Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “time security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

A Time-Domain Protection Approach for AC Transmission Systems With Grid-Forming Resources

Ac transmission protection must reliably detect, classify, and locate short-circuit faults from voltage and current measurements. At present, these functionalities, which have been classically engineered using phasors approaches, are being challenged by the dynamic behavior and fault-current limits of converter-based generation. This paper tackles these challenges by engineering a time-domain protection approach that leverages the classical Bergeron model in a new manner. Low- and high-impedance faults are detected and classified by ascertaining how well line voltage and current measurements match the Bergeron equations. Faults are located by posing a novel one-variable optimization problem, whereas voltage and current waveforms at the fault location are estimated by unveiling rigorous relationships. The proposed elements are secure against external faults, measurement errors, and variation of line parameters and sampling time. Furthermore, these advances are tested via electromagnetic transient simulations and are significant to satisfy IEEE and North American Electric Reliability Corporation requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Topological Analysis of Temporal Hypergraphs

In this work we study the topological properties of temporal hypergraphs. Hypergraphs provide a higher dimensional generalization of a graph that is capable of capturing multi-way connections. As such, they have become an integral part of network science. A common use of hypergraphs is to model events as hyperedges in which the event can involve many elements as nodes. This provides a more complete picture of the event in comparison to the standard dyadic connection limitation of a graph. However, a common attribution to events is temporal information as an interval for when the event occurred. Consequently, a temporal hypergraph is born which accurately captures both the temporal information of events as well as their multi-way connections. Common tools for studying these temporal hypergraphs typically use summary statistics of snapshots from a sliding window procedure to capture changes in the underlying dynamics. However, these do not provide insight into how the changing structure of the hypergraph evolves and which components of the temporal hypergraph persist and are influential to the underlying system. To alleviate this need we leverage zigzag persistence from the field of Topological Data Analysis (TDA) to study the change in topological structure of time-evolving hypergraphs. We apply our pipeline to both a cyber security and social network dataset and show how the topological structure of their temporal hypergraphs change and can be used to understand the underlying dynamics.

hypergraphs, topological data analysis, zigzag per↗

Impact of light output on the timing resolution of organic glass scintillator bars in a dual-ended readout configuration

The effectiveness of detector system modeling and validation depends on the quality of characterization performed on the system. For nuclear nonproliferation applications, which require detectors to address complex and variable field conditions, access to accurate system models is essential. This study presents the timing characterization of organic glass scintillator bars used in an imaging system developed at the University of Michigan. 137 Cs and 60 Co gamma-ray sources were used to determine the coincidence time resolution as a function of measured light output for two Compton scatter events between two organic glass scintillator bars. Timing resolution for two events, each with light output ranging from 100 to 1100 keVee were characterized. The resulting data were fit to a parametric function that was validated to agree with experimental results within ±25 ps. Simulations were performed to establish appropriate calibration points for each organic scintillator, thereby ensuring accurate calibration of light output values during analysis. This work successfully characterized the light output dependence of the coincidence timing resolution of a pair of organic glass detectors for use in an imaging system. Depending on the amount of scintillation light output from the events, the full width at half maximum of the measured coincidence time resolution ranged from 653.2 ± 16.1 ps for low light yields, 100 keVee, to 121.0 ± 8.4 ps for higher yields at 1100 keVee. The insights obtained from the timing resolution behavior will allow for accurate simulation capabilities in future security and verification efforts using scatter-based imaging systems.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Cyber threat assessment of machine learning driven autonomous control systems of nuclear power plants

We report advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)-based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber–physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems.

99 GENERAL AND MISCELLANEOUS↗

A Secure Learning Control Strategy via Dynamic Camouflaging for Unknown Dynamical Systems under Attacks

This paper presents a secure reinforcement learning (RL) based control method for unknown linear time-invariant cyber-physical systems (CPSs) that are subjected to compositional attacks such as eavesdropping and covert attack. We consider the attack scenario where the attacker learns about the dynamic model during the exploration phase of the learning conducted by the designer to learn a linear quadratic regulator (LQR), and thereafter, use such information to conduct a covert attack on the dynamic system, which we refer to as doubly learning-based control and attack (DLCA) framework. We propose a dynamic camouflaging based attack-resilient reinforcement learning (ARRL) algorithm which can learn the desired optimal controller for the dynamic system, and at the same time, can inject sufficient misinformation in the estimation of system dynamics by the attacker. The algorithm is accompanied by theoretical guarantees and extensive numerical experiments on a consensus multi-agent system and on a benchmark power grid model.

