Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Operational Technology”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3

Vedizar Fingerprinter

SAND2025-03289O Vedizar Fingerprinter simplifies the process of identifying devices on a network by analyzing traffic data. It uses a unique library to recognize different devices, making it easier for users to understand what is happening on their networks. This software is ideal for IT and operational technology environments, helping organizations monitor their networks effectively. By saving results in a database, it allows for easy access and review of device information. Users can enhance their network security and optimize performance without needing specialized hardware or technical expertise. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jacobellis, John [Sandia National Lab. (SNL-CA), L

Materials for Energy Management across the Electromagnetic Spectrum (MEMES) (LDRD Report)

Electrification of the United States has been a major driver of economic growth, powering industrialization, modern manufacturing, and the digital economy. Today, further economic and environmental benefits can be realized by improving the energy efficiency of the technologies we have come to rely on. This project focused on enhancing the energy efficiency of two cornerstone technologies of modern society: electronic displays and building climatization. While these two technologies operate in different parts of the electromagnetic spectrum (the visible and infrared, respectively), they share a common potential technological solution: electrically-driven displays that change reflectivity. In this work, we developed the first multipixel multicolor reflective display that achieves multi-colorization with fast-changing structural color. In the course of this demonstration, we quantified the structural changes that occur across different time and length scales and resolved device sealing issues, enabling operation of these devices over months (as opposed to days previously). We furthermore developed two reflectivity changing devices in the infrared and demonstrated how these technologies can be used to reduce climatization demands for both smart window and smart wall technologies. Implementing such a device in a scaled down mock room resulted in 10 degree Celsius change.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI

Piezoelectrically actuated silicon-nitride-based high-speed spatial light modulator

Advancements in light modulator technology have been driving discoveries and progress across various fields. The problem of large-scale coherent optical control of atomic quantum systems—including cold atoms, ions, and solid-state color centers—presents among the most stringent requirements. This motivates a new generation of high-speed large-scale modulator technology operating in the visible to near-infrared wavelength range. We introduce a scalable modulator technology based on piezoelectrically actuated silicon nitride resonant waveguide gratings fabricated on 200 mm diameter silicon wafers with CMOS-compatible processes. We present a proof-of-concept device with 4 × 4 individually addressable 50 μ m × 50 μ m pixels or channels, each containing a resonant waveguide grating with a ~ 780 nm design wavelength, supporting > 100 MHz modulation speeds, and a spectral response with > 20 dB extinction.

integrated optics

Precursor Analysis Report: Blackmatter Ransomware Attack on New Cooperative 2021

The BlackMatter Ransomware Attack on New Cooperative 2021 Precursor Analysis Report leverages publicly available information about the New Cooperative cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The BlackMatter ransomware was first identified in July 2021 and is reported to have infected more than 50 corporations around the world. , The Iowa-based grain cooperative, New Cooperative, was impacted by the BlackMatter ransomware on or before 18 September 2021. The adversary likely resided on New Cooperative’s networks for 15 days prior to encrypting its network and demanding New Cooperative pay $5.9 million in ransom by 25 September to unlock systems and prevent 1 terabyte (TB) of sensitive data from being publicly released. It is not clear if New Cooperative paid the ransom. The full impact of the ransomware attack is not known; however, according to New Cooperative’s general manager, the attack caused the company’s automated processes to revert back to processes used in the 1970s. , As of 6 October, only 50 percent of New Cooperative’s operations were utilizing automated processes. The company took eight weeks to rebuild the entire network and information technology (IT) systems from the ground up, which puts the date of fully recovery around 13 November. Researchers and analysts identified 20 unique techniques utilized during the attack with a total of 404 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Seventeen of the identified techniques used during the New Cooperative cyber attack were precursors to the triggering event. Analysis identified 360 observables associated with these precursor techniques, 284 of which were assessed to have an increased likelihood of being perceived in the 15 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Accelerating technology development to monitor and minimize effects from land‐based wind energy on birds and bats

