Assessment and Experience Using Open-Source NPP Environments for Cyber-Security Training
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Issues associated with establishing a SNF Transportation System in the U.S. are complex. In part, this is because in the US when discussing SNF, there are two distinct categories. The two categories represent significant differences in ownership, transportation-regulator, and even the physical characteristics of the SNF. Specifically, the physical differences in the SNF include size of the rods, associated quantities to be shipped, cladding material, and radionuclide content/enrichment. The first is commercial SNF (i.e., that associated with nuclear power plants), owned by utilities, until a permanent repository is built with DOE obligated by law to then assume the responsibility for shipping and ownership of the SNF. Since no-permanent repository currently exists, most commercial SNF is stored near the reactor in which it was installed, hence requiring no shipments. Although current shipments of commercial SNF are very limited, the few that do occur are generally performed to support a utilities SNF consolidation effort utility and for post irradiation examination/testing. However, with approximately 83,000 metric tons currently being stored at more than 70 sites around the U.S., when a permanent repository becomes available, the required number of shipments will be extensive. The second category is DOE and research reactor fuel. These fuel rods are generally much smaller in length than commercial fuel rods, with the quantity of rods transported in a shipment significantly less than the number of rods in a typical commercial fuel assembly. Currently, most of the SNF shipments within the U.S come from this category. DOE is currently managing about 2500 metric tons of heavy metal of SNF. This panel focused on updates and status of transportation of SNF/UNF. Panelists provided updates and information on continuing impacts, risk assessment, equipment (rail cars, handling, securement), possible rail routing, and proposed inspection equipment/routing prior to shipments. Panelists with presentations: Preparing for Nuclear Waste Transportation (Daniel Ogg); Challenges and Opportunities in Establishing a System for Transportation of SNF/UNF (Kathy Langan); UNF Transportation: Challenges and Opportunities (Michael Valenzano)
Securing the energy delivery system (EDS) from complex, nonlinear, and evolving cyber threats requires a complex set of changing and interwoven classes of technologies, policies, relationships, and personnel. One key area in this technological milieu is assessment methodologies to compare information, gathered by a variety of means, about networked devices with publicly known possible threat information about said devices. This information is used to generate risk-based characterizations that allow for the adjudication and proper corresponding management action chains to be assigned.
Relational Database Management Systems are the backbone of modern enterprises and public-sector services, and are thus frequent targets of security incidents, insider threats, and thorough regulatory audits. Consequently, databases have become key sources of digital evidence, requiring investigators to reconstruct past activity from audit logs, transaction logs, and backups. Although benchmarking frameworks such as those developed by the Transaction Processing Performance Council (TPC) are widely used to evaluate database performance, they do not capture forensic requirements such as evidentiary completeness, tamper-evidence, chain of custody, or regulatory compliance under GDPR and CCPA. This survey examines the emerging domain of forensic database benchmarking. We gathered prior research on database forensics, secure logging, and tamper-evident data structures; we analyze modern forensic-ready features in commercial and open-source systems (SQL Server Ledger, Oracle Blockchain Tables, PostgreSQL pgAudit, Db2 Audit, Aurora Database Activity Streams, Oracle Real Application Security and IBM Guardium) and assess why existing benchmarks are insufficient. We propose forensic workloads, metrics, and methodologies that incorporate adversarial stressors, deleted-record recovery, and backup analysis. We also identify open research problems and call for a community-driven forensic benchmark suite. The result is an idea for evaluating not only database performance but also forensic soundness, bridging the gap between system engineering, compliance, and digital investigations.
Power engineers rely on computer-based simulation tools to assess grid performance and ensure security. At the core of these tools are solvers for sparse linear equations. When transformed into a bordered block-diagonal (BBD) structure, part of the sparse linear equation solving can be parallelized. This work focuses on using the Schur-complement-based method for LU factorization on BBD matrices, specifically, Jacobian matrices from large-scale systems. Our findings show that the natural ordering method outperforms the default ordering method in computational performance for each block of the BBD matrix. This observation is validated using synthetic 25k-bus and 70k-bus cases, showing a speedup of up to 38% when using natural ordering without permutation. Additionally, the impact of the number of partitions is studied, and the result shows that computational performance improves with more, smaller partitions in the BBD matrices.
This dataset presents a suite of high-resolution downscaled hydro-climate projections over the conterminous United States (CONUS) based on multiple selected Global Climate Models (GCMs) from the Coupled Models Intercomparison Project phase 6 (CMIP6). The CMIP6 GCMs are downscaled using either statistical (DBCCA) or dynamical (RegCM) downscaling approaches based on two meteorological reference datasets (Daymet and Livneh). Subsequently, the downscaled precipitation, temperature, and wind speed are employed to drive two calibrated hydrologic models (VIC and PRMS), enabling the simulation of projected future hydrologic responses across the CONUS. Each ensemble member covers the 1980-2019 baseline and 2020-2059 near-future periods under the high-end (SSP585) emission scenario. Moreover, utilizing only DBCCA and Daymet, the projections are further extended to the 2060-2099 far-future period and across three additional emission scenarios (SSP370, SSP245, and SSP126). This dataset is formulated to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). For further details on this dataset, please refer to Kao et al. (2022) and Rastogi et al. (2022).
