote access attack, DoS attack, and MiTM attack. RTCPS testbed offers a more comprehensive approach for cybersecurity assessment of the large-scale cyber-physical power system. The RTCPS testbed proposed in this paper comprises a variety of real-time simulators widely used in the industry, such as OPAL-RT, RTDS, and EXata. The testbed is designed to facilitate the simulation of large-scale cyber-physical power systems. Various scripts are developed to automate the simulation testbed, including Python scripts to coordinate the RTDS and OPAL-RT real-time simulators and an adaptive attack script to perform various cyber-attacks in a desired sequence. These scripts enable the testbed to simulate a large number of scenarios with minimal effort. This paper is an extended version of [23]. In this paper, the development of a simple simulation setup is presented in detail, including how to set up the testbed, configure the communication systems, and the required scripts. The provided information is intended to help researchers quickly reproduce the simulation testbed for their investigations. Furthermore, a complex simulation setup is also presented to demonstrate the feasibility of the RTCPS testbed in assisting the cybersecurity of large-scale power systems. The main contribution of this paper is as follows. r Propose a realistic cyber-physical simulation testbed for testing and demonstrating the cybersecurity solutions. The proposed testbed is developed based on the electromagnetic transient (EMT) model of the New York State power grid. r The proposed testbed is scalable and able to simulate a large-scale cyber and power systems. r The automation process is proposed to allow users to focus on higher-level analysis, making the testbed easy accessible for a wide range of users, such as industry professionals or researchers. The remainder of this paper is organized as follows: Section II describes the power system, cyber system, and the RTCPS testbed for a simple scenario. This section also explains the developed scripts to automate the simulation. The simulation results are provided in Section III-A. Section III-B explains the supported capabilities of the RTCPS testbed and the additional scenario for large-scale cyber-physical simulation. Finally, the key findings and recommendations are presented in Section V. II. REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED Fig. 1 depicts a typical configuration of a cyber-physical power system, which combines electric power components such as generators, transformers, and transmission lines, with cyber components including communication networks, data management systems, and control systems. Fig. 2 provides an overview of the RTCPS tested presented in this paper. The RTCPS testbed Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8332 IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 Fig. 1. Typical cyber-physical power system. Fig. 2. An overview of the real-time cyber-physical simulation testbed. Fig. 3. model. Electric diagram of the 345-kV substation in the NYS power grid Fig. 4. Network diagram of the cyber system. incorporates real-time simulations of power grids and real-time emulation of the communication network. Physical hardware and power system operators can participate in the real-time simulation with hardware-in-the-loop and human-in-the-loop interfaces. The following subsections provide a description of the RTCPS testbed for a simple scenario, allowing researchers to understand and reproduce the simulation. A. Electric Power Grid The model used in this study encompasses transmission systems with voltage levels ranging from 230 kV to 765 kV, comprising 322 three-phase buses, 109 generators, 119 transformers, and 354 transmission lines. The RSCAD simulation software is utilized to model the NYS power grid in the electromagnetic transient (EMT) domain. The real-time RTDS simulators are then employed to simulate the RSCAD NYS power grid model in real time. A detailed explanation of the NYS power grid model used in this study can be found in [20]. The NYS power grid model includes crucial components such as the phasor measurement unit (PMU) and remote terminal unit (RTU). These components are simulated in the RTDS simulator to test and analyze the grid’s performance under different conditions. The PMU transmits synchronized phasor measurement data to the phasor data concentrator (PDC) via the IEEE C37.118 synchrophasor protocol. On the other hand, the RTUs monitor signals from various sensors and devices in the power grid and send them to the control center, which, in turn, sends control signals to the RTUs. The communication between the RTUs and the control center is based on the DNP3 protocol. Both the PDC and the control center are modeled in the OPAL-RT simulator. Fig. 3 shows the location of PMUs and RTUs in a 345-kV