Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Zero Trust and Identity Access Management in Support of Service-Based Urban Air Mobility Applications

Urban Air Mobility environments will contain of a collection of service-based services, which will be typically hosted within cloud infrastructures. The underlying data for these UAM services will need to be secured. One approach to securing these UAM services would be to leverage the Zero Trust framework, that focuses on securing services and associated data, instead of securing the network. An early step in moving towards a Zero Trust framework is to standardize identity access manage support for an ever-widening set of services, where users must explicitly be granted access to each service.

UAM↗

TriC: Distributed-memory Triangle Counting by Exploiting the Graph Structure

Graph analytics has emerged as an important tool in the analysis of large scale data from diverse application domains such as social networks, cyber security and bioinformatics. Counting the number of triangles in a graph is a fundamental kernel with several applications such as detecting the community structure of a graph or in identifying important vertices in a graph. The ubiquity of massive datasets is driving the need to scale graph analytics on parallel systems. However, numerous challenges exist in efficiently parallelizing graph algorithms, especially on distributed-memory systems. Irregular memory accesses and communication patterns, low computation to communication ratios, and the need for frequent synchronization are some of the leading challenges. In this paper, we present TriC, our distributed-memory implementation of triangle counting in graphs using the Message Passing Interface (MPI), as a submission to the 2020 GraphChallenge competition. Using a set of synthetic and real-world inputs from the challenge, we demonstrate a speedup of up to 90x relative to previous work on 32 processor-cores of a NERSC Cori node. We also provide details from distributed runs with up to8192 processes along with strong scaling results. The observations presented in this work provide an understanding of the system-level bottlenecks at scale that specifically impact sparse-irregular workloads and will therefore benefit other efforts to parallelize graph algorithms.

Halappanavar, Mahantesh↗

Communication system and method for applying security for a time sensitive network

A method includes identifying power connections between plural components of a time sensitive network (TSN) that are interconnected via a predetermined connection plan. The method also includes determining a topology of the components of the TSN based on the power connections. Also, the method includes scheduling flows for the TSN based on the topology determined based on the power connections.

Bush, Stephen Francis↗

Methods and systems for detection of man-in-the-middle attacks for SCADA communication networks and applications of same

A system for detecting MITM for SCADA communication networks includes secure substation-substation communication links for providing secure and reliable paths to exchange OT data between substations for OT data consistency check; a SIB in each substation for sampling CT and PT measurements to calculate voltage magnitude and phase angle thereof; a S&C server in each substation coupled to the SIB for receiving the voltage magnitude and phase angle from the SIB and obtaining a packet carrying active power flow in transmission lines between two substations and a time stamp; an IDS server placed in a SCADA center for collecting the packet of each substation sent by the S&C server; analyzing the received packet from every adjacent substation; inspecting the payload of the received packet; and triggering an intrusion alarm to a SCADA operator when the power flow is not the same as the payload of the packets.

McCann, Roy A.↗

Secure authentication using recurrent neural networks

A computer-implemented method of user authentication is provided. The method comprises combining, by a computer system, a user recurrent neural network with a system recurrent neural network to form a unique combined recurrent neural network. The user recurrent neural network is configured to generate a unique user key, and the system recurrent neural network is configured to generate a system key. The computer system inputs a predetermined input into the combined recurrent neural network, and the combined recurrent neural network generates a unique combined key from the input, wherein the combined key differs from both the user key and system key. The computer system then associates the combined key with a unique access authorization to authenticate a user.

Aimone, James Bradley↗

Peer-to-Peer Energy Trading under Network Constraints Based on Generalized Fast Dual Ascent

We report the wide deployment of renewable energy resources, combined with a more proactive demand-side management, is inducing a new paradigm in both power system operation and electricity market trading, which especially boosts the emergence of the peer-to-peer (P2P) market. A more flexible local market mechanism is highly desirable in response to fast changes in renewable power generation at the distribution network level. Moreover, large-scale implementation of P2P energy trading inevitably affects the secure and economic operation of the distribution network. This paper presents a new P2P electricity trading framework with distribution network security constraints considered using the generalized fast dual ascent method. First, an event-driven local P2P market framework is presented to facilitate short-term or immediate local energy transactions. Then, the sensitivity analysis of nodal voltage and network loss with respect to nodal power injections is used to evaluate the impacts of P2P transactions on the distribution network, which ensures the secure operation of the distribution system. Thereby, the external operational constraints are internalized, and the cost of P2P energy trading can be appropriately allocated in an endogenous way. Moreover, a generalized fast dual ascent method is employed to implement distributed market-clearing efficiently. Finally, numerical results indicate that the proposed model could guarantee secure operation of the distribution system with P2P energy trading, and the solution method enjoys good convergence performance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

