Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrating Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Cyber-Informed Engineering Implementation Guide: Version 1.0 [Slides]

This Implementation Guide describes the principles of Cyber-Informed Engineering (CIE) and outlines questions that engineering teams should consider during each phase of a system's lifecycle to effectively employ these principles. It describes what it means to engineer systems in a cyber-informed way, rather than offering a comprehensive, step-by-step process or procedure for CIE implementation. This guide complements - but does not replace - the application of cybersecurity standards or practices currently in place within an organization. Engineers and technicians that design critical energy infrastructure installations can use this Implementation Guide to integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. The guide is aimed at system or design engineers, rather than software engineers or operational cybersecurity practitioners. The engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system's engineering design to diminish the severity of cyber attacks or digital technology failures. CIE expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Automatic Generation of Event Trees and Fault Trees: A Model-Based Approach

In the past few decades, the increasing complexity of modern engineering systems has been driven by the integration of a large number of components whose operations may involve many disciplines (e.g., thermal hydraulics, plant operations, cybersecurity). Most computational tools used by industry and regulators for system safety and reliability assessments are still based on the traditional fault tree (FT) and event tree (ET) approach, which may not be able to capture complex interactions among system constituents. The use of simulation tools has widely increased in the past few decades to improve the fidelity of the reliability and safety analyses. However, the direct use of simulation tools as part of dynamic probabilistic risk assessment (DPRA) methods is not getting traction since (1) modeling the whole system under consideration with DPRA methods may be computationally expensive and unnecessary, and (2) the manual integration of DPRA models into existing state-of-practice probabilistic risk assessment models (i.e., based on FTs and ETs) can be time consuming and prone to errors. Here, in this paper we propose a procedure to overcome this limitation by presenting several algorithms designed to automatically construct subsystem ETs and FTs from DPRA methods for integration into an existing ET/FT system model.

97 MATHEMATICS AND COMPUTING↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Poster: Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The rapid integration of artificial intelligence (AI) in the utility transmission and distribution (T&D) sector is revolutionizing traditional grid management practices. As utilities encounter complexities from evolving consumer behaviors and energy integration, AI becomes a critical solution for enhancing grid monitoring, fault detection, and operational optimization. However, increased reliance on interconnected technologies introduces significant cybersecurity risks, regulatory compliance challenges, and human factors concerns. This study proposes a strategic, responsible and consequence-driven approach to AI implementation, examining the dual nature of AI adoption by highlighting its transformative benefits for utilities and associated risks. It provides utilities with a framework for evaluating AI integration, enabling them to navigate challenges and capitalize on opportunities to achieve greater reliability, efficiency, and resilience in an increasingly complex energy landscape.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗

Demonstrating the Transient System Impact of Cyber-Physical Events Through Scalable Transmission and Distribution (T&D) Co-Simulation

Modern power systems become more vulnerable to cyber threats due to their growing interconnectivity, interdependence, and complexity. Widespread deployment of distributed energy resources (DERs) further expands the threat landscape to the grid edge, where fewer cybersecurity protections exist. In this article, a systematic cyber-physical events demonstration, enabled by an integrated transmission, distribution, and communication co-simulation framework, is performed. It analyzes cyber risks to power grid under DER-enabled automatic generation control from different angles. Unlike existing works, the simulation captures millisecond-to-minutes frequency and voltage transient dynamics at a cross-region system scale.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Supporting U.S. National Security Through Cybersecurity Partnerships

At NLR, we're studying energy evolutions and threats to understand the challenges they pose and uncover ways to leverage grid advancements to achieve more secure, defensible, and reliable systems. Our integrated research approach bridges the gap between cyber threats and real-world consequences to deliver actionable solutions that reduce vulnerabilities and help strengthen U.S. national security.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

GLIMPSE of Future Power Grid Models

Power grid is one of the critical national infrastructures with social, economics, and national security impacts. Particularly, power distribution systems represent part of the infrastructure between power distribution substations and customers such as residential, commercial, and industrial. To address various grid modernization challenges, state-of-the-art algorithms and methodologies have been developed to deploy, operate, and expand a secure and resilient power grid. At the same time, there is a need to develop capabilities to assist power grid stakeholders to quickly get insight into the design and structure of the grid. Data visualization is a key approach to comprehend and understand complex systems such as the power grid. We present GLIMPSE Grid Layout Interface for Model Preview and System Exploration), a graph-based semantic-aware application to visualize and update distribution power grid models. The GLIMPSE can be used with standard IEEE models to search and highlight power grid objects such as generators, loads, overhead lines, etc. Additionally, it supports updating attributes and model export to integrate with GridLAB-D simulations.