The general objective of this white paper is to share lessons learned and provide interdisciplinary recommendations on how to use NLE to evaluate, assess and improve national nuclear security regimes. The specific objectives of this white paper are: — To describe the type of exercises, benefits and requirements — To outline the different capacity areas and capability performance levels — To provide concrete and actionable recommendations to INS’s partners on how to use NLE to improve national nuclear security regimes.
This dataset presents an ensemble of streamflow projections based on the hydroclimate projections dataset supporting the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). The six-member General Climate Model (GCM) ensemble from the Coupled Models Intercomparison Project phase 6 (CMIP6) downscaled using statistical (i.e., DBCCA) and dynamical (i.e., RegCM) and bias-corrected using two meteorological reference observations (Daymet & Livneh) are driven through two calibrated hydrologic models (VIC & PRMS) to simulate projected future hydrologic responses. This leads to the production of an ensemble of hydroclimate projections, including total runoff (surface runoff and baseflow) for 1980–2019 baseline and 2020–2059 near-term future periods under multiple emission scenarios at 1/24° (~4 km) spatial resolution across the CONUS. The total runoff projections are routed through the Routing Application for Parallel computatIon of Discharge (RAPID) routing model to produce an ensemble of streamflow projections for both periods across 2.7 million NHDPlusV2 stream reaches in the CONUS.
We present a suite of high-resolution downscaled hydro-climate projections over the conterminous United States (CONUS) based on a six-member General Climate Model (GCM) ensemble from the Coupled Models Intercomparison Project phase 6 (CMIP6). The CMIP6 GCMs are downscaled using two different downscaling approaches (statistical-based DBCCA & dynamical-based RegCM) based on two meteorological reference observations (Daymet & Livneh), and then fed to two calibrated hydrologic models (VIC & PRMS) to simulate projected future hydrologic responses. Each ensemble member covers 1980–2019 in the historic period and 2020–2059 in the near-term future period under the high-end (SSP585) emission scenario. Major variables such as daily maximum temperature (tmax), daily minimum temperature (tmin), daily total precipitation (prcp), daily average wind speed (wind), and daily total runoff (runoff) at 1/24° (~4 km) spatial resolution across the CONUS are provided through this data portal. This dataset is derived to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). Further details of this dataset can be referred to Kao et al. (2022) and Rastogi et al. (2022).
A good vulnerability testing program can help reduce system compromises, provide a way of assessing and measuring improvements in security, and motivate everyone to get involved.
The Fast Modular Reactor (FMR) is a 50 MWe Gascooled Fast Reactor (GFR) being developed by General Atomics Electromagnetic Systems (GA-EMS) under U.S. Department of Energy’s (DOE’s) Advanced Reactor Demonstration Program (ARDP), specifically Advanced Reactor Concepts 2020 (ARC-20). The 3-year conceptual design of the FMR is being conducted with verifications of key metrics in fuel, safety, and operational performance. GAEMS is pursuing design, licensing, and commercialization of the proposed reactor, with demonstration by 2030 and deployment by the mid-2030s. The U.S. Nuclear Regulatory Commission (NRC) recommends the pre-application regulatory engagement to provide for early identification of regulatory requirements for advanced reactors and to provide all interested parties with a timely, independent assessment of the safety and security characteristics of advanced reactor designs. As such, GAEMS is developing a pre-application regulatory engagement plan (REP) of the FMR.
This report was produced in partial fulfillment of the mitigation of adverse effects to Building 06-CP-10, the first device assembly building on the Nevada National Security Site (NNSS), and is intended to comply with the 2021 Memorandum of Agreement DE-GM58-21NA25543 Between the U.S. Department of Energy and the Nevada State Historic Preservation Officer Regarding Demolition of Fourteen Buildings and Structures in Area 6 of the Nevada National Security Site, Nye County (hereafter referred to as the MOA). This MOA was executed to resolve adverse effects from the U.S. Department of Energy (DOE) plan to demolish 14 architectural resources at the Control Point and in the vicinity in Area 6 of the NNSS. The management and operations contractor for the NNSS identified these 14 architectural resources as environmental hazards unsafe for human occupation due to deterioration and rodent infestation. Building 06-CP-10 and two small magazine bunkers (06-CP-10A and 06-CP-805) associated with Building 06-CP-10 are scheduled for demolition as part of this undertaking. Building 06-CP-10 was originally recorded in 2003 during a historical evaluation of four buildings in Area 6. In consultation with the Nevada State Historic Preservation Office, the building was determined individually eligible for inclusion in the NRHP under the Secretary of the Interior’s Significance Criterion A because of its association with nuclear testing and under Significance Criterion C as a distinct type of construction associated with the nuclear industry. Building 06-CP-10A, a munitions magazine, and 06- CP-805, a cap-and-fuse bunker, have been recorded as contributing accessory resources to 06-CP-10. Pursuant to Stipulation III.C.3 of the MOA, this report provides a summary of the historic significance of Building 06-CP-10 and a description of its current condition and accessory resources. In addition, an updated Architectural Resource Assessment (ARA) form with new information and photographs is included in the appendix in fulfillment of Stipulation III.C.2.
