Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Consequence-based Targeting”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Towards Software Bill of Materials in the Nuclear Industry

Large, modern industrial facilities often incorporate thousands of digital assets in their operational technology. Regulated facilities, such as nuclear power plants (NPPs), maintain robust cybersecurity and configuration management programs that often use bills of materials (BOMs) for these assets, including make, model, and version of hardware, firmware, and software. However, these BOMs typically capture only first- or second-tier information provided by the original equipment manufacturer (OEM). Unfortunately, as indicated by the increasing number and sophistication of software supply chain attacks, this level of detail is insufficient for identifying all the potential vulnerabilities and risks in software applications. Software BOMs (SBOMs) provide detailed enumeration of components and dependencies within the product or devices, including firmware. SBOMs can be combined with vulnerability data sources and vendor vulnerability attestations to improve vulnerability management and enable rapid identification of affected components when new software vulnerabilities are discovered. Ideally, SBOMs are created by the OEM prior to installation. However, since this practice is not yet commonplace and since NPPs are typically slow to adopt new technology, most NPPs do not incorporate SBOMs into their asset or configuration management programs. Fortunately, SBOMs can be generated by NPPs on existing digital assets to provide further insight into risk management decisions. This report provides an overview of the current SBOM ecosystem and recommends guidance on how to get started in a “crawl, walk, run” manner to develop and implement a sustainable SBOM program for digital assets in an NPP.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Engineering-In Cybersecurity

Cyber-Informed Engineering is a framework which allows engineers to build resiliency to the impacts of cyber attack into engineered systems starting in the early design phases. This article introduces the framework and provides a description of some of its principles and resources for learning more.

42 ENGINEERING↗

Cyber-Informed Engineering for Nuclear Reactor Digital Instrumentation and Control

As nuclear reactors transition from analog to digital technology, the benefits of enhanced operational capabilities and improved efficiencies are potentially offset by cyber risks. Cyber-Informed Engineering (CIE) is an approach that can be used by engineers and staff to characterize and reduce new cyber risks in digital instrumentation and control systems. CIE provides guidance that can be applied throughout the entire systems engineering lifecycle, from conceptual design to decommissioning. In addition to outlining the use of CIE in nuclear reactor applications, this chapter provides a brief primer on nuclear reactor instrumentation and control and the associated cyber risks in existing light water reactors as well as the digital technology that will likely be used in future reactor designs and applications.

42 ENGINEERING↗

2021 Annual Report Laboratory Directed Research & Development

The Department of Energy’s (DOE) Laboratory Directed Research and Development (LDRD) program is an essential pathway for innovation, capability growth, and research staff development at Idaho National Laboratory (INL). This program enables timely and agile response to national security, energy, and environmental challenges that motivate INL’s mission to discover and demonstrate innovative nuclear energy solutions and other clean energy options as well as securing our critical infrastructure. This report highlights INL’s LDRD projects concluding in fiscal year (FY) 2021 which included innovative research and development (R&D) across INL’s five science and technology initiatives: nuclear reactor sustainment and expanded deployment, integrated fuel cycle solutions, integrated energy systems, advanced design and manufacturing for extreme environments, and secure and resilient cyber-physical systems.

99 GENERAL AND MISCELLANEOUS↗

Integrating Cybersecurity with System Operations and Restoration

This presentation covers the interaction of the discipline of system operations with the discipline of cybersecurity. First, a common mental model for risk - both cybersecurity and all-hazards - is presented, followed by a discussion of high-level management strategies for different kinds of cyber harm facing system operators, based on the consequences and frequencies of the harm. The next section covers the importance of cybersecurity for a system operator organization and explains some general concepts to understand the relationships. Finally the role of system operators in the security of the grid as a larger system of systems is discussed over the framework of a resilience event.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving American Leadership in Cybersecurity and Digital Components Factsheet

The Biden Administration’s efforts to meet 100% clean electricity by 2035 and net-zero greenhouse gas emissions by 2050 has created opportunities to rebuild American supply chains create new jobs, strengthen community engagement, and spur U.S. economic growth. DOE’s strategy for success in the transition to a clean energy economy hinges on building and maintaining technology supply chains that are advanced, secure, and resilient to cyber threats. As the energy sector grows increasingly globalized, complex, and digitized, the supply chain for digital components of energy systems – including software, virtual platforms and services, and data – is facing greater threats. Nearly all digital components of U.S. energy sector systems are vulnerable to cyber supply chain instability, stemming from a variety of causes and shared among a broad set of interdependent stakeholders. Overall, supply chain risks for digital components in energy sector systems will continue to evolve and likely increase as these systems are increasingly interconnected, digitized, and remotely operated.

CCE↗

INL FY 2021 Laboratory Overview

The INL FY 2021 Laboratory Overview is an opportunity for INL to share its achievements and plans for the future with the entire Laboratory, stakeholders, and the public. This document outlines how INL will advance its clean energy and national security objectives in the future and highlights FY 2020 accomplishments across the Laboratory in science and technology, community outreach, and operations.

