Engineering PapersSearch

SEARCH · Engineering Papers

Results for “OT security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

35 records · Page 2

Scan2Sim: Software to Convert Network Scans to Emulations

Within operational technology (OT) systems design, the construction of testing environments for simulation is often a tedious, manual process that slows down safety and security evaluations. This document details the design and functionality of Scan2Sim, a program designed to construct high-fidelity topological schematics for OT systems without significant manual human input. Scan2Sim may take as input a detailed network scan of a system, and produces an instruction set to re-create the original scanned network within a virtualized simulation network. This construction is achieved via heuristic methods of machine template selection, which allows for a fast, performant approach to automated environment construction. The current tool is designed to produce topology schematics compatible with the Minimega, a tool designed by Sandia National Laboratories for repeatable experimentation management.

97 MATHEMATICS AND COMPUTING

Clean Energy Cybersecurity Accelerator: Cohort 2 - runZero Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator™ (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION

Clean Energy Cybersecurity Accelerator: Cohort 2 - Asimily Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator (TM) (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION

Engineering Out Industry 4.0 Cyber Risk Presentation for EnCyCriS

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

99 GENERAL AND MISCELLANEOUS

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING

Secure and Resilient Operations Using Open-Source Distributed Systems Platform (OpenDSP)

The goal of this project is to identify and address cybersecurity gaps by developing a multi-layer multi-channel cyber-physical defense and survival mechanism for operating distribution networks with high penetration of solar / inverter-based resource (IBR) / distributed energy resource (DER). The proposed security enhancements are built upon the distributed framework and solution architecture for both information technology (IT) and operational technology (OT) systems. The technical solutions consist of two composite functionalities and six layers: proactive defense (vulnerability assessment, communication protection, and attack detection, as layers 1-3), and adaptive self-healing (attack-resilient control, adaptive recovery, and resilient survival, as layers 4-6). These layers, built on and extended from DHS CISA Cyber Framework, establish an integrated and robust cybersecurity framework for operating large-scale distribution networks.

14 SOLAR ENERGY

Cyber-Physical Tabletop Exercise for Small Modular Reactor Facilities

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. This evolving threat landscape includes adversaries having offensive cyber capabilities to attack information technology (IT) systems and operation technology (OT) systems. These adversaries may have the ability to attack the physical protection system (PPS) networks with potential consequential impacts that could degrade the effectiveness of the PPS. These cyber attacks may also be used to attack the safety and operational systems used to operate and ensure the safety of the reactor. Additionally, adversaries may gain access to unmanned aerial systems (UAS) that may be used to provide reconnaissance and surveillance of the facility, provide information to the adversaries, and be equipped with kinetic capabilities such as explosives or weapons that can be used to directly attack the facility. The Department of Energy’s Office of Nuclear Energy’s Advanced Reactor Safeguards and Security (ARSS) program funded Sandia National Laboratories (SNL) and Idaho National Laboratory (INL) to develop a cyber-physical tabletop exercise (TTX). This exercise was conducted on a hypothetical small modular reactor (SMR) facility, and only considered a potential adversary cyber attack on the PPS to a physical attack on the hypothetical facility to achieve a radiological release. This cyber-physical TTX is meant to provide lessons learned to integrate the cyber security system design and the physical protection system (PPS) design to decrease design, operation, and maintenance costs as well as increase effectiveness for defending against design basis threat attacks at the facility. This TTX will also provide a framework and method for SMR and microreactor vendors to conduct their own cyber-physical TTX and gain impactful insights to improving the cyber and physical protection system design for their SMR or microreactor facility design.

42 ENGINEERING

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION

Cybersecurity for the Operational Technology Environment (CyOTE)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop CyOTE. This research initiative addresses cybersecurity threats against operational technology (OT) networks by sharing intelligence about adversarial tactics and techniques with the energy sector. CyOTE improves the sector’s ability to detect anomalous behavior that indicates potential malicious cyber activity in OT networks.

