Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Cyber Physical Security (CPS) Extension to Air Traffic Management (ATM) Testbed

The Air Traffic Management (ATM) Testbed is being developed at NASA to enable benefit, impact, safety and cost assessments for accelerating the deployment of Concept and Technologies (C&T) in the National Airspace System (NAS). Today, C&T introduction into the NAS takes decades. The primary reason for this is an inability to assess the operational impact of the interaction between the proposed C&T and operationally deployed systems (Realistic Technologies) in terms of NAS-wide safety, traffic flow efficiency, roles and workload of controllers and traffic managers, and impact on airline fleet operations. Transition of C&T to operations requires mathematical modeling and simulation, Human-in-the-Loop (HITL) testing and shadow-mode evaluation driven by operational data. Whereas interaction with the operational system during testing and stages of deployment is not permissible due to safety concerns, it is certainly possible to create a simulation environment that closely mimics the NAS using the same operational systems/hardware for enabling such assessments. This presentation focuses on a proposed Cyber Physical Security extension to the ATM Testbed for creating a modeling and simulation architecture to study how well the Air Traffic Management system will perform and analyze effectiveness of mitigating security measures against particular cyber-attack scenarios.

Datta, Koushik↗

Mission-centric cyber security assessment of critical systems

We present a novel model-based, mission-centric approach to perform cyber security assessments for evaluating the impact of low-level cyber events on high-level mission objectives.We demonstrate the benefits of our approach using a system model and attack trees specific to the command-and-control system of a spacecraft. Specifically, we demonstrate how our approach enables a decision-maker to assess the security posture of the system, identify necessary mitigations and prioritize their deployment.

Tan, Kymie↗

Role of Cyber-Physical Testing in Developing Resilient Extraterrestrial Habitats

Extraterrestrial long-term habitat systems (henceforth referred to as habitat systems) require groundbreaking technological advances to overcome the extreme demands introduced by isolation and challenging environments. A habitat system must operate as intended under continuous disruptive conditions. Designing for the demands that challenging environments will place on habitat systems (e.g., wild temperature fluctuations, galactic cosmic rays, destructive dust, meteoroid impacts, vibrations, and solar particle events) represents one of the greatest challenges in this endeavor. This engineering problem necessitates that we design and manage habitat systems to be resilient. System resilience requires a comprehensive approach that accounts for disruptions through the design process and adapts to them in operation. As the habitat system evolves—growing in physical size, complexity, population, and connectivity—and diversifies in operations, it must continue to be safe and resilient. In this endeavor, we should take advantage of lessons learned in developing civil infrastructure responsive to catastrophic natural hazards, autonomous robotics platforms, smart buildings, cyber-physical testing, complex systems, and diagnostics and prognostics for intelligent health management. This study highlights the importance of system resilience and cyber-physical testing to address the grand challenge of developing habitat systems.

Public health and safety↗

Thermal Actuator Identification and Control for Thermomechanical Real-Time Cyber–Physical Testing

Thermomechanical cyber–physical testing enables two-way thermal coupling between a numerical and an experimental subsystem. The interactions between the numerical model and the physical specimen occur through transfer systems, which enforce interface conditions. Thus, efficient control methodologies are necessary to achieve the desired interface interaction through thermal actuators with minimal error. This study introduces a novel thermal transfer system that imposes distributed cooling (or heating) thermal loads on a physical subsystem. First, the thermal actuator is identified considering switching-mode continuous dynamics for heating and cooling conditions. A switching-mode estimation algorithm is adopted to estimate the operating thermal cycle of the actuator in real-time. A control system is developed to experimentally impose the desired temperature and reduce tracking error (i.e., the error between the desired and actual temperature) under different thermal cycles. The identification and control of the thermal transfer system are then validated through a set of experiments considering different temperature rates of change. The developed control system is found to effectively minimize tracking errors in real-time cyber–physical experiments.