07 ISOTOPE AND RADIATION SOURCES↗

Cyber-Resilient Design Methodology for Microgrids

Recent advancement in tools has helped with microgrid design, development, planning and operation. Microgrids offer a unique application based on users with different requirements for tools. The process of designing, constructing, commissioning, and assessing a microgrid is not always straightforward due to these distinct requirements. Additionally, metrics are needed for performance evaluation. This panel will offer an overview and description of tools that helps with microgrid design, construction, planning, operation, cyber security, and metrics-driven performance assessment driven by multiple diverse applications and use cases.

CCE↗

BioSecure Digital Twin: Manufacturing Innovation and Cybersecurity Resilience

U.S. national security, prosperity, economy, and well-being require secure, flexible, and resilient Biopharmaceutical Manufacturing. The COVID-19 pandemic reaffirmed that the biomedical production value-chain is vulnerable to disruption and has been under attack from sophisticated nation-state adversaries. Current cyber defenses are inadequate, and the integrity of critical production systems and processes are inherently vulnerable to cyber-attacks, human error, and supply chain disruptions. The following chapter explores how a BioSecure Digital Twin will improve U.S. manufacturing resilience and preparedness to respond to these hazards by significantly improving monitoring, integrity, security, and agility of our manufacturing infrastructure and systems. The BioSecure Digital Twin combines a scalable manufacturing framework with a robust platform for monitoring and control to increase U.S. biopharma manufacturing resilience. Then, the chapter discusses some of the inherent vulnerabilities and challenges at the nexus of health and advanced manufacturing. Next, the chapter highlights that as the Pandemic evolves, we need agility and resilience to overcome significant obstacles. This section highlights an innovative application of Cyber Informed Engineering to developing and deploying a BioSecure Digital Twin to improve the resilience and security of the biopharma industrial supply chain and production processes. Finally, the chapter concludes with a process framework to complement the Digital Twin platform, called the Biopharma (Observe, Orient, Decide, Act) OODA Loop Framework (BOLF), a four-step approach to decision-making outputs from the Digital Twin. The BOLF will help end users leverage twin technology by distilling the available information, focusing the data on context, and rapidly making the best decision while remaining cognizant of changes that can be made as more data becomes available.

99 GENERAL AND MISCELLANEOUS↗

Advancing Nuclear Energy to Support a Net-Zero Future

Seminar for the KEPCO International Nuclear Graduate School (KINGS) in South Korea. The presentation will cover a brief introduction to INL, opportunities for advanced nuclear, and integrated energy systems.

08 HYDROGEN↗

Cybersecurity concerns for the energy sector in the maritime domain

The world has seen a number of high-profile maritime disasters in recent months and years, and has felt the impact of them. At the same time, the world has also seen a number of high-profile cyberattacks. It has felt their impact, as well. And, likely no sector has been more affected by the maritime and cyber incidents than the energy sector, as fuel prices often spike or trough, and access to energy resources can become an instant source of concern, tension, or even conflict. As energy sectors—in all their forms—continue to rely on the maritime domain or even increase that reliance, they must be mindful that traditional maritime threats—like piracy, theft, and weather events—are not the only threats they face today. Maritime cybersecurity concerns are among the most potentially disruptive to energy-sector interests and, yet, are among the least understood and least addressed. This paper identifies nine areas in which the energy sector faces harmful cyber vulnerabilities in the maritime domain, to provide enough insight and examples to allow for action to be taken to reduce the risk of harm from these different vulnerabilities. The paper develops the example of offshore wind energy to model how to assess cyber considerations more fully. Ultimately, it concludes with a series of recommendations that offer policymakers, energy-sector actors, and security and law-enforcement professionals steps to minimize the exposure of the maritime energy sector to harmful cyberattacks.

99 GENERAL AND MISCELLANEOUS↗

Cyber-Informed Engineering

Briefings provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.

42 ENGINEERING↗

Applying Cyber-Informed Engineering to Power System Operations

This presentation covers the interaction of the discipline of system operations with the growing body of knowledge around Cyber-Informed Engineering (CIE). First is discussion of a number of fundamental concepts for system operators - organizational division of responsibilities, human and machine cooperation, goals, and priorities. The next section covers the reasons why CIE was developed, what it is, and the key design and operational, and organizational principles of CIE. Finally, some thoughts on how CIE can be applied to power system operations are offered, along with some examples of how an organization can approach applying CIE principles in their particular circumstances.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A National Secure-by-Design Strategy

The US National Cybersecurity Strategy published March 2, 2023 uses plain language to communicate that the US is calling for a major change in how we prioritize the security of software systems used in critical infrastructure. It acknowledges that our current approach, which is essentially, “let the buyer beware,” leaves entities who are least able to assess or defend vulnerable software responsible for the impacts of designed-in weaknesses while the makers of the technology bear no liability. The strategy recommends a security-by-design approach, recommending that software vendors be held liable to uphold a “duty of care” to consumers and for systems to be designed to “fail safely and recover quickly” . For energy infrastructure, the strategy calls out the need to implement the National Cyber-Informed Engineering Strategy to achieve higher confidence security for energy infrastructures. The Idaho National Laboratory, a pioneer in cyber-informed engineering concepts, is at the forefront of organizations educating others in industry, academia, and government on how to apply these concepts to real-world challenges. In this brief, we'll outline some of the basic principles of security-by-design and offer examples of how, in a water sector context, they're being put into successful practice.

42 ENGINEERING↗