Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Secure Command Line Solution for Token-based Authentication

The WLCG is modernizing its security infrastructure, replacing X.509 client authentication with the newer industry standard of JSON Web Tokens (JWTs) obtained through the Open ID Connect (OIDC) protocol. There is a wide variety of software available using the standards, but most of it is for Web browser-based applications and doesn’t adapt well to the command line-based software used heavily in High Throughput Computing (HTC). OIDC command line client software did exist, but it did not meet our requirements for security and convenience. This paper discusses a command line solution we have made based on the popular existing secrets management software from Hashicorp called vault. We made a package called htvault-config to easily configure a vault service and another called htgettoken to be the vault client. In addition, we have integrated use of the tools into the HTCondor workload management system, although they also work well independent of HTCondor. All of the software is open source, under active development, and ready for use.

Dykstra, Dave↗

A technique to make an enterprise network a Darknet on the Internet, while providing required services to authorized users

In a well-designed and secure enterprise network, the hosts inside the network are not directly accessible from the Internet. The enterprise firewall blocks direct access to hosts inside the enterprise network and also blocks any attempts to probe or discover information about those hosts from the Internet. However, access to the enterprise network from the Internet is a must in today’s day and age. Hence, specialized mechanisms to allow secure access are implemented.

97 MATHEMATICS AND COMPUTING↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Abstracted, Modular, Ephemeral Autonomic Computing Systems Codified

The purpose of this report is to share work based on material originally described in a Sandia LDRD proposal for 2016 as well as an invention submission SD 14734 ( DOE # 150281) –“Abstracted, Modular, Ephemeral Autonomic Computing System(s) Codified” from April 2018. This work was done at Sandia National Laboratories, a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525

97 MATHEMATICS AND COMPUTING↗

INTEGRATION OF FLEX EQUIPMENT AND OPERATOR ACTIONS IN PLANT FORCE-ON-FORCE MODELS WITH DYNAMIC RISK ASSESSMENT

The overall operation and maintenance cost to protect nuclear power plants accounts for approximately 7% of the total cost of power generation, with labor accounting for half of this cost. In the current research, from interaction with utilities and other stakeholders, it was determined that physical security forces account for nearly 20% of the entire workforce at several nuclear power plants. Labor costs continue to rise in the U.S., so any measures to reduce the cost of operating a nuclear power plant will need to include a reduction in labor. The physical security pathway within the DOE’s Light Water Reactor Sustainability program aims to lower the cost of physical security through directed research into modeling and simulation, application of advanced sensors or deployment of advanced weapons. This report presents a modeling and simulation framework for integrating Diverse and Flexible Mitigation Capability (FLEX) portable equipment performance with Force on Force models of a plant’s physical security posture. The generic framework is described in detail, followed by a case study of modeling an adversarial attack aimed at causing a radiological release by sabotaging the plant’s power supply and its ultimate heat sink capabilities at a hypothetical nuclear power plant. Two different FLEX deployment strategies, series and parallel, are modeled with distinct timelines. The results of the adversarial attack modeled in a commercial Force on Force tool are integrated with the FLEX deployment model in INL’s dynamic modeling tool EMRALD. Monte Carlo simulation is used to model the distribution of the timeline in FLEX deployment strategies. The results demonstrate that, even in the extreme case of a successful adversarial attack, deployment of FLEX equipment can result in a significantly high likelihood of preventing radiological release. The modeling and simulation framework integrating FLEX equipment with Force on Force models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security.

97 MATHEMATICS AND COMPUTING↗

Cyber Threat Assessment Methodology for Autonomous and Remote Operations for Advanced Reactors (Conference Presentation)

The next generation of Advanced Reactors include planned capabilities for both Autonomous (operating without human interaction for a set period-of-time) and Remote (operating with human interaction from a separate physical location) Operations. Existing Nuclear Reactor architectures include a set of safety and security constraints tightly coupled with personnel policies and procedures. As Advanced Reactors are fielded with these new Autonomous and Remote operational capabilities, the architectures and associated infrastructure services and components will perceivably expand the overall attack surface and risk calculations with regards to safe and secure operations. This paper is part of an FY21 work program focused on ensuring Advanced Reactor designs are informed with threat-based guidance on design and operation of Secure Architectures with a specific focus on the deployment of Autonomous Systems in support of Advanced Reactor Operations. The next phase of this research program is to complement produce a methodology for assessment of the cyber threat against these architectures as well as a catalogue of Use Cases to support the Advanced Reactor community in their implementation of Autonomous and Remote Operations.