Herta Montoya↗

The Nuclear Digital I&C System Supply Chain Cyber-Attack Surface

The nuclear supply chain attack surface is a large, complex network of interconnected stakeholders and activities. The global economy has widened and deepened the supply chain, resulting in larger numbers of geographically dispersed locations and increased difficulty ensuring the authenticity and security of digital assets. Although the nuclear industry has made significant strides in securing facilities from cyber-attacks, the supply chain remains vulnerable. This paper outlines supply chain threats and vulnerabilities and provides a Digital I&C System Supply Chain Cyber-Attack Surface diagram to illustrate the complexity of securing hardware, firmware, software, and system information throughout the entire supply chain lifecycle. The knowledge presented in this paper provides a foundation to use in cybersecurity supply chain risk analysis and to guide future supply chain research and development efforts leading to enhancement of a nuclear facility’s overall security posture.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Cyber for All! A LinkedIn Article

As part of NSD's cyber security careers recruitment campaign i was asked to write a LinkedIn article of 300 words on cyber security.

O'Neil, Lori Ross↗

Data-driven model generation for deception defence of cyber-physical environments

Cyber-physical systems have the potential to greatly improve both the economic and the environmental efficiency of our current infrastructure. However, the necessary fusing of the cyber world with the physical world that results from these technologies also creates a host of new attack opportunities. In this work, we discuss how deception can be employed to effectively defend these systems.

Nowak, Kathleen E.↗

Cyber Threat Landscape for Distribution Systems

INL cyber analysts will present an overview of the current threat landscape for distribution systems. We will begin with examples of known attacks that have occurred recently to motivate the threat analysis and mitigation discussed in the remainder of the presentation. Examples may include the attacks affecting wind plants in Europe in Spring 2022, ransomware attacks on city utilities and commercial distribution systems, and advanced persistent threats (APTs) including the attacks on Ukrainian electric system in 2015 and 2016, as well as more recent evidence of other APT activity. We will present the end-to-end attack paths and discuss the various attacker skills, financing, motivations, and access that contributed to these attacks. In the second part of this presentation, we will discuss mitigating the cyber threats for distribution systems. We will discuss recent publicly disclosed vulnerabilities and explain their relevant context for distribution system security. Likely attacks to affect distribution systems, such as denial-of-service (DoS), ransomware, edge-device compromise, and advanced persistent threats (APTs) will be described. In addition to an overview of these kinds of attacks, we will provide examples of the various ways in which these attacks can start and what systems they can affect. Simple, cost-effective counter-measures to these attacks will be discussed and we will emphasize how these mitigations can reduce threats when properly applied and maintained.

24 POWER TRANSMISSION AND DISTRIBUTION↗

High-fidelity model-driven deception platform for cyber-physical systems

Methods are described for protecting a cyber-physical system against a potential attacker of the system. The methods include a method of generating a plurality of examples for a training data set and training a system model using the training data set to generate a decoy configured to generate a synthetic output that mimics historical outputs generated by the system for a given historical system context. Also described is a method including receiving a system context of a cyber-physical system; receiving an inquiry into the system by a potential attacker; applying a system model to the system context and the inquiry; obtaining from the system model a synthetic output that mimics how a component of the system would respond to the inquiry given the system context; and providing the synthetic output to the potential attacker.

Edgar, Thomas W.↗

NUMERICAL MODELING OF A SOLID OXIDE FUEL CELL FOR USE IN REAL-TIME SIMULATION AND CYBER-PHYSICAL SYSTEMS

Cyber-physical systems provide a mechanism with which to investigate the physical phenomena and behavior of traditionally cost-prohibitive or otherwise fragile equipment. For the National Energy Technology Laboratory (NETL), this approach resulted in the Hybrid Performance (Hyper) facility which features a gas turbine-SOFC hybrid cycle utilizing real turbomachinery and a simulated SOFC stack. This allows for the investigation of combined cycle performance and control strategies, in an exhaustive manner, both without fear of destroying delicate state-of-the-art fuel cells, and with the full accuracy of real-world turbomachinery. Issues arose between the transient response of the SOFC model being limited to a sample time of 80 milliseconds, due to the calculation time of the SOFC model taking on average 40 milliseconds to calculate for a given timestep with spikes in calculation time reaching the 80 millisecond threshold. In order to be able to match the speed of transients from the turbomachinery and likewise better discern transient behavior, it was determined that the SOFC model must be optimized to operate at a sample time of 5 milliseconds. Therefore, it is necessary to optimize the SOFC model in order to decrease the calculation time from around 40 milliseconds, down to at the most 5 milliseconds. To do this, both the electrochemical algorithm and the thermal algorithm used to simulate the physical behavior of the SOFC are investigated to determine where improvements can be made. To this end the rootfinding numerical recipes of the electrochemical algorithm are investigated as the complex electrochemistry requires a highly iterative nested dual convergence loop to resolve the voltage-current relationship, and likewise the temporal discretization of the thermal algorithm is modified for the sake of higher accuracy and stability. Ultimately the new electrochemical algorithm featuring higher order rootfinding schemes proves to be efficient enough to reach the sub 5 millisecond target, signifying an order of magnitude reduction in calculation time, and when coupled with the new temporal discretization similar calculation time characteristics show that a fully implicit, higher order temporal discretization can also successfully be used if desired. Ultimately this result means that the cyber-physical simulation system can operate at higher sample rates, and resolve transient events at significantly higher resolution and fidelity.

