Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Biodiversity and Global Health: Intersection of Health, Security, and the Environment

One of the biggest consequences of large-scale environmental change is the loss of biodiversity. Recent studies predict a loss of 1 million species in the near future. Biodiversity loss and land use change through anthropogenic disturbance are known to affect disease exposure, disease severity, and disease impacts. It is becoming increasingly clear that biodiversity loss will lead to an increase in infectious diseases in certain regions. Changes in biodiversity may contain important signatures for prediction of infectious diseases and outbreaks. Here, we argue that areas of high or rapid biodiversity loss will be critical to monitor under the umbrella of global health security. Global Health Security consists of the actions and activities required to reduce the impact of public health events in populations living in different geographic regions and across international borders. Like infectious diseases, climate change and other causes of environmental changes do not respect international borders and are becoming more widespread in all parts of the world. Here, the relationships among biodiversity, climate and environmental changes, and pathogen prevalence are dynamic, context dependent, and complex. Accounting for this complexity requires the inclusion of the environment sector, presently missing, when evaluating the potential of global health security actions for mitigating disease risks.

59 BASIC BIOLOGICAL SCIENCES↗

Flexible visualization of a 3rd party Intrusion Prevention (Security) tool: A use case with the ELK stack

A difficult aspect of cyber security is the ability to achieve automated real time intrusion prevention across various sets of systems. To this extent, several companies are offering comprehensive solutions that leverage an "accuracy of scale" and moving much of the intelligence and detection on the Cloud, relying on an ever-growing set of data and analytics to increase decision accuracy. Often, they provide tools to visualize the decision workflows in attack prevention (as well as tune the algorithm) but those solutions are not always practical as companies see the problem as "global" that is, from a unified Cyber-security standpoint. However, a key to a successful Cyber-security program is transparency and trust: from an experimental team viewpoint, this specifically means having the ability to immediately see what and from where, who has been blocked and being able to inform the community in case of a revoked access without the need for filing a "ticket" (that may eventually be answered) – in other words, rapid response to their user-base is essential but solutions targeting "sub-groups" in an organization are not often available. We have come up with a versatile solution leveraging the ELK stack (Elasticsearch, Logstash, & Kibana) and an IPS (Intrusion Prevention System) based WAF (Web Application Firewall) from Signal Sciences. Signal Science allows the streaming of detailed logs in a Logstash format suitable for custom solutions for visualization. By combining these two tools, we have strengthened our security posture and enabled individual experiments to monitor their own traffic. Specifically, the IPS WAF provides unique data such as country of origin, protocol, response code, source IP, and paths accessed. In this contribution, we will show how we engineered a visualization solution so experiment groups could access a dashboard with predefined graphs but also, where they can create individual customizable dashboards used to display blocked traffic and troubleshoot latency issues. We will discuss the details and procedures for developing and configuring these tools and how it benefits cyber security postures across our scientific based environment.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Acoustic Measurements of Solvent Extraction Processes in Support of Safeguards

The proposed poster focuses on using acoustic monitoring to advance detection techniques for reprocessing equipment in support of nuclear safeguards. The usage of free air acoustic monitoring has been previously demonstrated at Idaho National Laboratory (INL) at facilities such as the Advanced Test Reactor and the National Security Test Range. However, this work focuses on a deployment environment dedicated to monitoring separation processes, using solvent extraction equipment such as centrifugal contactors. This environment offers an opportunity for signal discovery and in characterizing acoustic signatures of the equipment in operation. This data can support the development of safeguards by design and security by design measures for aqueous reprocessing facilities. Furthermore, this type of monitoring can aid in early detection and identification of removed materials indicating diversion, which is essential for initiating material recovery and actor identification. The results of this work include data from nine low-frequency acoustic sensors used to investigate potential acoustic characteristics of centrifugal contactors used in multi-stage processes. The results also discuss the correlation between the signatures and the operation of the contactor banks.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

97 MATHEMATICS AND COMPUTING↗

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

Modeling Data Flows with Network Calculus in Cyber-Physical Systems: Enabling Feature Analysis for Anomaly Detection Applications