Mukherjee, Sayak↗

Dragonstone Strategy – State of Cybersecurity in the Oil & Natural Gas Sector

The oil & natural gas (ONG) system touches every corner of the nation and increased communications & control capabilities have not only allowed for greater efficiency of system operation, but have also created a massive target for adversaries to launch cyber-attacks. Like any other heavy industrial process, the ONG system relies on a complex system of information technology (IT) and operational technology (OT) devices. The current state of cyber-preparedness across the ONG industry varies from organization to organization. Among the most common challenges that ONG companies face are remote locations, longlived field assets, and lacking capabilities to find and track malware on their systems. ONG companies tend to be concerned with lack of cyber-awareness from employees, risk stemming from remote access for operations & maintenance, and software vulnerabilities within third-party equipment. Various industry and government organizations are performing research and development activities to address some of these challenges, but in many cases industry stakeholders are not aware of solutions that already exist. It is clear that a need exists for a coherent, comprehensive, multi-layered strategy for assuring the security and resilience of the nation's pipeline infrastructure against cyber threats. For a variety of reasons, the general consensus from stakeholders interviewed by LLNL is that the state of cyber-security within the electric grid is currently outpacing its ONG cousin. Existing strategies for the resilience and cyber-security of the electric grid can and should be leveraged to provide immediate benefits to the ONG system. In LLNL’s view, there are two key factors currently limiting the development of necessary cyber-practices within the ONG industry: The sheer number of differing regulatory bodies and trade groups offering both standards and best-practice recommendations for ONG cyber-security makes it difficult to create a comprehensive, directed, and coherent strategy that is applicable to all players within the ONG industry. The ONG industry is unaware of potentially useful technologies that have been developed for ensuring cyber-security of other infrastructure systems, such as the electric grid. Leveraging these technologies—and the science and engineering behind them—can provide some low-hanging fruit that can greatly improve cyber-security in the ONG industry without significant investments in terms of time and money. In the months following this report, LLNL will continue to perform outreach to key oil & gas industry stakeholders in a continual effort to identify the most pressing cyber-resilience issues in the industry. This outreach will be supplemented with LLNL’s threat intelligence capabilities to begin painting a clearer picture of the overall threat landscape faced by this sector. This assessment will be threat-informed and while the strategy itself will not be classified we will leverage intelligence analysis and adversary capabilities to identify gaps in current cybersecurity practices for oil & gas pipeline systems. Recommended efforts will be compiled into a cyber-resilience roadmap for the oil & gas pipeline sector, in which LLNL will highlight priority activities to immediately improve the state of cyber-resilience in the industry.

02 PETROLEUM↗

Hydrothermal Liquid Recovery of Rare Earth Elements and Critical Materials

This project demonstrated the technical viability of using tunable hydrothermal liquid (HTL) solutions to recover valuable minerals from a range of source materials. The effort focused upon rare earth elements (REE) and other minerals critical to the industrial security of the United States. This effort demonstrated, for the first time, that s, supercritical water (SCW) in particular, can: Extract critical and valuable minerals from a range of matrices ranging from rock ore to biomass; The process can be used to recover a wide range of minerals; This novel extraction chemistry can be cheap, simple, and nontoxic/”green”: The chemical extraction uses water, the cheapest industrial acid (sulfuric), and simple salts (i.e. sodium sulfate). However, other acids, salts, and additives could be used as appropriate. This Laboratory Directed Research and Development (LDRD) project identified that the process is complex with many interacting factors, but the benefits are significant if the complexities can be resolved. Challenges remain in the development of this technology and are described in this report. However, the results are positive, and commercial partners have already expressed interest. In summary, a novel, green, inexpensive mineral extraction process has been developed and demonstrated in a small batch reactor system. The effort provided information for an invention disclosure, proposal to DOE, and will support future business development efforts.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

High-Resolution Modeling of the Gulf of Mexico using E3SM

Coastal ocean modeling is a high priority in the DOE‘s Energy Exascale Earth System Model (E3SM). The goal is to accurately predict the risk of damage to coastal resources and infrastructure due to a changing climate in the coming decades. North American coastal communities are areas of particular interest, as this fits under the topic of US national security and planning assessments in a changing climate. LANL Institutional Computing time for the Tier 1 allocation ”Coastal Ocean and Sea Ice Modeling” have been used for development and testing of numerical methods needed for E3SM coastal applications.

54 ENVIRONMENTAL SCIENCES↗

Identifying neutron sources using recoil and time-of-flight spectroscopy

Identification of neutron sources is central to nuclear physics and its applications, from planetary science to nuclear security, yet direct source discrimination from measured neutron spectra remains fundamentally elusive. Here, we introduce a Bayesian protocol that directly infers source ensembles from measured neutron spectra by combining full-spectrum template matching with probabilistic evidence evaluation. Applying this protocol to recoil and time-of-flight spectroscopy, we recover single- and two-source configurations with strong statistical significance (beyond 4⁢𝜎) at event counts as low as ∼10 3 . These results demonstrate that neutron spectral signatures can be leveraged for robust source identification, opening a new observational window for both fundamental research and operationally driven applications.