99 GENERAL AND MISCELLANEOUS

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING

Malcolm Deployment Guide for Solar Power Generation Plants

This guide provides detailed instructions for deploying Malcolm in Solar Power Generation systems. It covers the deployment process, from understanding the network architecture of these systems to configuring network switches and Switched Port Analyzer (SPAN) ports or mirror ports or TAPs. The guide also includes best practices for deploying Hedgehog sensors, another critical component in these systems. Following this guide, users can enhance network visibility, improve their system’s security, and effectively troubleshoot common issues.

14 SOLAR ENERGY

Cybersecurity Considerations for the Liquified Natural Gas Sector

Due to the highly volatile nature of Liquified Natural Gas (LNG) and the systems required for generation and safe containment, it is likely a targeted cyber-attack on LNG control and safety systems will have a significant economic impact on energy supplies and prices. Moreover, if the interconnected operational technology (OT) devices within LNG systems are exploited to malfunction, the repair and recertification process will almost certainly be longer than for natural gas (NG) systems.

03 NATURAL GAS

OT Defender Presentation - Hacker Mindset

Presentation on hacker mindset and what utilities may be up against from lone hackers or professional groups, with ideas on how to improve defensive posture.

99 - GENERAL AND MISCELLANEOUS

Soil and groundwater environmental sensor data, Wax Lake Delta, Louisiana, March 2023 - March 2024

This study evaluates how environmental parameters that integrate biogeochemical processes vary with water table fluctuations in the freshwater Wax Lake Delta (WLD) in Louisiana, U.S.A. This data package contains seven *.csv files and one Excel file that compiles all the data from the individual .csv files. This dataset reports high frequency (15-min) observations of water level, soil redox potential, specific conductance, and pH made for one year along elevation transects located on the older, proximal (OT) and younger, distal (YT) ends of a deltaic island. Water depth relative to the ground surface (cm; HOBO U20L-04; error ± 0.4 cm), water pH and temperature (HOBO MX2501), and specific conductance and temperature (HOBO U24-001) sensors were installed in March 2023. Water depth was corrected for barometric pressure recorded by a separate logger secured to a platform above the highest water level. Soil redox probes (SWAP ORP-40-4-B) were also installed in March 2023. Each probe had four Pt sensors (2 mm width) placed at 10 cm, 20 cm, 30 cm, and 40 cm below the ground surface. Redox data were referenced to an external Ag0/AgCl (3M KCl) reference probe placed in saturated ground and recorded on CR1000X dataloggers (Campbell Scientific) powered by solar panels. A second reference probe was positioned near the primary reference probe for backup and data correction. The tops of the soil redox probes and soil moisture probes were flush with the soil surface so that sensors are reported at their indicated depths below ground surface. Here, we report data collected between 15 March 2023 to 15 March 2024 for all sensors, with some differences due to exact dates of sensor placement or data gaps associated with sensor malfunction. For example, water depth at OT4 was not recorded between March to November 2023. Data flags indicate whether a value is valid (1) or was excluded from data analysis in the associated manuscript (-1).

EARTH SCIENCE > LAND SURFACE > SOILS

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY

Integrity Enhancing Protocols: Performance and Recommendations for Nuclear Systems

In today’s communication landscape there are multiple technologies and protocols used for communication between end devices. Within security paradigms for these protocols, integrity management is a common goal of system designers. Communication protocols focused on maintaining message integrity can provide assurance that some received data has not been altered or tampered with. While integrity is often coupled with confidentiality in protocol design, this analysis focuses on an evaluation of only integrity protocols. This report outlines various ways message integrity may be preserved with respect to high performance operational technology (OT) systems. It describes a series of experiments and an evaluation framework used to evaluate the performance of the identified integrity approaches regarding common system design goals. Finally, it addresses the testing environment utilized and closes the report with a summary of experimental results.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS