Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrating Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Protecting and Defending against Autonomous Control Systems and Digital Twin Cyber Attacks: Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Models in Nuclear Power Plants (Final)

Navigating through the complex tapestry of technological advancements, "Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Model in Nuclear Power Plants" stands at the intersection of cybersecurity and nuclear power plant operations, embarking on a journey through the intricacies of securing digital twins against malicious cyber activities. As nuclear power plants progressively integrate digital twin technology and machine learning models to optimize operations and ensure system reliability, they inadvertently expose themselves to a new spectrum of vulnerabilities, notably in the realm of hyperparameter attacks. Hyperparameters, integral in machine learning model tuning and optimal performance of digital twins, have emerged as a target for adversaries aiming to destabilize the predictive capabilities and therefore, the operational accuracy of these digital entities within critical infrastructures like nuclear plants. This paper, therefore, meticulously threads the needle through the development of a robust response strategy, poised to shield these digital reflections against calculated hyperparameter manipulations, ensuring that the digital twin can effectively and securely function as a reliable proxy for its physical counterpart. The ensuing sections delve into the orchestrated maelstrom of multi-rate time-changing intelligent coordinated hyperparameter attacks and the implementation of event-triggered predictive control, laying down a structured, predictive, and responsive framework that safeguards the nexus where the digital and physical realms of nuclear power plants coalesce. The operational integrity of digital twins in nuclear power plants depends critically on the security of machine learning hyperparameters. This study makes two different contributions. First, a decision-based idea known as a multi-rate time changing intelligent coordinated hyperparameter attack is put forth. In this attack, many hyperparameters are repeatedly changed using both random and intelligent optimal techniques by the attacker. These assaults introduce varied rates at different attack steps, compromise various amounts of hyperparameters, and improve stealth and flexibility. Second, a technique is developed for event triggered predictive control to rapidly respond to potential hyperparameter attacks. This control integrates a sliding window framework, retaining a history of previous data points and employing linear regression to predict the next data point from the current dataset. The control gain K is determined using the Lyapunov-Krasovskii method, and subsequently, an action is developed. Finally, the outcome of the simulation demonstrates the viability of the proposed method for defending nuclear power plant digital twins from hyperparameter attacks.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Hierarchical Attention Framework for Multimodal Malware Detection

The increasing use of Android in the worldwide mobile ecosystem has come along with a significant increase in advanced malware, highlighting the critical necessity for efficient, scalable, and adaptable detection systems. Despite recent advancements in machine learning improving malware detection, the majority of current solutions are limited to one, two, or three data modalities, hence neglecting the comprehensive behavioral spectrum of contemporary multi-vector threats. This thesis presents the first comprehensive multimodal framework for Android malware detection, which combines textual, time-series (temporal), graph-based (structural), and visual information using an innovative hierarchical attention mechanism and Dynamic Fusion Controller (DFC). Our methodology consistently classifies and processes modalities as either sequential or structural, facilitating content-adaptive weighting and resilient cross-modal representation learning. We advance the implementation of cutting-edge time series techniques, such as MiniRocket, for malware detection, hence creating new opportunities for temporal analysis in cybersecurity. Comprehensive experimental assessment shows that our framework performs exceptionally well, with 99.46% classification accuracy and 97.15% detection accuracy, significantly outperforming existing approaches through effective multimodal integration and hierarchical attention mechanisms.