Arias, Jesus↗

Are Satellites Cyber Physical Systems?

Abstract— Cyber-physical systems (CPS) are a key part of modern infrastructure. However, satellites are often excluded from discussions of CPS, despite their evident cyber-physical attributes, such as the ability to respond to information from its surroundings and adjust accordingly. Through a brief examination of relevant literature, we prove that satellites are CPSs, specifically through payload-bus interactions that occur on a satellite. By establishing satellites as a form of CPS, we hope to encourage its inclusion in discussions for bettering the security of such systems.

Jones, Rachel C.↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Cyber-Physical Security and Resiliency Analysis Testbed for Critical Microgrids with IEEE 2030.5: Preprint

IEEE 2030.5, also known as the Common Smart Inverter Standard (CSIP) is a protocol that specifies the interface between the end user and the smart grid. This standard was proposed recently, and provides many functions which if implemented incorrectly might lead to vulnerabilities. This paper proposes a cyber-physical microgrid testbed using OpenDSS and IEEE 2030.5 that can be used to study the performance of the CSIP protocol various scenarios. For critical microgrid installations, it is essential that the critical loads are served in spite of multiple contingencies. A resiliency analysis is performed for a military microgrid to study its performance and the results are analyzed.

CVSS↗

Cross-Layered Cyber-Physical Power System State Estimation towards a Secure Grid Operation

In the Smart Grid paradigm, this critical infrastructure operation is increasingly exposed to cyber-threats due to the increased dependency on communication networks. An adversary can launch an attack on a power grid operation through False Data Injection into system measurements and/or through attacks on the communication network, such as flooding the communication channels with unnecessary data or intercepting messages. A cross-layered strategy that combines power grid data, communication grid monitoring and Machine Learning based processing is a promising solution for detecting cyberthreats. In this paper, an implementation of an integrated solution of a cross-layer framework is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection of anomalies in the operation of power grid. IEEE 118-bus system is built in Simulink to provide a power grid testing environment and communication network data is emulated using SimComponents. The performance of the framework is investigated under various FDI and communication attacks.

cyber security, network security, cyber-physical s↗

Hypergames and Cyber-Physical Security for Control Systems

The identification of the Stuxnet worm in 2010 provided a highly publicized example of a cyber attack that physically damaged an industrial control system. This raised public awareness about the possibility of similar attacks against other industrial targets—including critical infrastructure. Here, we use hypergames to analyze how strategic perturbations of sensor readings and calibrated parameters can be used to manipulate a system that employs optimal control. Hypergames form an extension of game theory that enables us to model strategic interactions where the players may have significantly different perceptions of the game(s) they are playing. Past work with hypergames has focused on relatively simple interactions consisting of a small set of discrete choices for each player. Here, we apply single-stage hypergames to larger systems with continuous variables. We find that manipulating constraints can be a more effective attacker strategy than manipulating objective function parameters. Moreover, the attacker need not change the underlying system to carry out a successful attack—it may be sufficient to deceive the defender controlling the system. It is possible to scale our approach up to even larger systems, but this will depend on the characteristics of the system in question, and we identify several characteristics that will make those systems amenable to hypergame analysis.

97 MATHEMATICS AND COMPUTING↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