Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Cyber-Informed Engineering (CIE) Benefits Quantification: Recommendations for Consideration

Cyber-Informed Engineering (CIE) integrates engineering principles into the design, development, and operation of cyber-physical systems (CPS) to mitigate or eliminate the impact of cyber-enabled attacks. In July 2024, Idaho National Laboratory (INL) engaged MITRE researchers to investigate methods for systematically measuring the benefits of CIE implementation. This included evaluating the success and outcomes of CIE, identifying and quantifying the value of early adoption, and determining the business justification for its implementation, especially in existing infrastructure. MITRE reviewed existing methods in engineering and cybersecurity to understand how organizations prioritize security investments, considering their strengths, weaknesses, and relevance to CIE stakeholders. Based on this analysis, MITRE proposed potential approaches for quantifying CIE benefits and provided recommendations for INL's consideration.

42 ENGINEERING↗

Requirements Framework for Cyber-Informed Engineering

The existing requirements frameworks or models cater to the existing practices. However, they fall short in directly using them for Cyber informed engineering. Therefore, this paper develops and presents a comprehensive framework that can be used for Cyber informed Engineering during the requirements phase. We describe the existing requirements process and models, then develop a requirements framework for cyber informed engineering.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING↗

Cyber-physical cascading failure and resilience of power grid: A comprehensive review

Smart grid technologies are based on the integration of the cyber network and the power grid into a cyber-physical power system (CPPS). The increasing cyber-physical interdependencies bring about tremendous opportunities for the modeling, monitoring, control, and protection of power grids, but also create new types of vulnerabilities and failure mechanisms threatening the reliability and resiliency of system operation. A major concern regarding the interdependent networks is the cascading failure (CF), where a small initial disturbance/failure in the network results in a seemingly unexpected large-scale failure. Although there has been a significant volume of recent work in the CF research of CPPS, a comprehensive review remains unavailable. This article aims to fill the gap by providing a systematic literature survey regarding the modeling, analysis, and mitigation of CF in CPPS. The open research questions for further research are also discussed. This article allows researchers to easily understand the state of the art of CF research in CPPS and fosters future work required towards full resolutions to the remaining questions and challenges.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Bayesian Estimation of Oscillator Parameters: Toward Anomaly Detection and Cyber-Physical System Security

Cyber-physical system security presents unique challenges to conventional measurement science and technology. Anomaly detection in software-assisted physical systems, such as those employed in additive manufacturing or in DNA synthesis, is often hampered by the limited available parameter space of the underlying mechanism that is transducing the anomaly. As a result, the formulation of anomaly detection for such systems often leads to inverse or ill-posed problems, requiring statistical treatments. Here, we present Bayesian inference of unknown parameters associated with a generic actuator considered as a representative vital element of a cyber-physical system. Via a series of experimental input-output measurements, a transfer function for the actuator is obtained numerically, which serves as our model for the proposed method. Linear, nonlinear, and delayed dynamics may be assumed for the actuator response. By devising a code-based malicious signal, we study the efficacy of Bayesian inference for its potential to produce a detection, including uncertainty quantification, with a remarkably small number of input data points. Our approach should be adaptable to a variety of real-time cyber-physical anomaly detection scenarios.

47 OTHER INSTRUMENTATION↗

Transforming Cyber Education thru Open to All Accessible Pathways

Boise State University’s (BSU) Cyber Operations and Resilience CORe program was intentionally designed so that any student, especially non-traditional and non-technical students, with an interest in cybersecurity could have an education and training pathway to enter the cyber workforce. The CORe curriculum focuses on teaching students how to design, apply, and improve cybersecurity through the interaction of people, processes, and technology. CORe is a stackable curriculum with elective credit hours and options for various academic and industry certificates and certifications that enable students to customize their unique career pathway. The CORe program guides students to think about the system being managed, the risks presented, and the dynamic intersection of system elements when considering how to incorporate resilience frameworks in achieving a resilient system. By developing systems thinking, the students gain an understanding of the interdependencies interacting with the operational system. Further, the CORe program encourages students to integrate cybersecurity knowledge with models and frameworks found in other academic disciplines through a unifying systems approach. CORe is designed around the realities of today’s broad cyber landscape: that breaches will occur in any system over time and proactive design of resilience into systems to detect, respond, and recover in a timely and orderly manner is critical. Students are taught to think holistically about cybersecurity focusing on all system elements. CORe is not a traditional cybersecurity degree. CORe is distinguished by the non-traditional engineering, computer science approach to cybersecurity education with the singular focus on infusing resilience operations and transdisciplinary systems thinking principles throughout the curriculum.

99 GENERAL AND MISCELLANEOUS↗

Scalable, Physical Effects Measurable Microgrid for Cyber Resilience Analysis (SPEMMCRA)

The ability to advance state of the art automated protections for industrial control systems (ICS) has as a precursor in the ability to understand the tradeoff space. That is, to enable a cyber feedback loop in a control system environment you must first consider both the security mitigation available, the benefits and the impacts to the control system functionality when the mitigation is used. More damaging impacts could be precipitated that the mitigation was intended to rectify. This paper details networked ICS that controls a simulation of the frequency response represented with the swing equation. The microgrid loads and base generation can be balanced through the control of an emulated battery and power inverter. The simulated plant, which is implemented in Raspberry Pi computers, provides an inexpensive platform to realize the physical effects of cyber attacks to show the tradeoffs of available mitigatoins. This network design can include a commercial ICS controller to introduce real world implementation of feedback controls, and provides a scalable, physical effects measurable Microgrid for cyber resilience analysis (SPEMMCRA).