Nazmin, Tamanna↗

Cyote-attack Chain Estimator

Attack Chain Estimator (ACE) Application Overview The Attack Chain Estimator (ACE) Application is a sophisticated tool designed for the ingestion, classification, sequencing, and enrichment of cybersecurity threat reports. This application leverages advanced machine learning models and extensive historical data to provide comprehensive insights into cyber threats, specifically targeting Industrial Control Systems (ICS). Purpose The primary functions of the ACE Application include: Ingestion of Cybersecurity Threat Reporting: Capable of ingesting text-based threat reports in markdown or text file format. Supports ingestion of structured data from other sources in STIX/JSON format. Classification of Report’s Text-Based Events: Utilizes a DeBERTa classifier, specifically trained on cybersecurity data, to map the events to MITRE ATT&CK for ICS Tactics and Techniques. Classification is performed using multiple Jupyter notebooks and machine learning workflows hosted as FastAPI microservices: regex_data deberta_base_35_train_hft_classifier_mlflow.ipynb hft_regex_classifier_mlflow.ipynb param_train_hft_classifier_mlflow.ipynb regex_tactic_tech.ipynb Ordering of Tactics, Techniques, and Observable Events: Sequences the identified tactics, techniques, and events to form a coherent attack chain. Enrichment with Historical Attack Chain Details: Enhances the attack chain with details from historical attacks using a Markov model developed from CyOTE Precursor Analysis Report data. The Markov model is available as a FastAPI endpoint for seamless integration. Enrichment with Adversary Emulation Capabilities Data: Integrates adversary emulation capabilities data using MITRE Caldera for OT adversary abilities UUIDs. Export of Output Files: Provides options to export the enriched attack chain in JSON or CSV formats. Routing of Output to Other Applications: Facilitates routing of output to various platforms and applications, including: Threat Intelligence Platforms COREII Scout for Threat Intelligence Analysis COREII Modeling and Simulation for Adversary Emulation Technical Description The ACE Application is an advanced cybersecurity tool designed to provide detailed threat analysis and sequence generation. It is built on a robust architecture that integrates natural language processing, machine learning, and historical data modeling. Key Components: Data Ingestion Module: Handles the input of threat reports and data from various formats, ensuring flexibility in data sources. Classification Engine: Employs DeBERTa-based classifiers hosted as FastAPI microservices to analyze and classify threat report events in accordance with the MITRE ATT&CK framework for ICS. Sequence Generator: Orders the classified events into a logical attack chain, providing clear insight into the sequence of tactics and techniques used in the threat. Enrichment Engine: Integrates historical data and adversary emulation capabilities to enhance the attack chain with valuable context and additional details. The historical data enrichment is powered by a Markov model, which is available as a FastAPI endpoint. Export and Routing Module: Facilitates the export of the enriched attack chain in multiple formats and routes the output to designated applications for further analysis or emulation.

Paul, Tony [Idaho National Laboratory (INL), Idaho↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Development of an Assessment Methodology That Enables the Nuclear Industry to Evaluate Adoption of Advanced Automation

Nuclear power has a crucial role in providing safe, reliable, and economical carbon-free electricity for today and the future. For continued operation, many of the existing United States nuclear power plants will begin the subsequent license renewal process for extending their operating license periods. As plants extend their expected operating lifetimes, there is a significant opportunity to modernize. These plants have a much stronger business case with these extended mission periods to modernize and significantly enhance their economic viability in current and future energy markets by implementing digital technologies that support innovation, efficiency gains, and business-model transformation. Ensuring continued safety and reliability is crucial. Transformative digital technologies—including automation—that fundamentally change the concept of operation for the nuclear power plant operating model requires a critical focus on the human and technology integration element. Further, the nuclear industry has historically been reluctant to modernize due to having a risk adverse culture and lack of clarity for a transformative new state vision (Joe & Remer, 2019; Thomas et al., 2020). Common barriers include (1) the perceived value and return on investment (ROI) of digital technology, (2) the perceived risk associated with licensing, regulatory, and cybersecurity, and (3) insufficient guidance for performing digital modifications to power generation systems. This work presents a methodology to address these barriers and support the industry in adopting advanced automation and digital technology through developing a transformative vision and implementation strategy that will address the human and technology integration element. This research leverages previous LWRS Program and industry results. It draws specifically on previous LWRS Program research in the areas of advanced alarm systems, computer-based procedures, model informed decision support, and advanced human-system interface displays (e.g., overviews and task-based). The modernization methodology can be used to guide transformative thinking when integrating a set of vendor-specific capabilities to support a new concept of operations and a utility’s end-state vision. The results of this research are organized into six major sections: - Section 1 introduces the need for supporting large-scale digital modifications that will renew the technology base for extended operating life beyond 60 years - Section 2 describes the challenges that the nuclear industry is enduring with modernizing. - Section 3 summarizes the primary standards and guidance. - Section 4 presents earlier work from the LWRS Program regarding the development of a transformative conceptual design for an advanced control room of a hybrid plants. - Section 5 presents a methodology that is designed at addressing the challenges in the industry today in achieving a transformative new state vision and concept of operations. - Conclusions and next steps of this research are provided in Section 6.

