Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security monitoring”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Opdefender Network Monitoring And Control System

OpDefender is a new system designed to enhance the cyber security of control system networks. It accomplishes this by inspecting each network packet using a novel, patent-pending method that extends software defined networking into the application/ICS protocol layer. OpDefender consists of two key components: 1. Smart, “ICS-aware” network switches that analyze and filter network traffic in real time. 2. A network management human machine interface (HMI) that allows an operator to monitor and control network traffic in real time. The “ICS-aware” switches can serve as a drop-in replacement for typical network switches, or they can be used in conjunction with existing network switches. OpDefender is configured and controlled in real time via a custom-built, web-based HMI designed with the operator in mind.

Johnson, BriamE.↗

Self-powered Through-wall communication for dry cask storage monitoring

Many nuclear facilities, such as spent fuel storage dry casks and nuclear reactor pressure vessels, are entirely sealed by metal layers to prevent harmful radiation. For safety and security operations, the temperature, pressure, radiation, and humidity inside the vessel needs to be closely monitored. However, no practical technology is currently available to realize the through-wall data communication and monitoring for these vessels due to the inside harsh environment of high temperature and nuclear radiation. In this paper, an innovative self-powered wireless through-wall data communication system for the nuclear environment is presented, which demonstrates a successful solution to such challenges. The presented system is composed of four modules, i.e., energy harvester with power management circuits, ultrasound wireless communication using high-temperature piezoelectric transducers, electronic circuits for sensing and data transmission, and radiation shielding for electronics. Here, constitutive functions of each module were firstly designed and followed by the system integration. Experiments were conducted subsequently to validate the designed functions and evaluate the performance of the integrated system. Results showed that the average power of over 40 mW was harvested from the thermal flow inside the nuclear spent fuel canisters which could provide enough energy to operate the sensing and data communication systems. The gamma radiation test results showed that the thermoelectric energy harvester and ultrasound transceivers can withstand radiation dosing over 100 Mrad. Furthermore, temperature shock tests demonstrated that the entire system including the shielded electronics can survive and maintain their functionalities at temperatures as high as 195°C. Under the in-lab mocked-up high temperature conditions and radiation shielding, the proposed system is foreseen to survive and operate stably for fifty years inside a nuclear spent fuel canister, and send the frequency modulated data out of the canister for 3 s in every 10 min.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Security assessment and impact analysis of cyberattacks in integrated T&D power systems

In this paper, we examine the impact of cyberattacks in an integrated transmission and distribution (T&D) power grid model with distributed energy resource (DER) integration. We adopt the OCTAVE Allegro methodology to identify critical system assets, enumerate potential threats, analyze and prioritize risks for threat scenarios. Based on the analysis, attack strategies and exploitation scenarios are identified which could lead to system compromise. Specifically, we investigate the impact of data integrity attacks in inverted-based solar PV controllers, control signal blocking attacks in protective switches and breakers, and coordinated monitoring and switching time-delay attacks. Index Terms—Cyberattacks, security assessment, impact analysis, case studies, integrated power systems.

14 SOLAR ENERGY↗

Demonstration of acoustic monitoring for structural health of microreactors: Through use of neural networks and resonant ultrasound spectroscopy

Nuclear microreactors prioritize modularity and portability and are intended to be a cost-effective technology for non-conventional nuclear markets. As such, the development of microreactors into a safe and feasible solution for energy security applications will necessitate the development of non-destructive technologies to monitor the integrity of inaccessible reactors components during operation. This demonstration applies linear and nonlinear acoustic techniques, in combination with machine learning, to detect and classify mechanical changes (stress and damage) in a test article which are broadly representative of potential operating challenges within a functioning microreactor. All necessary data has been collected for this demonstration, with minor experimental issues identified that can be addressed in follow-on work. Motivated by the expected conditions within a functioning microreactor, we have demonstrated our monitoring techniques on a core-block-like test article using an unstructured excitation source that approximates the noisy acoustic environment expected during reactor operation. At all stress states mechanically applied to the test article, a machine learning model using an artificial neural network was able to classify with 100% accuracy whether a 3D laser vibrometry point measurement was made on an intact or artificially defective test article. Further, model predictions about whether the defect interface was rough or smooth were 95% accurate, indicating the ability of acoustic techniques to recover defect characteristics. Resonant ultrasound spectroscopy (RUS) was also applied to the dataset to provide further quantitative insights about material properties. RUS analysis was ultimately hampered by several minor experimental and data issues, limiting results to certain cases for this demonstration. Last, analysis using nonlinear RUS exhibited sensitivity to changing levels of applied stresses for each intact and defective state. As presented in this demonstration, acoustic monitoring exhibits sensitivity to stress changes, which are of concern due to high thermal gradients expected during startup and operation. Further, our techniques distinguish between measurements made on intact and damaged test articles.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Man‐in‐the‐middle attacks and defence in a power system cyber‐physical testbed