The electric grid is becoming increasingly cyber-physical with the addition of smart technologies, new communication interfaces, and automated grid-support functions. Because of this, it is no longer sufficient to only study the physical system dynamics, but the cyber system must also be monitored as well to examine cyber-physical interactions and effects on the overall system. To address this gap for both operational and security needs, cyber-physical situational awareness is needed to monitor the system to detect any faults or malicious activity. Techniques and models to understand the physical system (the power system operation) exist, but methods to study the cyber system are needed, which can assist in understanding how the network traffic and changes to network conditions affect applications such as data analysis, intrusion detection systems (IDS), and anomaly detection. In this paper, we examine and develop models of data flows in communication networks of cyber-physical systems (CPSs) and explore how network calculus can be utilized to develop those models for CPSs, with a focus on anomaly and intrusion detection. This provides a foundation for methods to examine how changes to behavior in the CPS can be modeled and for investigating cyber effects in CPSs in anomaly detection applications.

97 MATHEMATICS AND COMPUTING↗

IoT Devices and Applications for Wire-Based Hybrid Manufacturing Machine Tools

Hybrid manufacturing machine tools have the potential to be a disruptive technology as they can leverage the benefits of both additive and subtractive manufacturing by incorporating both processes on the same machine while limiting the downsides of the individual processes. Since these machines use two very disparate manufacturing processes and hybrid manufacturing is an emerging technology, it will be useful to monitor data coming from the machine and apply it to improve the manufacturing process, the operation of the machine, and to integrate the machine into the larger digital framework of Industrial Internet of Things (IoT). The present work discusses IoT devices that would be beneficial to add to a hybrid machine tool as well as applications for those devices. The proposed methods discussed in this work have not been experimentally implemented on a hybrid machine tool and so there are no performance data available yet. The hybrid machine tool used as a basis to generate these IoT applications is the Mazak VC-500A/5x AM Hot Wire Deposition, which is a 5-axis machine tool incorporated with a wire feedstock 4kW laser deposition system. Methodologies and applications will be outlined for machine health and process monitoring. Other areas covered include process benchmarking, secure networking options for the proposed IoT framework, and hybrid process improvement. Limitations of these methods and future work for new sensor devices and application areas is also discussed.

Thien, Austen↗

Puck and Puck/SAW Loop Seals (Final Report)

Tamper-indicating devices (TIDs), also known as seals, play a crucial role in various sectors including international nuclear safeguards, arms control, domestic security, and commercial products, by ensuring that monitored or high-value items are not accessed undetected. These devices do not block access but alert to unauthorized tampering. With adversaries' capabilities evolving, there's a pressing need for seals to advance in terms of effectiveness (e.g., better tamper indication and unique identification), and new technology can improve the efficiency of installation and verification. Passive loop seals, widely used in international nuclear safeguards to ensure that continuity of knowledge is maintained on declared items, face stringent International Atomic Energy Agency (IAEA) requirements that surpass those met by commercial products. The metal cup seal (Figure 1, left), a staple IAEA seal, is robust but requires significant resources for post-use verification – specifically, the seal’s unique identity can only be verified at IAEA headquarters after removal from facilities. Further, the seal has been in use for decades and seal types should periodically be replaced to counter adversarial efforts for defeating seals. In 2020, the IAEA outlined about 40 requirements for a new passive loop seal, aiming for in-situ verification, minimal external tool use, unique identification (UID), and clear tamper indication. In response, research and development efforts focused on creating a new passive loop seal that meets these criteria and in 2022 the IAEA announced the completion of the Field Verifiable Passive Loop Seal (FVPS) (Figure 1, right). Concurrently to the IAEA’s efforts, Sandia National Laboratories (SNL) and Oak Ridge National Laboratory (ORNL) designed, developed, and tested two seal versions – Puck and Puck/SAW, with Puck based on the IAEA’s requirements and including a novel visually-obvious tamper response, and Puck/SAW adding additional beneficial capabilities like the ability to receive a unique identifier from a standoff distance and monitoring the wire integrity. Puck/SAW was specifically designed and developed to address sealing applications in dry spent fuel storage facilities, where the number of sealed spent fuel containers results in heavy verification burden and inspector safety issues related to radiation exposure. These efforts are described in this Executive Summary.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Signal Decomposition for Intrusion Detection in Reliability Assessment in Cyber Resilience (Summary Report)