substation considered in this paper. Seven PMUs are used to transmit synchronized phasor measurement data to the PDC, and one RTU is used to monitor and control four circuit breakers (CBs). B. Cyber System Fig. 4 depicts the cyber system modeled in this paper, which comprises the IT and OT systems, and the external system. The OT system includes hardware and software that manage, monitor, and control physical power systems, such as PMU, RTU, PDC, and the control center. Traditionally, OT devices are kept separate from the public internet, allowing only authorized Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. NGUYEN et al.: REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED FOR CYBERSECURITY ASSESSMENT OF LARGE-SCALE POWER SYSTEMS TABLE II CONFIGURATION OF OPERATIONAL HOST MODEL TABLE III CONFIGURATION OF PMU AND RTU DEVICES users to access them. The IT system facilitates communication and data exchange among multiple users, including those needing authorization to access the OT system. As IT devices can access the public internet, firewall devices are deployed to protect the IT system. These firewall devices prevent unauthorized access and protect the IT system from cyber-attacks. Attackers from the external system may attempt to hack into IT and OT systems. These attackers can exploit vulnerabilities in software, hardware, or human errors. The EXata network modeling allows for real-time simulation of large-scale communication networks using high-fidelity scenarios [24]. In Fig. 4, each component of the cyber system is modeled by an EXata node that comprises a network interface and an operational host model. The network interface is assigned an IP address, while the operational host emulates the operating scenarios and applications running on each node. The operational host model comprises the host and user profiles. The host profile includes the vulnerability attack model, while the user profile can be configured with email access and specifies how frequently the user clicks on phishing emails. Table II depicts the operational host models of EXata nodes. Two user profiles can be configured: an active user who talks with many contacts, accesses many files, and surfs many sites frequently; and a quiet user who talks with few contacts and accesses fewer files occasionally. For example, three users (Users 1∼3) in the IT system have email access and talk with many contacts. The host and user profiles of these users are window and active, respectively. These users are highly prone to phishing email attacks. The OT system focuses on the 345-kV substation, as given in Fig. 3. The configuration of the PMU and RTU devices is shown in Table III. The IEEE C37.118 protocol is used for communication between PMU and PDC, whereas the DNP3 protocol is used for communication between RTU and the control center. C. Real-Time Cyber-Physical Simulation Testbed A detailed diagram of the RTCPS setup is shown in Fig. 5. The RTCPS testbed is a comprehensive platform that comprises both 8333 hardware and software components to conduct various experiments. The hardware components of the RTCPS testbed include RTDS, OPAL-RT, an EXata server, a personal computer (PC), and an Ethernet switch. These components are interconnected to create a network that facilitates the exchange of data and information between the different components. The software components of the RTCPS testbed include RSCAD, RT-Lab, EXata network modeling software, and EXata connection manager. These software tools are used to model and simulate the cyber and power systems. 1) Hardware Components: Three real-time simulation platforms are used: RTDS simulator for the electric power system, EXata server for the cyber system, and OPAL-RT simulator for the control center and PDC. The PDC and control center are implemented on the Opal-RT platform due to the absence of the PDC library component in the RTDS environment. The network interface cards are used in RTDS and OPAL-RT to provide the real-time communication link via Ethernet. The GTNETx2 cards are used in RTDS while the Quad Port Ethernet server adapter are used in OPAL-RT. These cards can be used with different ICS protocols, such as the IEEE C37.118, DNP3, IEC 61850, and Modbus. The limited number of GTNET cards in RTDS restricts the implementation of various ICS protocols. Leveraging the Opal-RT system allows for the expansion of both ICS protocols within the testbed and power grid models. The IP addresses and default gateways of GTNETx2, QuadPort server adapter, EXata server, and User 2’s PC are given in Fig. 5. These IP addresses are on the same network subnet. It should be noted that the default gateway of GTNETx2, QuadPort server adapter, and User 2’s PC is the IP address of the EXata server. It’s a required step for EXata to map physical devices with its virtual counterparts to successfully link and run the network emulation process. 