Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level Risks
Anna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah, Emad Abukhousa, Betelihem Ashebo, Animesh Chhotaray, Daniel K. Molzahn, Frank Li, Saman Zonouz, Raheem Beyah
Abstract
Grid-connected solar distributed energy resources (DERs), such as solar inverters and monitoring platforms, have been deployed at unprecedented scale over the past few years, with global solar capacity more than doubling since 2022. To support monitoring and control, many of these systems are Internet-connected and configured by installers or end users, yet the real-world scale of their Internet exposure and the implications for power grid operation remain poorly understood. In this paper, we present an Internet-scale evaluation of exposed and vulnerable solar DER infrastructure, and assess the risk that compromised DERs can pose to energy grids. We develop a method for accurately identifying solar DERs from Internet scanning data, and discover a diverse population of over 66,000 Internet-exposed solar DERs. We detect that at least 10,000 of these DERs may have known CVEs, such as unauthenticated monitoring and control endpoints. To assess the risk that these vulnerable DERs pose to a power grid, we use an electric grid network for Oahu, Hawaii, established and used by the power system research community, and conduct a power system analysis. Our evaluation shows that by compromising exposed DERs, attackers can cause voltage and line flow violations across multiple locations in the Oahu network, resulting in a range of consequences from degraded power quality to damaged power system components to power outages. Ultimately, our work brings to light the emerging threat of grid-connected DERs, and provides directions for improving energy security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 38bb27d5-adc0-4fb9-ab18-384519cd76fbBuilds on15
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 348 citations
- Not Everything is Dark and Gloomy: Power Grid Protections Against IoT Demand AttacksBing Huang, Alvaro A. Cárdenas, Ross BaldickUSENIX Security 2019 · 87 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
Related papers
- ReThink: Reveal the Threat of Electromagnetic Interference on Power InvertersFengchen Yang, Zihao Dan, Kaikai Pan, Chen Yan et al.NDSS 2025
- Hall Spoofing: A Non-Invasive DoS Attack on Grid-Tied Solar InverterAnomadarshi Barua, Mohammad Abdullah Al FaruqueUSENIX Security 2020
- Shedding Light on Inconsistencies in Grid Cybersecurity: Disconnects and RecommendationsBrian Singer, Amritanshu Pandey, Shimiao Li, Lujo Bauer et al.S&P 2023
- Digital Healthcare-Associated Infection: A Case Study on the Security of a Major Multi-Campus Hospital SystemLuis Vargas, Logan Blue, Vanessa Frost, Christopher Patton et al.NDSS 2019 · 7 citations
- ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management SystemsTony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha et al.NDSS 2023