97 MATHEMATICS AND COMPUTING↗

Methodology and Tool for the Physical Security Analysis of Micro and Advanced Reactors

This work proposes a dynamic evaluation methodology to relax the conservatism in physical security evaluation, by leveraging an ongoing work in the Light Water Reactor Sustainability pathway. This methodology is implemented in a dynamic risk assessment tool named Event Modeling Risk Assessment using Linked Diagrams (EMRALD). The work extends EMRALD’s capability to support a sandbox feature where analysts can easily create attack scenarios and modify advanced/small modular reactor (A/SMR) security and safety features using templates. This approach saves time and cost since the analysis does not require creating detailed computer-aided design models, as is commonly required in commercial force-on-force software tools. EMRALD is completely free to use at https://emraldapp.inl.gov. We have developed basic templates including physical barriers, intrusion sensors, physical areas, and safety actions, that can be downloaded from EMRALD’s GitHub site: https://github.com/idaholab/EMRALD. These templates use generic data commonly used for training purposes, which do not reflect any actual operating nuclear reactor. Users may adjust the data in the templates with their own dataset and/or create new templates in EMRALD. The proposed methodology combines security and safety by assessing sabotage effects up to the radiological consequence to the public instead of merely the core damage state. This practice follows the industry standard for advanced non-light-water reactors currently proposed for endorsement by the Nuclear Regulatory Commission. The combination of security and safety is expressed in an achievability-consequence chart. EMRALD can be used to generate data for this chart. A hypothetical case study using a representative sodium-cooled fast reactor (SFR) facility is presented in this report to demonstrate this methodology. This case study does not contain any actual nuclear plant information. This work will benefit A/SMR vendors and utilities to implement security by design during the reactor design iteration phase, such that they do not have to perform upgrades and retrofits to the reactor after it is installed to improve its physical protection system. The tool may also be used to analyze domestic or foreign reactor designs to support the International Nuclear Security Techniques for Advanced Reactors (INSTAR) bilateral missions. Future works are planned to implement the methodology on a reference SFR reactor and a reference high-temperature gas-cooled reactor to obtain insights and lessons-learned for the A/SMR community.

97 MATHEMATICS AND COMPUTING↗

Securing Smart Manufacturing: Detection of Cyber-Physical Attacks in CNC-Based Systems

As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.

Williams, Bethanie [Tennessee Technological Univer↗

Regression Analysis with the Directed Infusion of Data

Integrating artificial intelligence and machine learning tools into industry necessitates large-scale collaborative efforts that ensure the robust and accurate execution of downstream analytics such as time series prediction, uncertainty quantification, grid optimization, and condition monitoring. However, concerns related to data privacy pervade the nuclear industry due to the proprietary nature of its data and the possibility of data leakage. Legacy techniques such as encryption often require the explicit transmission of data to trustworthy parties, thereby inviting data leakage concerns. The ideal collaboration scenario avoids the explicit dissemination of data/code while maintaining experimental fidelity, which is currently accomplished using various techniques such as trusted execution environments, homomorphic encryption, differential privacy, and multimatrix masking. These techniques, however, often necessitate a trade-off between trust, efficiency, and utility. This article extends a previously proposed technique called the directed infusion of data (DIOD) that ensures data privacy, allows for scalable obfuscation, and combats the risk of data leakage without compromising utility. The experiments discussed in this article examine a regression-type scenario using DIOD with the goal of preserving the inferential link between two variables. Using the point-kinetics equations, regression experiments compare the performance of a model trained using the original data to that of a model trained using the obfuscated data, which produced identical results. Our claim is further strengthened by an information theoretic proof and experiment, which showed that the inferential content between variables remains the same after obfuscation, thereby avoiding the required communication of the proprietary data.

47 - OTHER INSTRUMENTATION↗

Measurement and applications: Exploring the challenges and opportunities of hierarchical federated learning in sensor applications

Sensor applications have become ubiquitous in modern society as the digital age continues to advance. AI-based techniques (e.g., machine learning) are effective at extracting actionable information from large amounts of data. An example would be an automated water irrigation system that uses AI-based techniques on soil quality data to decide how to best distribute water. However, these AI-based techniques are costly in terms of hardware resources, and Internet-of-Things (IoT) sensors are resource-constrained with respect to processing power, energy, and storage capacity. These limitations can compromise the security, performance, and reliability of sensor-driven applications. To address these concerns, cloud computing services can be used by sensor applications for data storage and processing. Unfortunately, cloud-based sensor applications that require real-time processing, such as medical applications (e.g., fall detection and stroke prediction), are vulnerable to issues such as network latency due to the sparse and unreliable networks between the sensor nodes and the cloud server [1]. As users approach the edge of the communications network, latency issues become more severe and frequent. A promising alternative is edge computing, which provides cloud-like capabilities at the edge of the network by pushing storage and processing capabilities from centralized nodes to edge devices that are closer to where the data are gathered, resulting in reduced network delays [2], [3].