42 ENGINEERING↗

Cyber Physical Grid-Interactive Distributed Energy Resources Control for VPP Dispatch and Regulation: Preprint

This paper presents a cyber-physical algorithm for grid interactive DER control to enable two features of Virtual Power Plants (VPPs) dispatch and grid voltage regulation, considering the communication and security impacts. We first formulate the DER dispatch problem as a real-time, iterative, and grid-interactive DER control problem. Thereafter, we consider a probabilistic traffic model to characterize packet delays and loss in a communication network, and study how the delays enter the process of information exchange among the grid measurement units, local DER controllers and the grid control center that coordinately execute this dispatch algorithm. Finally, we propose a cyber-physical grid-interactive DER control algorithm using the previous message strategy. The tracking and regulation capabilities of this proposed algorithm can be made immune to the asynchrony resulting from the communications network traffic. We carry out simulations to show possible numerical instabilities and sensitivities of the tracking and regulation capabilities on the proposed strategy. Our results exhibit that the uncertainties of the underlying communications infrastructure must be considered in the control algorithm for the VPP tracking and regulation capabilities of any DER in a generic Cyber-Physical System (CPS).

co-simulation↗

Deconstructing the Nuclear Supply Chain Cyber-Attack Surface

The nuclear supply chain cyber-attack surface is a large, complex network of interconnected stakeholders and activities. The global economy has widened and deepened the supply chain resulting in larger numbers of geographically dispersed locations and increased difficulty ensuring the authenticity and security of digital assets. Although the nuclear industry has made significant strides in securing facilities from cyber-attacks, the supply chain remains vulnerable. This paper provides further details on each of the elements in the Digital I&C System Supply Chain Cyber-Attack Surface, including supply chain lifecycle activities, key stakeholders, touchpoints, and attack types. Deconstructing this attack surface provides insights into supply chain threats, vulnerabilities, and consequences. These insights will lead to improvements in cybersecurity supply chain risk analysis, development of new cybersecurity supply chain processes and tools, and enhancement of overall supply chain resilience.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Informed Engineering Principles: What’s in it for me?

CIE is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system that has digital connectivity, monitoring, or control. CIE complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Rather, it expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve, and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences. Engineers and technicians that design critical energy infrastructure installations can integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. These principles are aimed at system or design engineers, operators, and technicians, rather than software engineers or operational cybersecurity practitioners, because the engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. This approach creates new opportunities for engineering teams—and not just cybersecurity teams—to secure the system using the physics and mechanics of engineering controls—not just digital monitoring and controls.

99 GENERAL AND MISCELLANEOUS↗

Cyber Threat Landscape and Engineering Mitigations for Grid Forming Inverters

This talk will cover the cyber threat landscape and engineering mitigations for grid forming (GFM) inverters. It will discuss the penetration of inverter-based resources (IBRs) in the United States and expected growth. It will then discuss the threat landscape for IBRs based on current and expected penetration. Real-world examples of cyber incidents affecting IBRs will be presented, concluding with an introduction to Cyber-Informed Engineering (CIE) and a guide on applying it to GFM inverters.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Machine Learning Based Resilience Testing of an Address Randomization Cyber Defense

Moving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. Here, in this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

Enhancing the distribution grid resilience using cyber-physical oriented islanding strategy

The increasing penetration of distributed generations enables an innovative operation paradigm that allows islanded operation to enhance the resilience of the distribution grid. In this study, a cyber-physical oriented islanding strategy is proposed by coordinating centralised and distributed control to achieve seamless islanding transition and operational flexibility in emergency conditions. A cyber-physical control structure is developed to mitigate various disturbances (e.g. emergencies or fluctuations) according to different operation conditions. Specifically, the distributed fault isolation and seamless islanding transition are coordinated to mitigate the outage caused by unplanned islanding, while a secondary control is proposed to support primary control by reducing the power fluctuations during islanded operation. With a rapid response speed, the local cyber-physical devices are coordinated to accomplish islanding separation by selecting a feasible islanded area even under an unplanned islanding situation. A field test was conducted on a practical distribution network in China, and the results demonstrated the effectiveness and feasibility of the proposed islanding strategy.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-physical security framework for Photovoltaic Farms

With the evolution of PV converters, a growing number of vulnerabilities in PV farms are exposing to cyber threats. To mitigate the influence of cyber-attack on PV farms, it is necessary to study attacks' impact and propose detection methods. To meet this requirement, a cyber-physical security framework is proposed for PV farms. Data integrity attacks (DIAs) are studied on different control loops. As μPMU is gaining in popularity, a lower sampling rate of μPMU data is applied to develop a detection algorithm. We have evaluated two data-driven methods, which are support vector machine (SVM) and long short-term memory (LSTM). Lastly, the data-driven methods verify the feasibility of μPMU data in attack detection.

Attack Impact Analysis↗