The complexity of assuring cyber resilience for physical process interactions in connected systems such as energy grids increases dramatically as the coupling between processes becomes more direct and responsive. An example of this growing complexity is provided by Integrated Energy Systems (IES), in which various processes such as nuclear heat generation and commodity production are being directly coupled for increased responsiveness to highly variable signals such as market pricing or electricity demand. As such, the potential attack surface of the coupled processes is larger than the two processes independently. Securing these complex systems requires two-fold monitoring: cybersecure monitoring for potential malicious incursion, and physics monitoring for system tampering. Physics monitoring includes analyzing the behavior of the signals within the system for anomalous behavior. This analysis has been shown to be insufficient if approached by only data-driven machine learning and artificial intelligence (MLAI) techniques or only low-level model comparison. Previous efforts at Purdue University suggested combining high-fidelity models with MLAI algorithms as a basis for a software tool for detecting anomalies in physical processes. This work built on that suggestion, developing an advanced library for signal decomposition and analysis using both MLAI and high-fidelity physics algorithms for greatly improved anomaly detection, especially false data injection. This software can be used as part of a secure imbedded intelligence (SEI) system designed under Consequence-driven Cyber-informed Engineering (CCE) for complex coupled systems. This library established a foundation for online and posteriori analysis of digital signals for the purpose of detecting potential malicious tampering in digital signals representing physical processes. Demonstrations carried out throughout the development highlight the effective use of characterization algorithms to detect signal perturbations, particularly triangle attack-style perturbations, in three wide-ranging applications: seismic monitoring, nuclear thermal hydraulics system simulation, and custom manufacturing.

97 MATHEMATICS AND COMPUTING↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

2020 Postclosure Groundwater Monitoring and Inspection Report, Central Nevada Test Area, Subsurface Corrective Action Unit 443

This report presents the groundwater monitoring data collected by the U.S. Department of Energy (DOE) Office of Legacy Management (LM) from the Central Nevada Test Area (CNTA), Nevada, Site, Subsurface Corrective Action Unit (CAU) 443 in Nye County, Nevada (Figure 1). The CNTA is the site of an underground nuclear test in 1968 that resulted in residual contamination near the detonation depth of 3200 feet (ft); the contamination requires long-term monitoring. Responsibility for the environmental restoration and long-term monitoring was transferred from DOE’s National Nuclear Security Administration, Nevada Field Office, to LM on October 1, 2006. The environmental restoration and site closure process were completed in 2015 in accordance with the amended 1996 Nevada Federal Facility Agreement and Consent Order (FFACO) (State of Nevada et al. 1996, as amended) and all applicable Nevada Division of Environmental Protection (NDEP) policies and regulations. The Closure Report, Central Nevada Test Area, Subsurface Corrective Action, Unit 443 (DOE 2018), also called the Closure Report, originally was completed in January 2016 and revised in October 2018; it describes LM’s plan for long-term postclosure monitoring. This includes monitoring of the radioisotopes of interest and water elevations, inspecting the site and maintaining the institutional controls (ICs), evaluating and reporting data, and documenting the site’s records and data management processes (DOE 2018).

54 ENVIRONMENTAL SCIENCES↗

Y-12 Groundwater Protection Program Data Management Plan

This Data Management Plan (DMP) describes the processes in place to ensure the integrity of groundwater monitoring information collected by the U.S. Department of Energy (DOE), National Nuclear Security Administration (NNSA), Y-12 National Security Complex (Y-12), Groundwater Protection Program (GWPP). This information includes program plans, reports, and computer systems used to capture monitoring station information and analytical data. The primary computer system used by the GWPP is the Groundwater Information Management System (GIMS). Procedures used to ensure the integrity of the data are included in this document by reference.