Po-Leen Ooi, Melanie↗

The GABLE Report: Garbled Autonomous Bots Leveraging Ethereum

Simple but mission-critical internet-based applications that require extremely high reliability and availability could potentially benefit from running on robust public programmable blockchain platforms such as Ethereum. Unfortunately, program code running on such blockchains is ordinarily publicly viewable, rendering these platforms unsuitable for applications requiring strict privacy of application code, data, and results. However, might it be possible to encode an application's business logic and data for these platforms in such a way that it becomes impossible for unauthorized parties to infer any meaningful information whatsoever about the semantics of the data, and the operations being performed on that data? In this report, we describe GABLE (Garbled Autonomous Bots Leveraging Ethereum), a system concept developed at Sandia that achieves this security goal in a limited, but still useful range of circumstances. GABLE, uses simple but effective algorithms to permit secure private execution of garbled state machines (and more efficient garbled circuits) on public computing resources. We give an example working implementation for garbled state machines, written using the Python and Solidity programming languages, and outline how our methods can be extended to support a more powerful garbled universal circuit model of computation. The capability embodied by the GABLE, system has significant potential applications, a few of which we discuss in this report.

97 MATHEMATICS AND COMPUTING↗

20 years of the CEA/DAM NNSA/DP Agreement

For the past twenty years, there has been a very active, productive International Agreement between France and the United States of America for Cooperation on Fundamental Science supporting Stockpile Stewardship. Under this Agreement the scientists at the nuclear weapons laboratories in both countries have collaborated on many unclassified research projects in areas such as Materials in Extreme Conditions, Nuclear Physics, and Atomic and Plasma Physics. The results of their efforts have not only been published in the open literature but have enhanced the physics base of the computer codes essential to the mission of ensuring that the nuclear stockpiles are safe, secure and effective. Work on these collaborations is extremely important. Not only does such joint work bring more brilliant minds to work on pressing research problems for both countries but also the collaborative effort sharpens the scientific skills of and presents scientific challenges to the scientific and technical staff of the laboratories. As we reach the 20th Anniversary of the formal signing of the Agreement, we feel it is important to thank all of the individuals who have contributed to its continuing success. Our expectations for brilliant, exciting, challenging joint research projects under this Agreement are at an all-time high. We toast the achievement of this milestone and look forward to the research results to come.

36 MATERIALS SCIENCE↗

End-to-end Analytics for Grid Arch Design & All-hazard Assessment

Resiliency, reliability, and security of the next-generation smart grid depend upon leveraging advanced communication and computing technologies, integrating them with physical power systems, and developing real-time, fast, data-based applications to help in wide-area monitoring and control of the grid. Using a high sampling data rate from phasor measurement units (PMUs) to develop applications has opened the door to achieving the next-generation grid requirements. The North American Synchrophasor Initiative Network (NASPlnet) was developed in 2007-09 to create a standard and guide for PMU data exchanges. With the advancement in both networking and grid requirements, it is necessary to evaluate the performance of different NASPInet versions and their impact on applications. Therefore, we need a cyber-power cosimulation framework that supports very large-scale co-simulation capable of running in parallel, high-performance computing platforms and capturing real-life network behavior. This work presents a cyber-physical co-simulation testbed using NS3 to model the communication network, GridPACK to model the power grid, and HELICS as a co-simulation engine. Comparative analysis of latency in synchrophasor networks and a performance evaluation of a power system stabilizer application based on PMU data in an Institute of Electrical and Electronics Engineers 39-bus test system is presented using this co-simulation testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Use Case-Informed Framework for Utility Cloud Migration

This white paper presents a comprehensive methodology for assessing utilities’ cloud postures and frameworks. It aims to produce a roadmap and strategy for a cloud-enabled grid future, providing guidance for integrators, asset owners, and operators. Instead of offering a yes or no answer for cloud implementation, this framework offers strategic guidance on responsibly preparing for and deploying cloud solutions. This paper delves into cloud-service models pertinent to the electric sector, dissecting the shared responsibility model and elucidating what on-premise infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS) entail. A pivotal consideration within the context of the shared responsibility model is the allocation of responsibility for foundational security aspects—a decision that will be informed by a comprehensive risk assessment. The ensuing discussion will present a checklist of certifications necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and with a strategic roadmap. Furthermore, the paper outlines gaps in understanding the U.S. government’s role in shaping technology development and responsible use. Its purpose is to aid decision-making by offering support for risk-informed solutions that benefit those managing assets and operating in the cloud environment. The primary objective is to enhance the resilience and future readiness of a decarbonized electric grid, with cloud solutions as one viable option. The paper synthesizes information on current and future grid architectures and applications, considering both conservative and progressive energy transitions, along with scalable and distributed computing considerations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Methodology and Application of Physical Security Effectiveness Based on Dynamic Force-on-Force Modeling