2) Software and Tools: Various software and tools are utilized in the modeling and simulation of cyber and power systems. In particular, RSCAD software is used to model the power system, and the RSCAD RunTime software is utilized to control the simulation of the power system which is carried out on the RTDS simulator. The EXata network modeling software is used to model the cyber system and interact with the real-time network emulation that runs on the EXata server. This software tool is used to simulate the behavior of the cyber system and its interaction with the power system. The RT-Lab software is utilized to model the control center and PDC and to interact with the OPAL-RT simulator. Finally, the EXata connection manager application is installed on User 2’s PC. This application establishes a connection between the User 2’s PC and the EXata server. With this connection established, the user can run the Email Inbox application, which allows them to receive and send emails in real-time. 3) Integrate Cyber System Emulation With Power System Simulations: In order to integrate the emulation of the cyber system with the power system simulations, the network interfaces on EXata nodes are mapped onto physical network interfaces at Layer 3 using an IP address. This mapping allows the data exchange among OT devices to be passed through the EXata network emulation, and User 2 can interact with the IT and OT emulation networks. Table IV shows the IP addresses of Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8334 Fig. 5. IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 Connection diagram of the RTCPS testbed. TABLE IV CONNECTIONS BETWEEN EXATA NODES AND PHYSICAL NODES into the behavior of the cyber-physical system and identify any potential vulnerabilities or security threats. D. Automate Simulation the EXata nodes and their corresponding physical IP addresses. The mapping editor in EXata GUI is used to create a mapping between OT devices with the EXata server, while the EXata connection manager is used to create the mapping between User 2 with the EXata server. 4) Packet Sniffing: One of the useful features of the EXata network modeling is its ability to make the traffic inside the simulated network visible to an external packet sniffing tool such as Wireshark. This is done by configuring the packet sniffing interface in the EXata GUI. With this feature, researchers and cybersecurity professionals can log the simulated traffic data and use it for various purposes, such as assessing the security of their network or training machine learning models. By analyzing the captured traffic data, researchers can gain valuable insights The RTCPS testbed includes various hardware and software components, as described in Section II-C. Operating such a complex system seamlessly is challenging, and it requires a lot of effort and expertise. Automation scripts are the key to address the challenge, which involves the use of a master Python script to coordinate RTDS and OPAL-RT simulations. This allows the RTDS and OPAL-RT simulators to operate in a desired sequence and to ensure the successful establishment of the communication link between OT devices. Fig. 6 shows a flowchart of the master Python script. A detailed explanation of this automation process is as follows: r The RTDS script, written in C program language from RTDS is utilized to manage the electric power grid simulation model. It starts by extracting the scenario configuration from a text file, which includes details such as load profile, fault locations, fault type, and fault impedance. This information is then used in the next step to set the RSCAD model. At the end of this step, the ListenOnPort is enabled on a specific Port, allowing the master Python script to take control of the RTDS simulator. Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. NGUYEN et al.: REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED FOR CYBERSECURITY ASSESSMENT OF LARGE-SCALE POWER SYSTEMS 8335 Fig. 7. DNP3 and Synchrophasor messages captured by Wireshark during normal operation. Fig. 6. A flowchart of the master Python script to coordinate OPAL-RT and RTDS simulations. r Command RTDS to run scenario i and continuously check RTDS output’s messages r The RTDS script receives a command to run scenario i. The RSCAD model is set according to the scenario i ’s configuration that is extracted from the first step, then re-complied and run on the RTDS simulators. When the RSCAD model runs successfully, the Success status message is sent through the ListenOnPort. RTDS runs freely for 30 seconds before applying events. This allows the simulation of power grid models to reach a steady-state condition and also ensures that Opal-RT starts successfully. r When the Success status