99 GENERAL AND MISCELLANEOUS↗

Developing an AI-Powered Zero-Trust Cybersecurity Framework for Malware Prevention in Nuclear Power Plants

This study presents the development of an AI-powered Zero-Trust cybersecurity framework for malware prevention in nuclear power plants. The framework aims to enhance the security of critical systems within nuclear power plants by adopting the principles of Zero-Trust and leveraging artificial intelligence (AI) technologies. By assuming no implicit trust in any user or device and continuously authenticating and authorizing access, the framework ensures a robust defense against malware attacks. The integration of AI allows for the detection and prevention of malware through behavioral analytics, endpoint protection, network segmentation, and continuous monitoring. The paper discusses the key considerations, steps, and technologies involved in developing this framework, emphasizing the importance of regular updates, training, compliance, and auditing. The proposed framework serves as a comprehensive approach to safeguarding nuclear power plants from sophisticated malware threats and protecting the integrity and safety of critical infrastructure.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Exploring the Adoption Challenges of Post-Quantum Cryptography in EV Charging Infrastructure

The rapid evolution of electric vehicle (EV) technology and the corresponding growth of the Electric Vehicle Charging Infrastructure (EVCI) brings to light significant cybersecurity concerns, notably in the context of emerging post-quantum computing capabilities. This report, prepared by Pacific Northwest National Laboratory (PNNL) under the U.S. Department of Energy contract, delves into the challenges associated with integrating Post-Quantum Cryptography (PQC) into EVCI to safeguard against potential quantum computing threats. Post-quantum computers will eventually be able to invalidate technologies secured through public key cryptography. As part of this effort, the primary gaps and challenges in the EVCI were investigated with a focus on comparing traditional algorithms against PQC algorithms. One of the notable findings was that the P-521 algorithm was frequently surpassed in performance by PQC algorithms. This document provides a thorough examination of the hurdles the industry can expect when transitioning to PQC within the EVCI, such as interoperability concerns, the computational and memory demands of PQC algorithms, and the organizational readiness for such a transition. It emphasizes the necessity of a forward-thinking approach to cybersecurity, advocating for early and strategic engagement among EVCI stakeholders to ensure a seamless and cost-effective migration to quantum-resistant cryptographic standards. Through this report, the authors aim to catalyze awareness and action among policymakers, industry leaders, and cybersecurity professionals towards fortifying the EVCI against emerging quantum threats, thereby securing the infrastructure essential for the future of electric mobility.

33 ADVANCED PROPULSION SYSTEMS↗

Deep Reinforcement Learning for Resilient Power and Energy Systems: Progress, Prospects, and Future Avenues

In recent years, deep reinforcement learning (DRL) has garnered substantial attention in the context of enhancing resilience in power and energy systems. Resilience, characterized by the ability to withstand, absorb, and quickly recover from natural disasters and human-induced disruptions, has become paramount in ensuring the stability and dependability of critical infrastructure. This comprehensive review delves into the latest advancements and applications of DRL in enhancing the resilience of power and energy systems, highlighting significant contributions and key insights. The exploration commences with a concise elucidation of the fundamental principles of DRL, highlighting the intricate interplay among reinforcement learning (RL), deep learning, and the emergence of DRL. Furthermore, it categorizes and describes various DRL algorithms, laying a robust foundation for comprehending the applicability of DRL. The linkage between DRL and power system resilience is forged through a systematic classification of DRL applications into five pivotal dimensions: dynamic response, recovery and restoration, energy management and control, communications and cybersecurity, and resilience planning and metrics development. This structured categorization facilitates a methodical exploration of how DRL methodologies can effectively tackle critical challenges within the domain of power and energy system resilience. The review meticulously examines the inherent challenges and limitations entailed in integrating DRL into power and energy system resilience, shedding light on practical challenges and potential pitfalls. Additionally, it offers insights into promising avenues for future research, with the aim of inspiring innovative solutions and further progress in this vital domain.