While wind energy is a key sector of domestic energy production for the United States, operation of wind turbines directly and indirectly adversely affects certain species of birds and bats. The cumulative effect of wind turbine strikes can have both biological and regulatory consequences, and, in some cases, delay permitting and construction or affect ongoing operations. Technology can help quantify and minimize these effects, but the pace of development, acceptance, and adoption of technological solutions is slow. Although adopting cost‐effective technologies may reduce negative effects on wildlife and help achieve both energy production and conservation goals, consensus is lacking among developers, regulators, and the conservation community regarding how to define technology effectiveness and acceptance and how to develop a standardized process for doing so. Removing barriers to technology advancement requires deviating from the status quo. Changes include 1) creating incentives to mitigate impacts, 2) establishing options for research as mitigation, 3) rethinking how research is funded, 4) increasing stakeholder coordination, and 5) increasing the efficiency of research and development. We recommend the creation of a national framework to establish clear criteria and protocols for technology evaluation and adoption.

17 WIND ENERGY

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Security of DERs and Grid Edge Technologies [Slides]

Distributed energy resources (DERs) offer significant value for incorporating diverse generation technologies and improving reliability. They also present a new set of cybersecurity challenges. The move of generation to the grid edge can also mean more distributed control systems and expanded communication networks, resulting in an increase in attack surface. This presentation will discuss definitions and essential terms related to DERs; developments and deployment trends for DERs; recent cyber attacks on operational technology and industrial systems; cyber risk arising from distributed grid resources; and ways in which standards may help mitigate some of these risks.

24 POWER TRANSMISSION AND DISTRIBUTION

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE

Influence of Ordered Mesoporous Oxides in Plasma-Assisted Ammonia Synthesis

Widespread implementation of dielectric barrier discharge (DBD)-assisted NH 3 synthesis, a nascent technology operating under sustainable, ambient conditions, is hindered by low energy yields due to, in part, poor fundamental understanding. Porous oxides used to support metal nanoparticle catalysts have shown significant energy yield contributions for DBD-assisted NH 3 synthesis even without metal. Using an AC-powered, coaxial, single-stage reactor at 16 kV with equimolar (N 2 /H 2 ) feed, we measured NH 3 synthesis rates in the presence of different nonordered oxides, ordered SiO 2 structures (SBA-15 and MCM-41), and ordered Al-incorporated analogues (γ-Al 2 O 3 -coated with varying Al-loadings and Al-substitution, respectively: Al 2 O 3 -SBA-15 and Al-MCM-41). We systematically quantified NH 3 energy yield dependence on pore structures and material identities (i.e., ordered pores and Al incorporation) known to facilitate higher DBD-assisted NH 3 synthesis rates. SBA-15 displayed a higher steady-state energy yield than MCM-41, indicating that framework type is a crucial factor, with both ordered porous systems outperforming fumed SiO 2 . 10 wt % Al maximized in situ NH 3 uptake among the various Al loadings, exhibiting a higher steady-state energy yield and similar power to SBA-15. However, Al-MCM-41 had a similar steady-state energy yield and lower power than MCM-41, likely due to the extended γ-Al 2 O 3 surface that has a dielectric constant higher than that of SiO 2 . Both Al-incorporated analogues benefit from surface acid sites that can adsorb NH 3 in situ, resulting in higher overall NH 3 energy yields than that of their parent ordered SiO 2 . Al 2 O 3 -SBA-15 shielded more NH 3 than Al-MCM-41, likely due to a higher acid site density than the acid site identity. Furthermore, Al incorporation via γ-Al 2 O 3 coating more successfully improves the NH 3 energy yield; together with the high-performing ordered framework, these analogues are potential metal catalyst supports with promising energy yields for DBD-assisted synthesis of NH 3 and other chemicals.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN

Cyote Insights

CyOTE Insights leverages React, Vite, Typescript, Tailwind, and Daisy UI for the Graphical User Interface. It was designed in a particular style with a dark mode and a light mode. All code is broken down into components and reusable wrapper components for efficiency. All data is stored in Deep Lynx as a central data repository using an ontology based schema. The application serves as a main endpoint for the data in the COREII and CyOTE programs. The main purpose of the application is to display historical attack data in the Operational Technology space. At the time of this writing, it supports 27 historical attack reports compiled from OSINT sources. All of the data is publicly available, but what this application offers is the ability to see many years worth of publications in a detailed dashboard. It will also support future reports that are written using the other applications in the COREII program.

Pluth, AdamJ [Idaho National Laboratory (INL), Ida

Secure NTP Implementation for Power System Synchronization

Network Time Protocol (NTP), originally developed in the 1980s, remains one of the most widely adopted protocols for synchronizing clocks over Internet Protocol (IP)-based networks. It distributes time with millisecond-level accuracy across Ethernet-based systems and continues to be a standard in both enterprise and operational technology environments.

97 MATHEMATICS AND COMPUTING

Reduction of Porosity in Cementitious Waste Forms to Reduce Effective Diffusivity

Although current practices meet regulations for grout waste forms, development of sequestration materials and techniques for contaminants of concern could expand the use of grout waste forms and reduce risk to established processes from future compositional changes. There are contaminants in waste streams that are not permanently and completely sequestered in current grout waste forms under certain conditions. These contaminants include methyl mercury, 129 I, 99 Tc, and nitrate. Each of these species have minor fractions that are not permanently and completely isolated from the environment and therefore potentially contribute to long-term environmental impacts. An approach of interest includes the technique of reducing porosity to result in reduced leachability of all contaminants simultaneously. The current Savannah River Site (SRS) saltstone formulation was used to evaluate the relationship between leachability and porosity reduced waste forms by altering the water-to-binder ratio. Results indicated decreasing the water-to-binder directly reduced porosity and resulted in the waste form’s ability to more effectively immobilize nitrate. This work was funded by the Department of Energy Office of Environmental Management (DOE-EM) Technology Operations Office (TOO) Project # HQ221818.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W

OEDI—Solar Grid Integration Data and Analytics Library

As a part of the Open Energy Data Initiative, this effort aims to develop and demonstrate novel distribution state estimation, control optimization, and transient analysis as well as provide access to data, data integration, and mapping information. More specifically, the focus of the effort will be on physics-based distribution system state estimation, hybrid (physics-based and machine learning) distribution optimal power flow, and event detection/analysis for solar integration and analytics. This work will enable reproducible, robust, replicable, and generalizable R&D in simulation and emulation of solar system integration. These test models and datasets will provide an integrated library for developing and testing power system operation technologies. To make the library user-friendly, this project will provide data curation tools such as data translators, mapping scripts and APIs, database schemas and metadata, interfaces and user dashboard, source code for the reference algorithms, description of the use-cases/scenarios, and comprehensive information on all the assumptions.

14 SOLAR ENERGY

Cybersecurity at the Grid Edge: Protecting LA's Energy Systems in a Connected World

Join SoCalGas and the National Laboratory of the Rockies (NLR) for an insightful webinar on securing operational technology and energy systems. Los Angeles has the second-largest metro by population in the nation, making it vital to protect the energy infrastructure that powers day-to-day life. However, cybersecurity for energy systems is an immense challenge due to an increasing number of interconnected devices and stakeholders. While there was traditionally a limited need to secure energy infrastructure, the grid is only becoming smarter and more software-defined. Amid aging infrastructure and evolving cyber threats, the need to ensure the security of energy is at an all-time high. Together, SoCalGas and NLR are assessing the current state-of-the-art of the energy ecosystem to understand gaps in current best practices and technologies relevant to powering the city of Los Angeles.

97 MATHEMATICS AND COMPUTING