message is detected, an OPAL-RT python script is triggered to initiate Opal-RT simulation. This involves loading and running the RTLab model on the Opal-RT simulators. The OPAL-RT python script utilizes the RT-Lab Python API, RtlabApi, to manage the RT-Lab model. r Apply power system events defined in the scenario configuration to the RTDS simulation, such as fault, load change, and tranmission line switching. After the events are cleared, the RTDS simulation runs for 30 seconds in order to capture enough information for the post-analysis. It should be noted that the simulation duration after clearing events may vary depending on the case studies. After RTDS simulation stops, the Stop status message is sent through the ListenOnPort. r Reset Opal-RT simulation when the Stop status message is detected and repeat these above steps for the next scenario. In addition, various cyber attacks on the communication network are launched automatically using an adaptive attack script that includes a sequence of adaptive attacks. An adaptive attack is a type of cyber attack launched based on the success or failure of a previous attack. For example, the attacker sends a phishing email to a user with an attachment. The attackers can proceed to launch the next attack if the user downloads the attachment. An example of the adaptive attack script is explained in details in Section III-A2. III. SIMULATION RESULT A. Basis Setup of the RTCPS Testbed This section describes the operation of the cyber-physical power system under normal and cyber-attack conditions. The RTDS script runs first and the ListenOnPort is enabled on Port 4575 to allow the master Python script to take control of the RTDS simulator. Next, the Opal-RT simulation starts to establish the connection between OT devices, such as PMU and PDC, as well as RTU and control center. The following subsections explain the operation of the testbed during power system events. 1) Normal Operation: The purpose of evaluating the RTCPS testbed under normal operating conditions is to ensure that the RTCPS testbed functions correctly. In this condition, PMUs send synchrophasor data to the PDC, and the control center is able to send commands to RTU to open/close circuit breakers. By enabling the packet sniffing interface in EXata GUI, Wireshark can capture the network traffic within the EXata emulation, allowing users to analyze and understand the traffic flowing through the emulation network. Fig. 7 shows DNP3 and the Synchrophasor messages captured by Wireshark. It can be seen that the communication link between OT devices is successfully established, and the background traffic in the IT network is also included. The control center successfully opens one circuit breaker by sending an open command to RTU. PDC successfully receives the synchrophasor data from PMUs. 2) Adaptive Attacks: To gain valuable insights into a system’s behavior, it is crucial that the simulation testbed accurately represents the cyber-physical power system under realistic cyber attacks. These attacks can be sophisticated, planned, and executed over months before an actual power outage. An adaptive attack script is developed to replicate such cyber attacks, allowing for various cyber attacks to be conducted on both the IT and OT networks in a realistic manner. This approach helps to ensure that the RTCPS testbed accurately simulates the Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8336 Fig. 8. IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 A flowchart of adaptive attack script. potential impact of real-world cyber attacks on the power system. A flowchart of the adaptive attack script is shown in Fig. 8. The following cyber attacks are simulated: r Phishing attack: The attackers use a phishing attack to compromise user accounts. Several users within a corporate network are sent emails that contain malicious attachments, resulting in the installation of malware on their computers upon opening the attachments. Such malware provide attackers with backdoor entry into the corporate network. r Steal credentials: The attackers have the ability to find and gain entry to active directory servers, allowing them to obtain login information. r Scanning Attack: The attackers use the stolen credentials to access the OT network and subsequently subsequently perform the scanning attack to explore the OT network. r DoS Attack: The attackers perform a DoS attack on the RTU node, making the RTU device unresponsive to commands from the control center. Fig. 9 illustrates cyber attacks targeting various locations and devices, including corporate users on the IT network, router, and RTU on the OT networks. The sequence of adaptive attacks history shown in Fig. 10 is explained as follows: a) Phishing email attack: At 13:50, attacker 1 sends a phishing email to User 2in the IT coporate