24 POWER TRANSMISSION AND DISTRIBUTION↗

4th Big Data for Nuclear Power Plants Workshop 2023

The Ohio State University and Idaho National Laboratory organized the 4 th Big Data for Nuclear Power Plants Workshop in November, 2023 in Columbus, Ohio. Workshop topics were chosen to understand the challenges and gaps that need to be addressed to maximize the impact of data on the nuclear industry, as well as the associated applications and risks. Discussions were focused around six specific application areas: Operation and Maintenance; Machine Learning in Nuclear Materials and Advanced Manufacturing; Cybersecurity; High-Performance Computing and Massive Computation; Big Data and Digital Twins; and Nuclear Non-Proliferation. The opportunities, challenges, and risks identified in the six focus areas explored in this workshop are diverse, but some common themes emerge, such as the importance of data integrity, quality, coverage, privacy, and traceability. Big data and AI/ML tools can be leveraged to reduce costs, optimize human tasking, and reduce human error across various application areas. In order for the nuclear industry to benefit from big data and advanced analytic capabilities, it is essential to address challenges and risks, such as data privacy, model reliability, and computational resource availability. Learning from other industries that have successfully implemented big data and AI/ML technologies, like the aerospace industry, can help the nuclear industry successfully integrate these technologies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Network Security via Biometric Recognition of Patterns of Gene Expression

Molecular biology provides the ability to implement forms of information and network security completely outside the bounds of legacy security protocols and algorithms. This paper addresses an approach which instantiates the power of gene expression for security. Molecular biology provides a rich source of gene expression and regulation mechanisms, which can be adopted to use in the information and electronic communication domains. Conventional security protocols are becoming increasingly vulnerable due to more intensive, highly capable attacks on the underlying mathematics of cryptography. Security protocols are being undermined by social engineering and substandard implementations by IT organizations. Molecular biology can provide countermeasures to these weak points with the current security approaches. Future advances in instruments for analyzing assays will also enable this protocol to advance from one of cryptographic algorithms to an integrated system of cryptographic algorithms and real-time expression and assay of gene expression products.

cybersecurity↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

Guide to the Distributed Energy Resource Risk Management Framework

The emergence of distributed energy resources (DERs) has transformed the electric power sector and will likely have even more profound impacts on the future evolution of the United States energy sector as it modernizes and becomes more reliant upon complex informatics programming and systems to ensure that our power grid remains safe from malicious interference. To mitigate risks associated with the increased and diversified use of DERs, the Distributed Energy Resource Cybersecurity Framework (DER-CF) was developed in 2019. The National Renewable Energy Laboratory extended the scope of the DER-CF to include the RMF. To address the challenges faced by federal energy managers and energy system stakeholders in applying the RMF to DER systems, the Distributed Energy Resource Risk Manager (DER-RM) is a six-step process to proactively manage cybersecurity risk in a methodical manner. The DER-RM is independent of the DER-CF's existing assessment, allowing users to focus specifically on the RMF steps. The tools are targeted to different processes - DER-CF enables organizations to perform self-assessments to improve their cybersecurity posture, while DER-RM assists organizations in achieving compliance with specific requirements. This document provides an overview of the DER-RM. The RMF process outlined in this report serves as a guide to diagnose information and operational system threats, gather required materials to comply with industry standards, and document plans for achieving Authority to Operate. Using the DER-RM, federal agencies and other organizations can easily and intuitively follow the RMF process, manage the risks to their grid-edge infrastructure through the integration of their on-site DERs, and comply with appropriate requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Critical Roles of Information, Analysis, Research, and Operations in the Cyber Realm

PNNL has developed an adaptive cyber integration framework (ACIF) to facilitate the timely sharing of cyber threat information along with the advancement of situational awareness tools to enhance protection against and respond to critical infrastructure cybersecurity threats. The ACIF comprises components implemented iteratively to achieve research and mission goals. The ACIF components include data generation technologies, analytic tools development and maturation, data enrichment and fusion, trust building with stakeholders, investigative research, analytic rigor, production, and dissemination. Each component, its importance to the ACIF, and how they can be adopted and applied across other information-sharing sectors and domains are discussed in this paper.