Cybersecurity, power grid, visualization↗

Edge ML for CAN bus intrusion detection in AVs

Autonomous Vehicles (AVs) are revolutionizing transportation, but their reliance on interconnected cyber-physical systems exposes them to unprecedented cybersecurity risks. This study addresses the critical challenge of detecting real-time cyber intrusions in self-driving vehicles by leveraging a dataset from the Udacity self-driving car project. We simulate four high-impact attack vectors, Denial of Service (DoS), spoofing, replay, and fuzzy attacks, by injecting noise into spatial features (e.g., bounding box coordinates) to replicate adversarial scenarios. We develop and evaluate two lightweight neural network architectures (NN-1 and NN-2) alongside a logistic regression baseline (LG-1) for intrusion detection. The models achieve exceptional performance, with NN-2 attaining an AUC score of 93.15% and 93.15% accuracy, demonstrating their suitability for edge deployment in AV environments. Through explainable AI techniques, we uncover unique forensic fingerprints of each attack type, such as spatial corruption in fuzzy attacks and temporal anomalies in replay attacks, offering actionable insights for feature engineering and proactive defense. Visual analytics, including confusion matrices, ROC curves, and feature importance plots, validate the models' robustness and interpretability. This research sets a new benchmark for AV cybersecurity, delivering a scalable, field-ready toolkit for Original Equipment Manufacturers (OEMs) and policymakers. By aligning intrusion fingerprints with SAE J3061 automotive security standards, we provide a pathway for integrating machine learning into safety-critical AV systems. Our findings underscore the urgent need for security-by-design AI, ensuring that AVs not only drive autonomously but also defend autonomously. This work bridges the gap between theoretical cybersecurity and life-preserving engineering, offering a leap toward safer, more secure autonomous transportation.

97 MATHEMATICS AND COMPUTING↗

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber↗

SDN-Based Dynamic Cybersecurity Framework of IEC-61850 Communications in Smart Grid

In recent years, critical infrastructure and power grids have experienced a series of cyber-attacks, leading to temporary, widespread blackouts of considerable magnitude. Since most substations are unmanned and have limited physical security protection, cyber breaches into power grid substations present a risk. Nowadays, the susceptibility of SDN architecture to cyber-attacks has exhibited a notable increase in recent years, as indicated by research findings. This suggests a growing concern regarding the potential for cybersecurity breaches within the SDN framework. In this paper, we propose a hybrid intrusion detection system (IDS)-integrated SDN architecture for detecting and preventing the injection of malicious IEC 61850-based generic object-oriented system event (GOOSE) messages in a digital substation. Additionally, this program locates the fault’s location and, as a form of mitigation, disables a certain port. Furthermore, implementation examples are demonstrated and verified using a hardware-in-the-loop (HIL) testbed that mimics the functioning of a digital substation.

Liu, Chen-Ching [Virginia Tech] (ORCID:00000002894↗

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Data Center Cybersecurity, Supply Chain Risk Management, and Emerging Regulation Cohort Summary: Takeaways and Action Plans

This report summarizes the outcomes of the Data Center Cohort under the Department of Energy’s Technical Assistance for Digital Assurance (TADA) initiative, aimed at enhancing grid resilience through cybersecurity, supply chain risk management (SCRM), and Cyber-Informed Engineering (CIE). The cohort engaged 17 organizations across utilities, data center operators, vendors, and technology providers in three sessions combining presentations, discussions, and exercises. Key topics included AI-driven load behavior, cybersecurity vulnerabilities in UPS/BESS and cooling systems, governance gaps at utility–data center boundaries, and supply chain integrity. Five cross-cutting themes emerged: interconnection architecture vulnerabilities, fragmented governance, AI-driven stability risks, lack of regulatory frameworks, and long-term supply chain concerns. Actionable recommendations were developed, including implementing DMZ segmentation, formalizing vendor access agreements, designing AI workload limits, and advancing standards through NERC and state-level programs. These strategies aim to strengthen resilience, clarify responsibilities, and ensure secure integration of data centers into the grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Assessment and Coordination of DER Cybersecurity Standards

Distributed energy resources (DERs) are becoming increasingly important to the electric grid, including solar energy systems. However, DERs also introduce new cybersecurity risks, including those posed by cloud computing. Standards harmonization is essential for ensuring that DERs are secure and can be safely integrated into the grid. This panel will discuss cyber standards harmonization for solar security. The panel will feature experts from the S2G Program, National Labs and Industry.

14 SOLAR ENERGY↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

CyberMESA: Evaluation Procedures and Metrics for Charging Infrastructure Cybersecurity

A report detailing the cybersecurity evaluation and assessment procedures for EV charging infrastructure. This report is authored by three national lab contributors. INL, PNNL, NRL. The grid integration of Electric Vehicle Charging Infrastructure (EVCI) is a large and complex system of systems (SoS) made up of components from many manufacturers and integrated by various companies responsible for their operation and maintenance. This complexity makes it challenging to implement security standards like IEC 62443 across the entire infrastructure. This document aims to aid in the vulnerability assessments of individual devices, such as Electric Vehicle Supply Equipment (EVSE), to support vendors in adopting and implementing security standards such as UL 2900, NIST SP 800-53 and Common Criteria (CC) (ISO/IEC 15408). This document serves as a guide to help evaluate the cybersecurity posture of EVCI assets. It aims to provide a consistent method for evaluating EVCI, enabling cybersecurity research teams to systematically test a wide range of electric vehicle (EV) assets. The target audiences include cybersecurity research teams, vendor development teams, automotive OEMs, and third-party evaluators.

24 POWER TRANSMISSION AND DISTRIBUTION↗