network. At 13:51, User 2 opens the attachment in the email, opening the door to attacker to gain access to the IT network. Attacker 1 successfully gained the root and user credentials of User 2. Fig. 11 shows the phishing attack log captured by Wireshark. b) Steal root credentials: In order to get the root credential of the Firewall device, the user credential is needed. As shown in Fig. 10, attacker 1 only can steal the root credential at 13:52 after gaining the user credential. Fig. 12 shows the steal root credential attack log captured by Wireshark. c) Scanning attack: At 13:52, attacker 1 performs the network scan attack to scan the OT network. Three open IP addresses are found: router (190.0.4.1), PMU (190.0.4.7), and RTU (190.0.4.8). Attacker 1 can map the network topology and identify targets. Fig. 13 shows the network scan attack log captured by Wireshark. The OT network is scanned by sending the ping request message. Fig. 9. Cyber attacks on the IT and OT networks. Fig. 10. Sequence of cyber-attacks on IT and OT systems. d) DoS attack: Attackers explored the OT network and decided to launch a denial-of-service (DoS) attack on the RTU node at 13:55. Three attackers (190.0.1.1, 190.0.1.2, and 190.0.1.3) send massive SYN requests to the RTU node (190.0.4.8) to overwhelm it with open connections, as shown in Fig. 13. At this time, the RTU device is unresponsive to commands from the control center. B. Advanced Setup of RTCPS Testbed for Large-Scale Cyber-Physical System This section presents an additional simulation setup for a large-scale cyber-physical power system to show the capabilities of the RTCPS testbed. In this setup, the power system includes Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. NGUYEN et al.: REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED FOR CYBERSECURITY ASSESSMENT OF LARGE-SCALE POWER SYSTEMS Fig. 14. Fig. 11. 8337 DoS attack log. Phishing email attack log. Fig. 12. Attaker 1 steals the Firewall’s root credential. Fig. 13. Ping request message during network scan attack. the EMT model of the entire NYS power grid. The cyber system includes a control center and multiple remote sites, as shown in Fig. 15. Data from 55 PMUs located at remote sites is streamed in real-time to the control center and stored on the openPDC data server. Power system operators interact with the human-machine interface (HMI) that allows operators to open or close circuit breakers via RTUs installed at the local and remote sites. To simulate the attackers’ ability to gain physical access to the OT network, the Raspberry Pi node is initially deactivated and then activated during the simulation. This section provides various cyber attack scenarios targeting different locations and devices within the NYS power grid, such as Data Transfer Attack targeting the openPDC data server, Remote Access Attack targeting the circuit breakers at different critical locations of the NYS power grid, and Man-in-The-Middle Attacks targeting the RTU that controls STATCOM at a substation. These attacks demonstrate the testbed’s capability to simulate a wider range of scenarios that are of interest to utilities. 1) Data Transfer Attack: In this scenario, the attacker sends a phishing email with a malicious attachment to the corporate network users. When the users open the attachment, the attackers are able to steal credentials that give them access to the firewall and OT devices. Consequently, the attackers can steal sensitive data from the data center and transfer it to the attacker’s PC. These attacks are launched automatically by an adaptive attack script. Fig. 16 shows the screenshot of the adaptive attack log and traffic captured by Wireshark. Data from the data center (190.0.3.3) is transferred to the attacker’s PC (190.0.1.1) using UDP. 2) Remote Access Attack: The attackers use a phishing attack to compromise user accounts within a corporate network. Upon opening the attachments, malware is installed, which enables the attackers to steal an existing user credential of the HMI machine. Fig. 17 illustrates the sequence of cyber attacks that lead to remote access of the HMI machine. The attackers are able to gain access to the control center using credentials obtained from the compromised HMI machine. As a result, the attackers are able to open and close circuit breakers located at different critical locations, causing severe oscillations in power systems and generation outages. Fig. 18 shows the system frequency and the generator speed of the generator that experiences an outage. 