Cyber Threat Intelligence, Cyber Security, Data En↗

Commercial integration of advanced nuclear energy with Artificial Intelligence (AI): Possible implications

The integration of advanced nuclear technologies (both fission and fusion) with artificial intelligence (AI) presents unprecedented national security challenges and opportunities. As fusion energy approaches commercial viability alongside advanced Small Modular Reactors (SMRs), their integration with AI and Artificial General Intelligence (AGI) systems could fundamentally transform the global energy and AI landscapes — two pillars of national security. This document briefly examines how AI could accelerate nuclear energy development and deployment while altering existing power structures, a lot could be done to deepen the discussions. Simultaneously, it observes how nuclear-powered AI may expedite advances toward AGI and beyond. These issues are deeply interconnected and thus need to be examined as a whole and more comprehensively than what’s being summarized here. For instance, AI-powered autonomous operation of nuclear facilities could reduce human error but introduce new cybersecurity vulnerabilities and uncertainties. Further investigation would also address how AI-enhanced nuclear technologies might complicate proliferation concerns through advanced fuel cycle management, nuclear materials production and safeguard. The strategic advantage gained by first entities achieving successful AI-nuclear integration could reshape global and national security framework. Timely analysis of these implications may be crucial for policymakers seeking to harness these technologies' benefits while effectively mitigating their potential risks.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Formally Verified ZTA Requirements for OT/ICS Environments with Isabelle/HOL: Preprint

The clean energy transformation led to the integration of distributed energy resources on a top of the grid, and so a substantial increase in the complexity of power grids infrastructure and the underlying operational technology environment. Operational technology environments are becoming a system of systems, integrating heterogeneous devices which are software/hardware intensive, have ever increasing demands to exploit advances in commodity of software/hardware infrastructures, and this for good reasons - improving energy systems requirements such as cybersecurity and resilience. In such a setting, system requirements at different levels mix, thus undesirable outcomes will surely happen. The use of formal methods will remove ambiguity, increase automation and provide high levels of assurance and reliability. In this paper, we contribute a methodology and a framework for the system level verification of zero trust architecture requirements in operational technology environments. We define a formal specification for the core functionalities of operational technology environments, the corresponding invariants, and security proofs. Of particular note is our modular approach for the formal verification of asynchronous interactions in operational technology environments. The formal specification and the proofs have been mechanized using the interactive theorem proving environment Isabelle/HOL.

formal methods↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Survey on Cybersecurity Challenges, Detection, and Mitigation Techniques for the Smart Grid

The world is transitioning from the conventional grid to the smart grid at a rapid pace. Innovation always comes with some flaws; such is the case with a smart grid. One of the major challenges in the smart grid is to protect it from potential cyberattacks. There are millions of sensors continuously sending and receiving data packets over the network, so managing such a gigantic network is the biggest challenge. Any cyberattack can damage the key elements, confidentiality, integrity, and availability of the smart grid. The overall smart grid network is comprised of customers accessing the network, communication network of the smart devices and sensors, and the people managing the network (decision makers); all three of these levels are vulnerable to cyberattacks. In this survey, we explore various threats and vulnerabilities that can affect the key elements of cybersecurity in the smart grid network and then present the security measures to avert those threats and vulnerabilities at three different levels. In addition to that, we suggest techniques to minimize the chances of cyberattack at all three levels.

Tufail, Shahid↗

Charting the unknown: A dive into the world of standards mapping

When you hear standards mapping what do you think about? For the Secure Software Central (SSC) project this means comparing our process to the National Institute of Standards and Technology’s (NIST) security control catalog. So how is it done? The project completed this summer can be broken down into three simple phases. Phase one consists of mapping the SSC process to the NIST’s security control catalog. While phase two entails mapping mitigations from a threat profile to NIST. Lastly phase three requires the creation of a knowledge base allowing for the reuse of controls across numerous projects This project presented a few different challenges: locating the correct control within the NIST catalog while correctly matching the proposed mitigations from the SSC team, accurately leveling the mitigation to the security level of the system, creating a toolbox to showcase a dataset of mitigations and standards to be used in current and future projects. each challenge allowed for opportunities in growth and understanding of how security controls can map to a governing set of standards. These standards maps are a crucial element to support the insights provided by the SSC team and allow the client to have confidence in the work being completed. My internship has allowed me to set and achieve many goals such as coming to understand that the field of cybersecurity truly is the right place for me. I have also learned that it’s ok to be wrong if you learn something from it. For significant accomplishments I have helped integrate standards mapping into the fabric of SSC. The field experience that I have gained such as interacting with the SSC team along with other senior staff and building a good rapport are crucial skills to. This time at PNNL has been an irreplaceable experience.

42 ENGINEERING↗