NASA's Secured Advanced Federated Environment

In 1999, a NASA-wide team initially set out to create a collaborative environment to enable NASA's scientists and engineers to share information and tools across NASA locations and with world-wide partners. This paper describes the team's development process and solutions in resolving conflicting security issues of building a complex intra/inter-enterprise collaborative system. Based on the federated, hierarchical, compartmentalized principles, the Secured Advanced Federated Environment (SAFE) developed by the team is becoming a foundational element for building a collaborative infrastructure for NASA. This paper also introduces the concept of a Micro Security Domain which can achieve the balance between the need to collaborate and the need to enforce enterprise and local security rules. SAFE'S federated security concepts enables networks to be formed around the functional/security requirements. With the SAFE technologies and approaches, security will not be an afterthought of the enterprise network design.

network designs↗

Evaluating software defined networking solutions to reduce the digital attack surface of nuclear security systems

Most nuclear security systems used today were not designed for today’s threat environment. Systems that were intended to be stand alone are now interconnected. Devices that have a single purpose are built on multi-purpose platforms and communication protocols that, while effective, have no ability to authenticate authorized versus unauthorized commands. These attributes provide an attacker significant ability to affect the system, pivot throughout the interconnected networks, and remain undetected if he/she is able to compromise a single node. Software defined networking (SDN) has been used for years by information technology (IT) cloud service providers to quickly provision or remove servers or other systems to meet changing demand. The same concept has recently been applied to operational technology (OT) systems to enable very fast failover on critical systems that have stringent and deterministic (<5ms) transmit/receive times. By carefully engineering the communication flows through a network using preplanned routes and specific pathways it is possible to achieve deterministic and extremely reliable message delivery even when components fail. This engineering approach to network design has added security benefits including securing the networking control plane, eliminating network scanning and mapping, inhibiting ARP spoofing and host masquerading, eliminating unauthorized network pivoting and enabling greater situational awareness on the network. SDN in OT environments is new but early testing in electrical power and other critical infrastructure has shown it to be a very powerful tool for building reliable networks and reducing the digital attack surface of the network. The authors tested a software defined network switch on a simple physical protection system with components commonly found in nuclear security systems and found improved mitigations to denial of service attacks, lateral movement and network reconnaissance. The paper details the tests and their results.

Cyber security, Nuclear security, software defined↗

Towards Fully Secure 5G Ultra-Low Latency Communications: A Cost-Security Functions Analysis

Future components to enhance the basic, native security of 5G networks are either complex mechanisms whose impact in the requiring 5G communications are not considered, or lightweight solutions adapted to ultra-reliable low-latency communications (URLLC) but whose security properties remain under discussion. Although different 5G network slices may have different requirements, in general, both visions seem to fall short at provisioning secure URLLC in the future. In this work we address this challenge, by introducing cost-security functions as a method to evaluate the performance and adequacy of most developed and employed non-native enhanced security mechanisms in 5G networks. We categorize those new security components into different groups according to their purpose and deployment scope. We propose to analyze them in the context of existing 5G architectures using two different approaches. First, using model checking techniques, we will evaluate the probability of an attacker to be successful against each security solution. Second, using analytical models, we will analyze the impact of these security mechanisms in terms of delay, throughput consumption, and reliability. Finally, we will combine both approaches using stochastic cost-security functions and the PRISM model checker to create a global picture. Our results are first evidence of how a 5G network that covers and strengthened all security areas through enhanced, dedicated non-native mechanisms could only guarantee secure URLLC with a probability of ~55%.