54 ENVIRONMENTAL SCIENCES↗

Casing Annulus Monitoring of CO 2 Injection Using Wireless Autonomous Distributed Sensor Networks

Effective and secure carbon subsurface storage, involving the deep underground injection of CO 2 into geological formations where it is permanently trapped, is paramount to mitigating CO 2 emissions (Figure I). Ensuring the integrity of these storage sites and detecting potential leakage through the casing annulus necessitates robust monitoring. This work provides the first integrated demonstration of a wireless casing-annulus monitoring architecture that can operate in highly attenuating cement-brine environments relevant to CO 2 storage. This project focused on developing and validating a novel sensor system for integration with autonomous monitoring near the cement reservoir interface. The goal was a fully integrated Technology Readiness Level (TRL) 4/5 field validation of a distributed wireless intelligent sensor system providing real-time, direct subsurface formation measurements to enhance fluid movement monitoring in the cemented casing annulus. Achieving this objective required the development and integration of 1) wireless autonomous microsensor technology by California Institute of Technology (Caltech); 2) sensor packaging and emplacement technology by Research Triangle Institute (RTI); and 3) smart well completions using wireless active casing collars and NOV pipe by the Sandia National Lab (SNL). The collaboration with the Caltech team in this project aimed to develop millimeter-scale radio frequency identification (RFID) sensors capable of detecting CO 2 , pH, and/or methane levels. These sensors are engineered to be impervious to fluids, allowing them to be mixed with cement and installed within the casing annulus. They operate using RFID protocols at frequencies of 902–928 MHz for both power and communication. A Sandia National Laboratories’ team engaged their expertise in the development of a Smart Collar system designed for the wireless data collection from these RFID sensors embedded in the cement annulus and transmission of this information to the ground surface via IntelliPipe/IntelliServ NOV drill pipe. This is accomplished through inductive coupling at the collar, which facilitates data transfer through each segment of the pipe. Because the system cannot transmit a direct current signal to power the Smart Collar, both power and communication were implemented using alternating current and electromagnetic signals at varying frequencies. Furthermore, the developed microsensor technology had to be demonstrated and validated in comparison with reference transducer measurements in a field test site at The University of Texas at Austin (UT-Austin). Although the full sensor suite did not reach field-deployment readiness, the system-level integration achieved in this project establishes a validated pathway for future incorporation of advanced microsensors.

47 OTHER INSTRUMENTATION↗

Post-Closure Monitoring Letter Report for Corrective Action Unit (CAU) 97: Yucca Flat/Climax Mine; CAU 98: Frenchman Flat; and CAU 99: Rainier Mesa/Shoshone Mountain, Underground Test Area, Nevada National Security Site, Nevada, for Calendar Year 2020 (Rev. 1, May 2021)

This letter serves as the annual post-closure letter for Corrective Action Unit (CAU) 97, Yucca Flat/Climax Mine (YF/CM); CAU 98, Frenchman Flat (FF); and CAU 99, Rainier Mesa/Shoshone Mountain (RM/SM) for calendar year (CY) 2020. This letter will discuss the post-closure monitoring activities that occurred during CY 2020, identify any triggers reached, and summarize water usage on the Nevada National Security Site (NNSS) and surrounding hydrographic basins at the three CAUs.

54 ENVIRONMENTAL SCIENCES↗

DATASET RELEASE AND QUALITY CONTROL REVIEW OF LIVERMORE NEVADA NETWORK (LNN) RECORDINGS OF A SUBSET OF NEVADA NUCLEAR SECURITY SITE NUCLEAR EXPLOSIONS FROM 1979 TO 1992.