Abstract Man‐in‐The‐Middle (MiTM) attacks present numerous threats to a smart grid. In a MiTM attack, an intruder embeds itself within a conversation between two devices to either eavesdrop or impersonate one of the devices, making it appear to be a normal exchange of information. Thus, the intruder can perform false data injection (FDI) and false command injection (FCI) attacks that can compromise power system operations, such as state estimation, economic dispatch, and automatic generation control (AGC). Very few researchers have focused on MiTM methods that are difficult to detect within a smart grid. To address this, we are designing and implementing multi‐stage MiTM intrusions in an emulation‐based cyber‐physical power system testbed against a large‐scale synthetic grid model to demonstrate how such attacks can cause physical contingencies such as misguided operation and false measurements. MiTM intrusions create FCI, FDI, and replay attacks in this synthetic power grid. This work enables stakeholders to defend against these stealthy attacks, and we present detection mechanisms that are developed using multiple alerts from intrusion detection systems and network monitoring tools. Our contribution will enable other smart grid security researchers and industry to develop further detection mechanisms for inconspicuous MiTM attacks.

Wlazlo, Patrick↗

Recovery and Calibration of Legacy Underground Nuclear Test Seismic Data from the Leo Brady Seismic Network

The Leo Brady Seismic Network (LBSN, originally the Sandia Seismic Network) was established in 1960 by Sandia National Laboratories to monitor underground nuclear tests (UGTs) at the Nevada National Security Site (NNSS, formerly named the Nevada Test Site). The LBSN has been in various configurations throughout its existence, but it has generally been comprised of four to six stations at regional distances (~150–400 km) from the NNSS with approximately evenly spaced azimuthal coverage. Between 1962 and the end of nuclear testing in 1992, the LBSN—and a sister network operated by Lawrence Livermore National Laboratories—was the most comprehensive United States source of regional seismic data of UGTs. Approximately 75% of all UGTs performed by the United States occurred in the predigital era. At that time, LBSN data were transmitted as frequency-modulated (FM) audio over telephone lines to a central location and recorded as analog waveforms on high-fidelity magnetic audio tapes. These tapes have been in dry temperature-stable storage for decades and contain the sole record of this irreplaceable data; full waveforms of LBSN-recorded UGTs from this era were not routinely digitized or otherwise published. We have developed a process to recover and calibrate data from these tapes. First, we play back and digitize the tapes as audio. Next, we demodulate the FM “audio” into individual waveforms. We then estimate the various instrument constants through careful measurement of “weight-lift” tests performed prior to each UGT on each instrument. Finally, these coefficients allow us to scale and shape the derived instrument response of the seismographs and compute poles and zeros. Finally, the result of this process is a digital record of the recorded seismic ground motion in a modern data format, stored in a searchable database. To date, we have digitized tapes from 592 UGTs.

58 GEOSCIENCES↗

NCERC Provides Unique Opportunities for University Student Researchers

Five students and one faculty member - sponsored by the Defense Nuclear Nonproliferation (DNN, NA 22) university consortia - visited the National Criticality Experiments Research Center (NCERC) in July of 2023 to measure radiation signatures from Category I Special Nuclear Material (SNM) in a week-long measurement campaign organized by staff at Los Alamos National Laboratory. Participants included University of Florida, University of Michigan, and University of Illinois-Champaign Urbana. The measurement campaign was organized on behalf of the Consortium for Monitoring, Testing, and Verification (MTV), the Nuclear Science and Security Consortium (NSSC), and the Consortium for Enabling Technologies and Innovation (ETI).