5G networks↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Casing Annulus Monitoring of CO 2 Injection Using Wireless Autonomous Distributed Sensor Networks

Effective and secure carbon subsurface storage, involving the deep underground injection of CO 2 into geological formations where it is permanently trapped, is paramount to mitigating CO 2 emissions (Figure I). Ensuring the integrity of these storage sites and detecting potential leakage through the casing annulus necessitates robust monitoring. This work provides the first integrated demonstration of a wireless casing-annulus monitoring architecture that can operate in highly attenuating cement-brine environments relevant to CO 2 storage. This project focused on developing and validating a novel sensor system for integration with autonomous monitoring near the cement reservoir interface. The goal was a fully integrated Technology Readiness Level (TRL) 4/5 field validation of a distributed wireless intelligent sensor system providing real-time, direct subsurface formation measurements to enhance fluid movement monitoring in the cemented casing annulus. Achieving this objective required the development and integration of 1) wireless autonomous microsensor technology by California Institute of Technology (Caltech); 2) sensor packaging and emplacement technology by Research Triangle Institute (RTI); and 3) smart well completions using wireless active casing collars and NOV pipe by the Sandia National Lab (SNL). The collaboration with the Caltech team in this project aimed to develop millimeter-scale radio frequency identification (RFID) sensors capable of detecting CO 2 , pH, and/or methane levels. These sensors are engineered to be impervious to fluids, allowing them to be mixed with cement and installed within the casing annulus. They operate using RFID protocols at frequencies of 902–928 MHz for both power and communication. A Sandia National Laboratories’ team engaged their expertise in the development of a Smart Collar system designed for the wireless data collection from these RFID sensors embedded in the cement annulus and transmission of this information to the ground surface via IntelliPipe/IntelliServ NOV drill pipe. This is accomplished through inductive coupling at the collar, which facilitates data transfer through each segment of the pipe. Because the system cannot transmit a direct current signal to power the Smart Collar, both power and communication were implemented using alternating current and electromagnetic signals at varying frequencies. Furthermore, the developed microsensor technology had to be demonstrated and validated in comparison with reference transducer measurements in a field test site at The University of Texas at Austin (UT-Austin). Although the full sensor suite did not reach field-deployment readiness, the system-level integration achieved in this project establishes a validated pathway for future incorporation of advanced microsensors.

47 OTHER INSTRUMENTATION↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Addressing Software Security

Historically security within organizations was thought of as an IT function (web sites/servers, email, workstation patching, etc.) Threat landscape has evolved (Script Kiddies, Hackers, Advanced Persistent Threat (APT), Nation States, etc.) Attack surface has expanded -Networks interconnected!! Some security posture factors Network Layer (Routers, Firewalls, etc.) Computer Network Defense (IPS/IDS, Sensors, Continuous Monitoring, etc.) Industrial Control Systems (ICS) Software Security (COTS, FOSS, Custom, etc.)

software↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

Foundations of Rigorous Cyber Experimentation

This report presents the results of the “Foundations of Rigorous Cyber Experimentation” (FORCE) Laboratory Directed Research and Development (LDRD) project. This project is a companion project to the “Science and Engineering of Cyber security through Uncertainty quantification and Rigorous Experimentation” (SECURE) Grand Challenge LDRD project. This project leverages the offline, controlled nature of cyber experimentation technologies in general, and emulation testbeds in particular, to assess how uncertainties in network conditions affect uncertainties in key metrics. We conduct extensive experimentation using a Firewheel emulation-based cyber testbed model of Invisible Internet Project (I2P) networks to understand a de-anonymization attack formerly presented in the literature. Our goals in this analysis are to see if we can leverage emulation testbeds to produce reliably repeatable experimental networks at scale, identify significant parameters influencing experimental results, replicate the previous results, quantify uncertainty associated with the predictions, and apply multi-fidelity techniques to forecast results to real-world network scales. The I2P networks we study are up to three orders of magnitude larger than the networks studied in SECURE and presented additional challenges to identify significant parameters. The key contributions of this project are the application of SECURE techniques such as UQ to a scenario of interest and scaling the SECURE techniques to larger network sizes. This report describes the experimental methods and results of these studies in more detail. In addition, the process of constructing these large-scale experiments tested the limits of the Firewheel emulation-based technologies. Therefore, another contribution of this work is that it informed the Firewheel developers of scaling limitations, which were subsequently corrected.

97 MATHEMATICS AND COMPUTING↗