Geophysical research on historical nuclear tests is an important aspect of future monitoring capabilities in seismic research. This research is challenging due to the limited number of digital seismic recordings during the peak of nuclear testing (1945-1992). These limited records are unique and non-reproducible data with potential high research impact. Releasing available nuclear explosion seismic records to the explosion monitoring community is thus of high value and is the motivation for this dataset release. The target of this effort was on compilation and quality control of regional seismic records of nuclear explosions recorded on Lawrence Livermore National Laboratory stations ELK, KNB, LAC, and MNV, known collectively as the Livermore National Network (LNN) (Figure 1). LNN was established in the early 1960s for the primary purpose of monitoring underground nuclear testing at the former Nevada Test Site (NTS), now known as the Nevada Nuclear Security Site (NNSS) following the signing of the Limited Test Ban Treaty (LTBT). LNN consisted initially of short-period vertical component Benioff’s recorded on film located at Mina, NV (MNV) and Kanab, Utah (KNB). LNN added two additional stations at Landers, CA (LAC) and Elko, NV (ELK) in 1967 and upgraded equipment to broadband seismometers recorded on frequency modulation (FM) tapes from 1967-1979, followed by digital recordings after 1979 (Jarpe, 1989). The digital recordings were on a variety of now obsolete media, including 9-track, Exabyte, and DAT tapes. Jarpe (1989) describes the seismic station instrumentation details over the period of deployment. LNN recorded valuable non-repeatable unique data of several hundreds of nuclear explosions at NNSS, as well as earthquakes and chemical and mining explosions (Walter, 2020). The details of these nuclear tests are provided in the Department of Energy Report NV-209 Rev 16 (DOE, 2015).

58 GEOSCIENCES↗

Monitoring Operational States of a Nuclear Reactor Using Seismoacoustic Signatures and Machine Learning

Monitoring nuclear reactors is an important safety and security task with growing requirements. We explore the possibility of using seismic and acoustic data for inferring the power level of an operating reactor. Continuous data recorded at a single seismoacoustic station that is located about 50 m away from a research reactor was visualized and analyzed. The data show a clear correlation between seismoacoustic features and reactor main operational states. We designed a workflow that includes two machine learning (ML) models to classify the reactor operational states (OFF, transition, and ON) and estimate reactor power levels (10%, 30%, 50%, 70%, and 90%). We applied and compared five ML algorithms for the reactor OFF-transition-ON and four approaches for the power level classification. We also compared the performance of ML models trained with seismic-only, acoustic-only, and both types of data. Five-fold cross validations were implemented to assure a thorough evaluation of the model performances. Additionally, the results show the extreme boosting gradient algorithm worked best for the first model, whereas random forests performed best for the second model. Combining seismic and acoustic data leads to better performance than using a single type of data. Seismic data contributed more than acoustic data for both models. We reached an accuracy of 0.98 for reactor OFF and ON. The accuracies for the transition state and power levels are less optimal with a minimum accuracy of 0.66. However, our results suggest seismic and acoustic data contain useful information about the transition state as well as power levels. Seismic and acoustic data could be integrated with other observations to improve monitoring performance.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Remotely Sensed High‐Resolution Soil Moisture and Evapotranspiration: Bridging the Gap Between Science and Society

This paper reviews the current state of high‐resolution remotely sensed soil moisture (SM) and evapotranspiration (ET) products and modeling, and the coupling relationship between SM and ET. SM downscaling approaches for satellite passive microwave products leverage advances in artificial intelligence and high‐resolution remote sensing using visible, near‐infrared, thermal‐infrared, and synthetic aperture radar sensors. Remotely sensed ET continues to advance in spatiotemporal resolutions from MODIS to ECOSTRESS to Hydrosat and beyond. These advances enable a new understanding of bio‐geo‐physical controls and coupled feedback mechanisms between SM and ET reflecting the land cover and land use at field scale (3–30 m, daily). Still, the state‐of‐the‐science products have their challenges and limitations, which we detail across data, retrieval algorithms, and applications. We describe the roles of these data in advancing 10 application areas: drought assessment, food security, precision agriculture, soil salinization, wildfire modeling, dust monitoring, flood forecasting, urban water, energy, and ecosystem management, ecohydrology, and biodiversity conservation. We discuss that future scientific advancement should focus on developing open‐access, high‐resolution (3–30 m), sub‐daily SM and ET products, enabling the evaluation of hydrological processes at finer scales and revolutionizing the societal applications in data‐limited regions of the world, especially the Global South for socio‐economic development.

54 ENVIRONMENTAL SCIENCES↗