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

The NREL Sensor Laboratory Detection of Hydrogen Emissions

The development of a functional hydrogen detection system is a multifaceted process that integrates hardware, deployments strategies, and analytics which can be supported by the NREL Sensor Laboratory: 1. Support of the design, validation and optimization of sensing prototypes; 2. Guide optimized sensing element development, including control electronics; 3. Laboratory testing to validate/optimize metrological performance (measurement range, detection limit, etc.); 4. Provide test sites for field deployments representative of real-world scenarios with controlled hydrogen releases; 5. Develop sensor placement and operation guidance; 6. Provide guidance on electronics to accommodate facility integration; 7. Electrical safety designs to allow for operation within restricted zones; 8. Integration into facility monitoring and control systems; 9. Guide incorporation of cyber security elements to protect facilities from malicious attacks; 10. Modeling and application of advanced analytics to detect and quantify emissions; 11. Higher Order dispersion models to guide sensor placement for reliable detection; 12. Advanced analytics for improved metrological performances, and to inform inverse modeling; 13. Market support and commercialization (national and international markets); 14. Commercial deployments in H2@SCALE markets (e.g., HUBs and other large-scale hydrogen markets); and 15. Leverage off international collaborations/partnerships (e.g., NREL is on the advisory board for the European initiative "pre-Normative Research on Hydrogen Releases Assessment"-NHyRA).

08 HYDROGEN↗

Deep Space Network information system architecture study

The purpose of this article is to describe an architecture for the Deep Space Network (DSN) information system in the years 2000-2010 and to provide guidelines for its evolution during the 1990s. The study scope is defined to be from the front-end areas at the antennas to the end users (spacecraft teams, principal investigators, archival storage systems, and non-NASA partners). The architectural vision provides guidance for major DSN implementation efforts during the next decade. A strong motivation for the study is an expected dramatic improvement in information-systems technologies, such as the following: computer processing, automation technology (including knowledge-based systems), networking and data transport, software and hardware engineering, and human-interface technology. The proposed Ground Information System has the following major features: unified architecture from the front-end area to the end user; open-systems standards to achieve interoperability; DSN production of level 0 data; delivery of level 0 data from the Deep Space Communications Complex, if desired; dedicated telemetry processors for each receiver; security against unauthorized access and errors; and highly automated monitor and control.

Beswick, C. A.↗

Mission operations concepts for Earth Observing System (EOS)

Mission operation concepts are described which are being used to evaluate and influence space and ground system designs and architectures with the goal of achieving successful, efficient, and cost-effective Earth Observing System (EOS) operations. Emphasis is given to the general characteristics and concepts developed for the EOS Space Measurement System, which uses a new series of polar-orbiting observatories. Data rates are given for various instruments. Some of the operations concepts which require a total system view are also examined, including command operations, data processing, data accountability, data archival, prelaunch testing and readiness, launch, performance monitoring and assessment, contingency operations, flight software maintenance, and security.

Kelly, Angelita C.↗

Securing Environmental IoT Data Using Masked Authentication Messaging Protocol in a DAG-Based Blockchain: IOTA Tangle

The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.

Gangwani, Pranav (ORCID:0000000159226002)↗

System and method for monitoring power consumption to detect malware

A system and method (referred to as the system) detects malware, viruses, and/or malicious activity by generating a direct current source power consumption profile by causing a monitored device to execute a fully automated recurrent software operation. The system receives by an automated detection system, the direct current source power consumption profile generated by an intelligent power sensor and generates by a detection engine, a power security profile that identifies suspicious code by profiling direct current consumed by monitored type devices. The system executes a detection engine remote from the monitored device that identifies an infected device.