This report describes the research and development being performed at INL towards a dynamic modeling and simulation framework to enable physical security optimization at commercial nuclear power plants. The framework is based on the dynamic modeling tool EMRALD and is demonstrated for applications that can result in physical security optimization. Two main applications are presented: 1. Integrating FLEX portable equipment performance with FOF models of a plant’s physical security posture, and 2. Location optimization of bullet resistant enclosure. The generic framework for modeling FLEX portable equipment is described in detail, followed by a case study modeling an adversarial attack aimed at causing a radiological release by sabotaging the plant’s power supply and its ultimate heat sink capabilities at a hypothetical PWR. Two distinct FLEX deployment strategies, series and parallel, are modeled with distinct timelines. The results of the adversarial attack modeled in a commercial FOF tool, AVERT, are integrated with the FLEX deployment model in EMRALD. Monte Carlo simulation is used to model the distribution of the timeline in FLEX deployment strategies. Thermal-hydraulic analysis of FLEX performance is performed in RELAP5 and integrated with the EMRALD simulations to provide more realistic timelines in the models. The results demonstrate that, even in the extreme case of a successful adversarial attack, deployment of FLEX equipment can result in a significantly high likelihood of preventing radiological release. The modeling and simulation framework of integrating FLEX equipment with FOF models enables the NPPs to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security. The objective of location optimization of BRE is to determine the best location in the plant for a new BRE being planned by the plant to enhance their physical security effectiveness. The plant physical security FOF model is integrated with EMRALD that performs Monte Carlo simulation to run different attack scenarios and a discrete set of potential BRE locations. Sensitivity analysis is used to determine the most effective location for the BRE. The optimization approach can be extended to wide applications such as location optimization of remotely operated weapons and other strategic fixed assets.

97 MATHEMATICS AND COMPUTING↗

Baylor University Campus-Wide Deep Dive

In January 2020, staff members from the Engagement and Performance Operations Center (EPOC) and the Lonestar Education And Research Network (LEARN) met with researchers and staff at Baylor University for the purpose of a Campus-Wide Deep Dive into research drivers. The goal of this meeting was to help characterize the requirements for five campus research use cases and to enable cyberinfrastructure support staff to better understand the needs of the researchers they support. Profiled scientific use cases included: - Experimental High Energy Physics (HEP) - Proton Computed Tomography (pCT) - Nutrition and Relation to Digestive Microbiome - Baylor University Core Research Facilities - Molecular Quantum-dot Cellular Automata (QCA), and Material Science of Quantum Computing - Modeling and Simulation of Low-Dimensional and Nano-Structured Materials - Computational Fluid Dynamics Material for this event included the written documentation from each of the research areas at Baylor University, documentation about the current state of technology support, and a write-up of the discussion that took place in person. The Case Studies highlighted the ongoing challenges that Baylor University has in supporting a cross-section of established and emerging research use cases. Each Case Study mentioned unique challenges which were summarized into common needs. These included: - Tradeoffs for network/software security, and usability of the resulting infrastructure. Better communication to set expectations and understand realities is required. - Computation use on campus is widespread and healthy. While no major problems were uncovered, upgrades to maintain current usage patterns and encourage growth will be required. - Storage is a critical need for enterprise use cases and research. In particular, a campus wide ‘storage architecture’ to support research use cases (e.g. instruments, data sharing) is required in the 2-5 year time window. - Instrumentation on campus is healthy and expanding. Technology must scale with this in the form of computation and storage. - Working with LEARN to upgrade network capacity (in multiples of 10G, or upgrades to 100G) will be required in the 1-3 year time frame. - Network monitoring and visibility will help to establish external science use cases. - Data sharing via portal systems is not currently a critical need, but growing in scope. EPOC can assist Baylor with options.

99 GENERAL AND MISCELLANEOUS↗

Algorithms to Improve Training for Deep Learning with Diabetic Retinopathy Images

This is a minisymposium presentation I plan to give at the SIAM conference on Computational Science and Engineering on March 1st, 2021. The work is based on research from my SDRD this year and describes a new pooling method we've developed called variable stride. The goal of the minisymposium is to highlight some of the ground-breaking work being done across the National Nuclear Security Administration by graduate students and Postdocs.

97 MATHEMATICS AND COMPUTING↗