neutron physics↗

Real-time Event Detection Using Rank Signatures of Real-world PMU Data

Timely detection of power system events is a crucial task, which can facilitate the implementation of remedial actions to improve reliability, resiliency, and security of the system. Meanwhile, the widespread deployment of phasor measurement units (PMUs) makes it possible to develop data-driven event detection techniques. However, relying purely on data without incorporating domain knowledge for the event detection task in power systems poses substantial security and stability risks due to issues associated with data misinterpretation and model accuracy. In this regard, we propose a real-time event detection method using real-world PMU data by incorporating domain knowledge to adequately capture the event signatures. Specifically, we track the change in rank signatures of PMU data to accurately localize the events. To optimize the detection process, we incorporate an offline Bayesian optimization algorithm to tune the parameters by efficiently searching for the best values. The experiments using the real-world PMU dataset from a U.S. interconnection show that the proposed event detection approach can efficiently detect the events from PMU data streams with high accuracy.

Ghasemkhani, Amir↗

Digital data provenance for the power grid based on a Keyless Infrastructure Security Solution

In this work a data provenance system for grid-oriented applications is presented. The proposed Keyless Infrastructure Security Solution (KISS) provides mechanisms to store and maintain digital data fingerprints that can later be used to validate and assert data provenance using a time-based, hash tree mechanism. The developed solution has been designed to satisfy the stringent requirements of the modern power grid including execution time and storage necessities. Its applicability has been tested using a lab-scale, proof-of-concept deployment that secures an energy management system against the attack sequence observed on the 2016 Ukrainian power grid cyberattack. The results demonstrate a strong potential for enabling data provenance in a wide array of applications, including speed-sensitive applications such as those found in control room environments.

Sebastian Cardenas, David J.↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

Using Splunk® Enterprise Search Commands for Advanced Analysis of Ivanti Connect Secure© Logs

Analyzing the logs of even the smallest Information Technology (IT) system can be a challenge considering they can generate millions of lines of log data in a very short time. Splunk® Enterprise is an industry leading tool that allows analysis of log data, which can enhance troubleshooting capabilities, improve system performance, and improve the security posture of an IT system. Ivanti Connect Secure© (ICS) is a market-leading platform powered by the Ivanti Secure Socket Layer Virtual Private Network (SSL VPN) appliance, providing an architecture for secure access to and protection of network resources. This paper describes an approach for using Splunk Enterprise search capabilities to perform advanced data analysis of ICS logs.

97 MATHEMATICS AND COMPUTING↗

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS↗

Artificial Intelligence for Digital Security and Protections

Proper functioning of nuclear power plants relies on a mix of well-regulated human and machine-driven workflows. This regulation supports nuclear safety through a series of processes and many of the tasks that support these processes have a repetitive nature that make artificial intelligence (AI) informed by machine learning (ML) a potential aid in a variety of tasks. AI is being evaluated for activities that include inspections, fuel processing, monitoring, and other activities. The introduction of any new technology presents a potential new attack vector. In the case of AI/ML, there are many attacks that have already been discovered and over time the attacks can be expected to follow the growth pattern observed in cyber security. While future planning is necessary, current efforts need to be established now to predict the threat emergence over the next year 10 years and mitigate potential threats. Based on these observations, AI/ML will need to become trustworthy, which corresponds to techniques and procedures that emphasize AI explainability along with resilience techniques to data, algorithms, models, and systems. This kind of system robustness is the foundation for defenses against AI/ML-specific attacks. Attempting to look forward and take a broad view of capabilities provides input to research roadmaps and the ability to distill vulnerabilities into specific use cases may provide greater assistance in understanding the technology benefits while introducing new risks. The impact of current and future AI in three areas—capabilities, challenges, and recovery strategies—represents an initial attempt at balancing both.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

AI-ENABLED MONITORING OPTIONS TOWARDS SECURE MICROREACTOR DEPLOYMENT AND OPERATIONS

Global nuclear energy deployment scenarios suggest favorable economics for smaller, more versatile, and self-contained reactor technologies. Recognizing their key features as integrated, autonomous and either semi-remotely operated or fully remotely operated systems, microreactors are expected to be deployed in large numbers servicing off/micro-grids, many in geographically remote locations. Integrated nature of these systems as well as ease of their transportation as complete units, simplified installation and relocation/decommissioning challenge traditional continuity-of-knowledge practices used for conventional light water reactors where refueling is done onsite at designated times only replacing portions of their cores and only after their full commissioning for operations including completion of their containment building with security and safeguards measures in place. This effort is exploring AI (artificial intelligence)-enabled monitoring options that would be design agnostic and would assure secure unit deployment and operations. The principle is to maintain situational awareness via real-time evaluations of simultaneous and remotely transmitted monitoring data capturing key safeguards attributes including such characteristics as temperature, radiation, vibrational signals (inter alia), and others. The key principle is to provide reliable and resilient security options while maintaining simplified and economical deployment. The paper will review feasible options for AI-enabled solutions for such evaluations.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