3) Man-in-The-Middle Attacks: Attackers can gain access to the local area network (LAN) for OT devices by compromising corporate network users and installing malware on OT devices, such as the LAN’s router. Furthermore, attackers can physically access substations and plug in a Raspberry Pi to gain access to the LAN. [25]. These two attack scenarios are simulated in this paper. In the first scenario, the attackers compromise the LAN’s router in order to launch MiTM attack using false data injection (FDI). The attackers intercept and manipulate the communication between the STATCOM and its controller on the HMI Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8338 Fig. 15. IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 The screenshot of the EXata model for the large-scale cyber-physical simulation setup. Fig. 17. Fig. 16. Data transfer attack scenario: (a) sequence of cyber attacks launched by the adaptive attack script; (b) attack log captured by Wireshark. machine. The STATCOM generates reactive power, which is measured by PMU and sent to the data center. The controller then uses this measurement to calculate the control signal (dQ) to operate the STATCOM. Fig. 19 shows the reactive power output under normal operation and the MiTM attack. At 53 s, the STATCOM is commanded to generate reactive power from 0 pu to 0.25 pu, and it can be observed that the measured reactive power follows the reference (Qref ). At 59 s, attackers manipulate the synchrophasor data by modifying the PMU data packet. The STATCOM’s controller detects a deviation in the measured reactive power from Qref and generates a command, A sequence of cyber attacks to gain remote access to the HMI. Fig. 18. Impact of remote access attack on the power system: (a) system frequency; (b) generator speed of the generator that experiences an outage. dQ, to compensate for the deviation. However, due to the manipulation of the measured reactive power signal caused by the MiTM attack, the controller cannot function properly, resulting in severe oscillations in the reactive power output. In the second scenario, the simulation involves attackers who gain physical access to the local site and connect a Raspberry Pi to the OT network. This is carried out in EXata by initially disabling the Raspberry Pi node and then enabling it during the simulation. From the Raspberry Pi, the attackers launch an Address Resolution Protocol (ARP) spoofing attack by sending spoofed ARP messages to the RTU and HMI devices. The ARP Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. NGUYEN et al.: REAL-TIME CYBER-PHYSICAL SIMULATION TESTBED FOR CYBERSECURITY ASSESSMENT OF LARGE-SCALE POWER SYSTEMS 8339 TABLE V SUPPORTED CAPABILITY OF THE RTCPS TESTBED Fig. 19. Impact of the MiTM attack on STATCOM: (a) reactive power output; (b) control command generated by the control center. IV. DISCUSSION Fig. 20. Traffic captured on the attacker’s PC (Raspberry Pi). Fig. 21. Impact of FCI attack on the power grid: (a) bus voltage; (b) transmission line current; (c) STATCOM’s reactive power output; (d) Tripping signals of the circuit breaker (CB1) and distance relay (21). spoofing attack leads these devices to incorrectly forward the DNP3 traffic to the Raspberry Pi computer, giving the attackers the ability to intercept and modify the DNP3 data. The attackers launch the false command injection (FCI) attack by initiating the direct-operate commands to open and close circuit breaker (CB1) at the local site. Fig. 20 shows the screenshot of the DNP3 traffic captured on the attacker’s PC. The impact of the FCI attack on the power grid is shown in Fig. 21. The attackers send the command to open CB1 at 3.15 s, causing an interruption in power transfer through the transmission line. In addition, it also has a slight impact on the STATCOM. It is worth mentioning that the distance relay (21) does not detect any abnormal condition, thereby keeping the tripping signal unchanged. The RTCPS testbed can be set up to simulate a more complex scenario of the large-scale cyber-physical power system. Table V summarizes the supported capabilities of the RTCPS testbed. The utilization of RTDS and OPAL-RT simulators allows for the simulation of the entire NYS power grid in EMT, phasor, or hybrid EMT-phasor domains. It also enables real-time co-simulation of RTDS and OPAL-RT, wherein a detailed EMT model of the offshore wind farms is simulated on OPAL-RT, while the EMT model of the NYS power grid is simulated on RTDS. The RTCPS supports various industry-standard communication protocols, such as IEC 61850, DNP3, IEEE C37.118, and Modbus. Moreover, it supports hardware-in-theloop (HIL) simulation, allowing physical hardware components such as protective relays, PMUs, and RTAC to be integrated into a simulated environment. On the other hand, concerning cyber system simulation, the EXata software can model any network device, protocol, or configuration and simulate thousands of nodes while enabling hardware-in-the-loop simulation. Therefore, cyber-attacks are not limited to the EXata cyber library, which primarily focuses on IT systems. They can also originate from physical