97 MATHEMATICS AND COMPUTING↗

Y-12 Groundwater Protection Program Groundwater and Surface Water Sampling and Analysis Plan (CY 2021)

This plan provides a description of the groundwater and surface water quality monitoring activities planned for calendar year (CY) 2021 at the U.S. Department of Energy Y-12 National Security Complex (Y-12) that will be managed by the Y-12 Groundwater Protection Program (GWPP). Groundwater and surface water monitoring is performed by the GWPP. Groundwater and surface water monitoring will be performed in three hydrogeologic regimes at Y-12: the Bear Creek Hydrogeologic Regime (Bear Creek Regime), the Upper East Fork Poplar Creek Hydrogeologic Regime (East Fork Regime), and the Chestnut Ridge Hydrogeologic Regime (Chestnut Ridge Regime). The Bear Creek and East Fork regimes are located in Bear Creek Valley and the Chestnut Ridge Regime is located south of Y-12. Additional surface water monitoring will be performed north of Pine Ridge along the boundary of the Oak Ridge Reservation. The following sections of this report provide details regarding the CY 2021 groundwater and surface water monitoring activities. Section 2 describes the monitoring locations in each regime and the processes used to select the sampling locations. A description of the field measurements and laboratory analytes is provided in Section 3. Sample collection methods and procedures are described in Section 4, and Section 5 lists the documents cited for more detailed operational and technical information. The narrative sections of the report reference several appendices. Figures (maps and diagrams) and tables (excluding a data summary table presented in Section 4) are in Appendix A and Appendix B, respectively. Groundwater Monitoring Schedules (when issued throughout CY 2021) will be inserted in Appendix C, and addenda to this plan (if issued) will be inserted in Appendix D. Laboratory requirements (bottle lists, holding times, etc.) are provided in Appendix E, and an approved Waste Management Plan is provided in Appendix F. Modifications to the CY 2021 monitoring program may be necessary during implementation. Changes in programmatic requirements may alter the analytes specified for selected monitoring wells or may add or remove wells from the planned monitoring network. Each modification to the monitoring program will be approved by the Y-12 GWPP manager and documented as an addendum to this sampling and analysis plan.

54 ENVIRONMENTAL SCIENCES↗

Y-12 Groundwater Protection Program Groundwater and Surface Water Sampling and Analysis Plan for Calendar Year 2022

This plan provides a description of the groundwater and surface water quality monitoring activities planned for calendar year (CY) 2022 at the U.S. Department of Energy Y-12 National Security Complex (Y-12) that will be managed by the Y-12 Groundwater Protection Program (GWPP). Groundwater and surface water monitoring will be performed in three hydrogeologic regimes at Y-12: the Bear Creek Hydrogeologic Regime (Bear Creek Regime), the Upper East Fork Poplar Creek Hydrogeologic Regime (East Fork Regime), and the Chestnut Ridge Hydrogeologic Regime (Chestnut Ridge Regime). The Bear Creek and East Fork regimes are located in Bear Creek Valley and the Chestnut Ridge Regime is located south of Y-12. Additional surface water monitoring will be performed north of Pine Ridge along the boundary of the Oak Ridge Reservation. The following sections of this report provide details regarding the CY 2022 groundwater and surface water monitoring activities. Section 2 describes the monitoring locations in each regime and the processes used to select the sampling locations. A description of the field measurements and laboratory analytes is provided in Section 3. Sample collection methods and procedures are described in Section 4, and Section 5 lists the documents cited for more detailed operational and technical information.

54 ENVIRONMENTAL SCIENCES↗

Compilation and Evaluation of Data from Groundwater Impounded within the U12n and U12t Tunnels, Rainier and Aqueduct Mesas, Nevada National Security Site

The Department of Defense (DOD) Defense Threat Reduction Agency (DTRA) and the U.S. Department of Energy (DOE) Office of Environmental Management Nevada Program (EM NV) conducted routine physical and geochemical monitoring of water impounded behind impermeable structures placed within the U12n and U12t tunnels on the Nevada National Security Site (NNSS) (formerly the Nevada Test Site [NTS]). Desert Research Institute (DRI) conducted a semiquantitative evaluation of pressure data to determine the extent to which the tunnels have been inundated and a qualitative evaluation of monitored geochemical parameters to determine if trends exist that were indicative of hydrologic and/or geochemical processes operating behind the tunnel plugs. Data were also evaluated to determine if monitored radiological parameters exceeded primary standards associated with the Environmental Protection Agency’s (EPA) Safe Drinking Water Act (SDWA) (40 C.F.R. § 141.66).