The primary purpose of the Aerospace Computer Security Conference was to bring together people and organizations which have a common interest in protecting intellectual property generated in space. Operational concerns are discussed, taking into account security implications of the space station information system, Space Shuttle security policies and programs, potential uses of probabilistic risk assessment techniques for space station development, key considerations in contingency planning for secure space flight ground control centers, a systematic method for evaluating security requirements compliance, and security engineering of secure ground stations. Subjects related to security technologies are also explored, giving attention to processing requirements of secure C3/I and battle management systems and the development of the Gemini trusted multiple microcomputer base, the Restricted Access Processor system as a security guard designed to protect classified information, and observations on local area network security.
Recent advancement in tools has helped with microgrid design, development, planning and operation. Microgrids offer a unique application based on users with different requirements for tools. The process of designing, constructing, commissioning, and assessing a microgrid is not always straightforward due to these distinct requirements. Additionally, metrics are needed for performance evaluation. This panel will offer an overview and description of tools that helps with microgrid design, construction, planning, operation, cyber security, and metrics-driven performance assessment driven by multiple diverse applications and use cases.
This report documents activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2023 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective, and secure DI&C technologies for digital upgrades/designs. A risk assessment-informed framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk informed capability to quantitatively estimate the safety margin obtained from plant modernization, especially for safety-related DI&C systems, (2) support and supplement existing risk informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of safety-related DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the LWRS-developed framework provides a means to address relevant technical issues by: (1) defining a risk informed analysis process for DI&C upgrade that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies in nuclear power plants (NPPs). Adding diversity within a system or components is the primary means to eliminate and mitigate CCFs, but diversity also increases system complexity and may not address all sources of systematic failures. Optimization of diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in safety-related DI&C systems of NPPs and supporting relevant design optimization, the proposed framework provides: (a) A best-estimate, risk informed capability to address new technical digital issues quantitatively, focusing on software CCFs in safety-related DI&C systems of NPPs; (b) A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to predict and prevent risk in the early design stage of DI&C systems; (c) Technical bases and risk informed insights to assist users address the risk informed alternatives for evaluation of CCFs in safety-related DI&C systems of NPPs; and (d) A risk informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The research and development efforts of this project in FY 2023 are focused on refining current methods on software CCF modeling and estimation and exploring additional innovative approaches to risk assessment of DI&C systems to enable a more comprehensive and complete assessment of various safety-related DI&C design architectures. The primary audience of this report are DI&C designers, engineers, and probabilistic risk assessment (PRA) practitioners. This includes stakeholders, such as the nuclear utilities and regulators who consider the deployment and upgrade of DI&C systems, DI&C software developers and reviewers, and cybersecurity specialists. It should be noted that all the analyses are performed for the demonstration of the methodology, not for the evaluation of an actual digital control system. Results are obtained based on limited design information and testing data.
The Air Toxics "Hot Spots" Information and Assessment Act (AB 2588 or the “Act”) was enacted in September 1987. Under the Act, stationary sources are required to report the types and quantities of certain toxic substances their facilities routinely release into the air. AB 2588 is designed to provide information to state and local agencies and to the general public on the extent of airborne emissions from stationary sources and the potential public health impacts of those emissions. The San Joaquin Valley Air Pollution Control District (the District) is mandated by the State to implement AB 2588. On March 6, 2015, The State Office of Environmental Health Hazard Assessment (OEHHA) adopted changes to the Air Toxics Hot Spots Program Guidance Manual for the Preparation of Health Risk Assessments. These revisions were designed to incorporate three technical support documents and to provide enhanced protection of children as required under state law (SB 25, Escutia, 1999). Due to these recent changes, and the corresponding potential increases in calculated health risk, the District notified LAWRENCE LIVERMORE NATIONAL SECURITY, LLC that we must be re-evaluated under AB 2588. Pursuant to the Air Toxics "Hot Spots" Information and Assessment Act of 1987, we have prepared a comprehensive, site-specific Toxics Emissions Inventory Plan. The plan specifies in detail how LAWRENCE LIVERMORE NATIONAL SECURITY, LLC will inventory our facility's emissions of all toxic substances on the list of substances subject to the Act. The plan provides a comprehensive and detailed description of the methods that will be used to quantify air releases or potential air releases of listed substances from all points of release. The plan also includes quantification methods which result in accurate and comprehensive characterization of releases and comply with all applicable requirements of the “Hot Spots” regulation.
NTESS and its aviation security industry partners developed the Open Threat Assessment Platform (OTAP), an open-architecture platform project that provides a common set of software interfaces and data standards, for Transportation Security Administration airport screening.