attackers’ PCs targeting OT systems, such as man-in-the-middle (MiTM) attacks. Additionally, EXata network modeling supports a human-in-the-loop interface, allowing power system operators and cybersecurity researchers to interact with the simulated cyber system and the simulated power system. V. CONCLUSION This paper has presented a real-time cyber-physical simulation testbed for assessing the cybersecurity of the large-scale cyber-physical power systems. The presented testbed integrates real-time simulators of power grids and communication networks, allowing physical hardware and power system operators to be involved in the simulation loop. The Python scripts, RTDS’s script, and adaptive attack script were developed to automate the simulation testbed, enabling the simulation of Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply. 8340 IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, VOL. 60, NO. 6, NOVEMBER/DECEMBER 2024 many scenarios with minimal effort. The testbed provides a realistic and controllable cyber-physical environment for power system operators to evaluate the resilience of their systems against cyber-attacks and to test the effectiveness of cybersecurity measures before implementation. In addition, cybersecurity researchers can leverage the testbed to develop and test machinelearning models for enhanced cybersecurity assessment. REFERENCES [1] A. Ashok, S. Krishnaswamy, and M. Govindarasu, “PowerCyber: A remotely accessible testbed for cyber physical security of the smart grid,” in 2016 IEEE Power Energy Soc. Innov. Smart Grid Technol. Conf., 2016, pp. 1–5. [2] M. M. S. Khan, A. Palomino, J. Brugman, J. Giraldo, S. K. Kasera, and M. Parvania, “The cyberphysical power system resilience testbed: Architecture and applications,” Computer, vol. 53, no. 5, pp. 44–54, 2020. [3] H. Tong, M. Ni, L. Zhao, and M. Li, “Flexible hardware-in-the-loop testbed for cyber physical power system simulation,” IET Cyber-Phys. Syst.: Theory Appl., vol. 4, no. 4, pp. 374–381, 2019. [4] V. Venkataramanan, A. Srivastava, and A. Hahn, “Real-time co-simulation testbed for microgrid cyber-physical analysis,” in 2016 Workshop Model. Simul. Cyber- Phys. Energy Syst., 2016, pp. 1–6. [5] C. B. Vellaithurai, S. S. Biswas, and A.K. Srivastava, “Development and application of a real-time test bed for cyber–physical system,” IEEE Syst. J., vol. 11, no. 4, pp. 2192–2203, Dec. 2017. [6] S. Poudel, Z. Ni, and N. Malla, “Real-time cyber physical system testbed for power system security and control,” Int. J. Elect. Power Energy Syst., vol. 90, pp. 124–133, 2017. [Online]. Available: https: //www.sciencedirect.com/science/article/pii/S0142061516312911 [7] B. Chen, K. L. Butler-Purry, A. Goulart, and D. Kundur, “Implementing a real-time cyber-physical system test bed in RTDS and OPNET,” in 2014 North Amer. Power Symp., 2014, pp. 1–6. [8] U. Adhikari, T. Morris, and S. Pan, “WAMS cyber-physical test bed for power system, cybersecurity study, and data mining,” IEEE Trans. Smart Grid, vol. 8, no. 6, pp. 2744–2753, Nov. 2017. [9] G. Cao et al., “Real-time cyber- physical system co-simulation testbed for microgrids control,” IET Cyber-Phys. Syst.: Theory Appl., vol. 4, no. 1, pp. 38–45, 2019. [10] Z. Wang, D. Qi, J. Mei, Z. Li, K. Wan, and J. Zhang, “Real-time controller hardware-in-the-loop co-simulation testbed for cooperative control strategy for cyber-physical power system,” Glob. Energy Interconnection, vol. 4, no. 2, pp. 214–224, 2021. [11] V. Venkataramanan, P. S. Sarker, K. S. Sajan, A. Srivastava, and A. Hahn, “Real-time federated cyber-transmission-distribution testbed architecture for the resiliency analysis,” IEEE Trans. Ind. Appl., vol. 56, no. 6, pp. 7121–7131, Nov./Dec. 2020. [12] J. M. Riquelme-Dominguez, F. Gonzalez-Longatt, A. F. S. Melo, J. L. Rueda, and P. Palensky, “Cyber-physical testbed co-simulation real-time: Normal and abnormal system frequency response,” IEEE Trans. Ind. Appl., vol. 60, no. 2, pp. 2643–2652, Mar./Apr. 2024. [13] A. Chawla, M. A. Aftab, S. S. Hussain, B. Panigrahi, and T. S. Ustun, “Cyber–physical testbed for wide area measurement system employing IEC 61 850 and IEEE C37. 