54 ENVIRONMENTAL SCIENCES↗

User Access to Scientific Facilities via 5G: A Cyber Security Thought Experiment

5G is more than an over-the-air radio technology upgrade. It is a strategy to extend Mobile Network Operator service offerings beyond traditional voice, instant messaging and Internet access. 5G Mobile Network Operators will offer new telecommunication services that include enhanced guarantees of confidentiality, integrity and availability. How could such services change the way Science collaborations connect scientists to supercomputers and other scientific facilities? Current scientific collaborations implicitly trust cloud service providers to securely store and process data. The perceived risks of outsourcing Science data security are counterbalanced by assurances that cloud providers operate at a scale that allows them to implement security measures impractical for Science collaborations (e.g. continuous system administrator behavioral monitoring and strict individual separation of duties). If that is true for a cloud service provider like Amazon Web Services (2018 revenue: $25.7 billion), could it also be true for Mobile Network Operators like Verizon Wireless (2018 revenue: $91.7 billion) or AT&T Mobility (2018 revenue: $71.3 billion)? DOE Leadership Class supercomputer facility users currently access them from the public Internet via Secure Shell. The sponsors and operators of the supercomputer facilities have determined that the public Internet path between the Scientist’s Device and the Login Node does not natively provide enough confidentiality or integrity to protect those communications. Therefore, the facilities achieve additional confidentiality and integrity by requiring Secure Shell encryption across those untrusted network paths. Using 5G Network Slice technology, a Mobile Network Operator may offer communication services between supercomputer users and facilities that natively provide confidentiality and integrity guarantees. Sponsors and operators of supercomputer facilities may determine that these guarantees provide enough confidentiality and integrity to protect those communications. If so, a 5G Network Slice could replace an SSH session running over the public Internet. Finally, this use case could be extended to other Office of Science user facility access requirements. Consider microscopy instruments at (e.g.) the Center for Nanoscale Materials or the Environmental Molecular Sciences Laboratory. The embedded systems controlling such instruments may not always support encrypted network access technologies like SSH. 5G Network Slices may offer an alternative to current VPN or SSH tunneling techniques, with additional benefits like guaranteed minimum bandwidth.

5G↗

Anatomy of a Security Operations Center

Many agencies and corporations are either contemplating or in the process of building a cyber Security Operations Center (SOC). Those Agencies that have established SOCs are most likely working on major revisions or enhancements to existing capabilities. As principle developers of the NASA SOC; this Presenters' goals are to provide the GFIRST community with examples of some of the key building blocks of an Agency scale cyber Security Operations Center. This presentation viII include the inputs and outputs, the facilities or shell, as well as the internal components and the processes necessary to maintain the SOC's subsistence - in other words, the anatomy of a SOC. Details to be presented include the SOC architecture and its key components: Tier 1 Call Center, data entry, and incident triage; Tier 2 monitoring, incident handling and tracking; Tier 3 computer forensics, malware analysis, and reverse engineering; Incident Management System; Threat Management System; SOC Portal; Log Aggregation and Security Incident Management (SIM) systems; flow monitoring; IDS; etc. Specific processes and methodologies discussed include Incident States and associated Work Elements; the Incident Management Workflow Process; Cyber Threat Risk Assessment methodology; and Incident Taxonomy. The Evolution of the Cyber Security Operations Center viII be discussed; starting from reactive, to proactive, and finally to proactive. Finally, the resources necessary to establish an Agency scale SOC as well as the lessons learned in the process of standing up a SOC viII be presented.

Wang, John↗

Towards 5G-Enabled Operational Technology for Process Monitoring and Network Slicing

Cyber-Physical Systems (CPS) are deployed to monitor physical processes in critical cyber-enabled services like power generation. However, CPS ecosystems are typically designed without robust security. While it is important to ensure optimal performance of the Operational Technology (OT) environments, security cannot be overlooked. To modernize traditional OT services, 5G technology is being integrated. 5G technology offers low latency and high availability, making it a suitable infrastructure for managing and monitoring physical processes. How-ever, integrating 5G mechanisms into large-scale OT networks introduces new implementation and performance challenges. Therefore, this paper presents a 5G-enabled CPS architecture (5G-CPS) that describes the necessary components, services, and communication protocols and conducts feasibility study to integrate 5G technology in industrial control system networks to understand the performance merits. The 5G-CPS architecture aims to minimize implementation and operational challenges associated with integrating 5G technology into constrained OT.

Aguayo, Jared M.↗