118 based communication,” Energy Rep., vol. 8, pp. 570–578, 2022. [14] A. Ashok and T. Edgar, “A high-fidelity cyber-physical testbed-based benchmarking dataset for testing operational technology specific intrusion detection systems,” in 2021 IEEE Int. Symp. Technol. Homeland Secur., 2021, pp. 1–7. [15] R. V. Yohanandhan et al., “A specialized review on outlook of future cyber-physical power system (CPPS) testbeds for securing electric power grid,” Int. J. Elect. Power Energy Syst., vol. 136, 2022, Art. no. 107720. [16] M. H. Cintuglu, O. A. Mohammed, K. Akkaya, and A. S. Uluagac, “A survey on smart grid cyber-physical system testbeds,” IEEE Commun. Surv. Tut., vol. 19, no. 1, pp. 446–464, Firstquarter 2017. [17] A. A. Smadi, B. T. Ajao, B. K. Johnson, H. Lei, Y. Chakhchoukh, and Q. A. Al-Haija, “A comprehensive survey on cyber-physical smart grid testbed architectures: Requirements and challenges,” Electronics, vol. 10, no. 9, 2021, Art. no. 1043. [18] S. V. B. Rakas, M. D. Stojanović, and J. D. Marković-Petrović, “A review of research work on network-based SCADA intrusion detection systems,” IEEE Access, vol. 8, pp. 93083–93108, 2020. [19] X. Zhou, X. Gou, T. Huang, and S. Yang, “Review on testing of cyber physical systems: Methods and testbeds,” IEEE Access, vol. 6, pp. 52179–52194, 2018. [20] M. Abdelmalak et al., “PSS/E to RSCAD model conversion for large power grids: Challenges and solutions,” in 2021 IEEE Power Energy Soc. Gen. Meeting, 2021, pp. 1–5. [21] J. Thapa et al., “Plug-and-play regional models for real-time electromagnetic transient simulations of large-scale power grids: A case study of New York state power grid,” IEEE Access, vol. 11, pp. 87600–87614, 2023. [22] M. Abdelmalak, H. Hooshyar, E. Farantatos, G. Stefopoulos, R. Kadavil, and M. Benidris, “Real-time emt-phasor co-simulation modeling for largescale power grids: Challenges and solutions,” in 2022 IEEE Power Energy Soc. Gen. Meeting, 2022, pp. 1–5. [23] T.-T. Nguyen, H. Hooshyar, and R. Kadavil, “A real-time cyber-physical simulation testbed for cybersecurity assessment of power systems,” in 2023 IEEE Ind. Appl. Soc. Annu. Meeting, 2023, pp. 1–5. [24] “EXata network modeling,” 2022. [Online]. Available: https://www.key sight.com/us/en/product/SN100EXBA/exata-network-modeling.html [25] “Researchers found they could hack entire wind farms,” 2017. [Online]. Available: https://www.wired.com/story/wind-turbine-hack/ Thai-Thanh Nguyen (Senior Member, IEEE) received the B.S. degree in electrical engineering from the Hanoi University of Science and Technology, Hanoi, Vietnam, in 2013, and the Ph.D. degree in electrical engineering from Incheon National University, South Korea, in 2019. From 2019 to 2022, he was a Postdoctoral Researcher and a Research Professor with Incheon National University, South Korea, and a Research Associate with Clarkson University, Potsdam, NY, USA. Since April 2022, he has been an Engineer with the Advanced Grid Innovation Laboratory for Energy (AGILe), New York Power Authority, White Plains, NY, USA. His research interests include power system modeling and control, power converter control, the application of power electronics to power systems, and cyber-physical power systems. Rahul Kadavil (Senior Member, IEEE) received the B.E. degree in electrical engineering from Fr. C. Rodrigues Institute of Technology, University of Mumbai, Mumbai, India, in 2009, and the M.S. degree in electrical engineering from Colorado State University, Fort Collins, CO, USA, in 2017. He was engaged as a Research Engineer with the Power and Energy Real-Time Laboratory (PERL), Idaho National Laboratory for modeling and integration testing of Hybrid Energy Storage Systems (HESS) using real-time simulation tools. He is currently a Manager with the Advanced Grid Innovation Lab for Energy (AGILe), New York Power Authority, White Plains, NY, USA. He designs and tests hardware in the loop experiments to analyze the diverse smart technologies and understand how they complement each other. His research interests includes power systems digital simulation, digital twins, protection, cyber-physical testbeds, and integration of renewable energy resources. He is the second inventor of Energy Storage Ramping Optimization for aggregating ramping capabilities from multiple HESS. Hossein Hooshyar (Senior Member, IEEE) received the Ph.D. degree in electrical engineering from North Carolina State University, Raleigh, NC, USA, in 2012. He has been the Director of the Advanced Grid Innovation Laboratory for Energy (AGILe), New York Power Authority (NYPA), White Plains, NY, USA, since 2022. Prior to joining NYPA, he took various research positions with the Electric Power Research Institute (EPRI), White Plains, NY, the Rensselaer Polytechnic Institute, Troy, NY, USA, the KTH Royal Institute of Technology, Sweden, and the Luleå University of Technology, Sweden. He is the coauthor of more than 80 scientific articles in accredited journals and international conferences, and the co-owner of a U.S. patent. His research interests include digital simulation of power systems, integration of renewable energy resources, and applications of PMU data for smart grids. He was the co-winner of the Research and Development 100 Awards. He is the Chair of the IEEE Task Force on Digital Twin of Large Scale Power Systems. Authorized licensed use limited to: UNIVERSITAT POLITECNICA DE CATALUNYA. Downloaded on October 27,2025 at 22:05:53 UTC from IEEE Xplore. Restrictions apply.
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )