Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Technology and Operations”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Advance Reactor Operational Technology Architecture Categorization

Seven generation III+ and generation IV nuclear reactor types, based on twelve reactor concepts surveyed, are examined using functional decomposition to extract relevant operational technology (OT) architecture information. This information is compared to existing nuclear power plants (NPPs) OT architectures to highlight novel and emergent cyber risks associated with next generation NPPs. These insights can help inform operational technology architecture requirements that will be unique to a given reactor type. Next generation NPPs have streamlined OT architectures relative to the current generation II commercial NPP fleet. Overall, without compensatory measures that provide sufficient and efficient cybersecurity controls, next generation NPPs will have increased cyber risk. Verification and validation of cyber-physical testbeds and cyber risk assessment methodologies may be an important next step to reduce cyber risk in the OT architecture design and testing phase. Coordination with safety requirements can result in OT architecture design being an iterative process.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Community threat intelligence and visibility for operational technology networks

Techniques are provided for community threat intelligence for operational technology networks. For a plurality of OT networks, at least one monitoring device processes OT network traffic and collects telemetry data, and a telemetry sanitization system applies a sanitization process to the telemetry data to generate sanitized telemetry data that does not include sensitive data. A computer system receives sanitized telemetry data from the telemetry sanitization systems provided for the plurality of OT networks, maintains threat intelligence data generated based on the sanitized telemetry data, and provides access to at least one of the threat intelligence data and the sanitized telemetry data to a plurality of users.

Bladow, Garrett↗

Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE)

NASA has partnered with Advanced Space to develop and build the Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE) mission which will serve as a pathfinder for Near Rectilinear Halo Orbit (NHRO) operations around the Moon. The NHRO, (Perilune = 3,200 km; Apolune = 70,000 km) will be the intended orbit for the NASA’s Artemis Gateway lunar orbital platform. The CAPSTONE mission will validate simulations and confirm operational planning for Gateway while also validating performance of navigation and station-keeping requirements for the Power and Propulsion Element. Thus, this mission will provide operational experience to NASA, commercial, and international missions for operations in a demanding orbital regime. The baseline for CAPSTONE is to fly a 12U cubesat developed, integrated, and tested by Tyvak Nanosatellite Systems carrying a payload communications system capable of cross-link ranging with the Lunar Reconnaissance Orbiter (LRO), a dedicated payload flight computer for software demonstration, and a camera. The launch, coordinated by NASA Launch Services Program, will be provided by a Rocket Lab launch vehicle utilizing their new Proton upper stage to deploy the CAPSTONE spacecraft into the lunar orbit. The CAPSTONE mission is targeting a launch no earlier than September 23, 2021. Upon launch, the spacecraft will traverse a highly efficient transfer taking approximately three months to enter a primary demonstration phase in an NRHO for six months followed by a twelve month technology enhancement operations phase. The CAPSTONE Project is lead by Advanced Space, LLC of Boulder Colorado. Spacecraft development and mission operations will be conducted by Tyvak Nanosatellite Systems of Irvine, California. Noted objectives for the CAPSTONE mission will be to demonstrate the accessibility of NHROs, validate key operational concepts in the NHRO environment, lay a foundation for commercial support of future lunar operations and accelerate the availability of peer-to-peer navigation capabilities provided by the Cislunar Autonomous Positioning System (CAPS). The CAPSTONE mission is funded through NASA's Small Spacecraft Technology Program (SSTP), which is one of several programs in NASA’s Space Technology Mission Directorate. SSTP is chartered to develop and demonstrate technologies to enhance and expand the capabilities of small spacecraft with a particular focus on enabling new mission architectures through the use of small spacecraft, expanding the reach of small spacecraft to new destinations, and augmenting future missions with supporting small spacecraft. The launch for the CAPSTONE Mission is provided by Human Exploration & Operations Missions Directorate Advanced Exploration Systems Division. Coordination and Acquisition of the Launch is managed by NASA’s Launch Services Program. The CAPSTONE Mission and project status will be presented.

CAPSTONE↗

Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE) Mission

NASA has partnered with Advanced Space to develop and build the Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE) mission which will serve as a pathfinder for Near Rectilinear Halo Orbit (NHRO) operations around the Moon. The NHRO, (Perilune = 3,200 km; Apolune = 70,000 km) will be the intended orbit for the NASA’s Artemis Gateway lunar orbital platform. The CAPSTONE mission will validate simulations and confirm operational planning for Gateway while also validating performance of navigation and station-keeping requirements for the Power and Propulsion Element. Thus, this mission will provide operational experience to NASA, commercial, and international missions for operations in a demanding orbital regime. The baseline for CAPSTONE is to fly a 12U cubesat developed, integrated, and tested by Tyvak Nanosatellite Systems carrying a payload communications system capable of cross-link ranging with the Lunar Reconnaissance Orbiter (LRO), a dedicated payload flight computer for software demonstration, and a camera. The launch, coordinated by NASA Launch Services Program, will be provided by a Rocket Lab launch vehicle utilizing their new Proton upper stage to deploy the CAPSTONE spacecraft into the lunar orbit. The CAPSTONE mission is targeting a launch no earlier than September 23, 2021. Upon launch, the spacecraft will traverse a highly efficient transfer taking approximately three months to enter a primary demonstration phase in an NRHO for six months followed by a twelve month technology enhancement operations phase. The CAPSTONE Project is lead by Advanced Space, LLC of Boulder Colorado. Spacecraft development and mission operations will be conducted by Tyvak Nanosatellite Systems of Irvine, California. Noted objectives for the CAPSTONE mission will be to demonstrate the accessibility of NHROs, validate key operational concepts in the NHRO environment, lay a foundation for commercial support of future lunar operations and accelerate the availability of peer-to-peer navigation capabilities provided by the Cislunar Autonomous Positioning System (CAPS). The CAPSTONE mission is funded through NASA's Small Spacecraft Technology Program (SSTP), which is one of several programs in NASA’s Space Technology Mission Directorate. SSTP is chartered to develop and demonstrate technologies to enhance and expand the capabilities of small spacecraft with a particular focus on enabling new mission architectures through the use of small spacecraft, expanding the reach of small spacecraft to new destinations, and augmenting future missions with supporting small spacecraft. The launch for the CAPSTONE Mission is provided by Human Exploration & Operations Missions Directorate Advanced Exploration Systems Division. Coordination and Acquisition of the Launch is managed by NASA’s Launch Services Program. The CAPSTONE Mission and project status will be presented.

CAPSTONE↗

Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE): Pathfinder for Artemis Gateway

The Cislunar Autonomous Positioning System Technology Operations and Navigation Experiment (CAPSTONE) mission was developed by NASA in collaboration with Advanced Space, LLC of Westminster, Colorado. This technology demonstration mission serves as a pathfinder for near rectilinear halo orbit (NHRO) operations around the Moon. The NHRO, (Perilune = 3,200 km; Apolune = 70,000 km) is the intended orbit for NASA’s Artemis Gateway, a small, human-tended space station planned for lunar orbit. The CAPSTONE mission will validate simulations and confirm operational planning for Gateway while also validating performance of navigation and stationkeeping requirements for Gateway’s Power and Propulsion Element. Therefore, this mission will provide operational experience to NASA, commercial, and international missions for operations in a demanding orbital regime. This presentation accompanies the paper of the same title.

Elwood F Agasid↗

Unattended network operations technology assessment study. Technical support for defining advanced satellite systems concepts

The results are summarized of an unattended network operations technology assessment study for the Space Exploration Initiative (SEI). The scope of the work included: (1) identified possible enhancements due to the proposed Mars communications network; (2) identified network operations on Mars; (3) performed a technology assessment of possible supporting technologies based on current and future approaches to network operations; and (4) developed a plan for the testing and development of these technologies. The most important results obtained are as follows: (1) addition of a third Mars Relay Satellite (MRS) and MRS cross link capabilities will enhance the network's fault tolerance capabilities through improved connectivity; (2) network functions can be divided into the six basic ISO network functional groups; (3) distributed artificial intelligence technologies will augment more traditional network management technologies to form the technological infrastructure of a virtually unattended network; and (4) a great effort is required to bring the current network technology levels for manned space communications up to the level needed for an automated fault tolerance Mars communications network.

Price, Kent M.↗

Strengthening the Security of Operational Technology: Understanding Contemporary Bill of Materials

The evolution of cyber-physical infrastructure has made its security more challenging. The last few years have witnessed a convergence of hardware and software segments in various domains, including operational technology (OT) which is responsible for carrying out critical tasks such as monitoring and controlling power grids, nuclear plants, transportation, and emergency services. Both hardware and software encapsulate numerous open source and proprietary subcomponents, making it crucial for end-users to understand the composition of the products they are using. For example, wind turbines incorporate thousands of lines of code (software) used for the turbine's design, planning, operation, and analytics in addition to the numerous hardware subcomponents that construct it. Due to the highly complex nature of software and hardware, knowledge of the components and subcomponents is required to mitigate cyber vulnerabilities and defend against cyberattacks. There has also been a transformation from a traditional linear supply chain into a global, dynamic, diverse, and interconnected system. The digitization of the supply chain makes it easier to find and exploit vulnerabilities. Critical infrastructures (e.g., power grids, oil, natural gas, water, and wastewater) rely on OT to function, and if the OT is compromised, equipment damage and potential interruption of services could result. A significant security measure to protect OT systems from disruption is to develop a supply chain bill of materials (BoM) corresponding to the software and hardware used in OT, along with attestations amongst vendors and asset owners. A supply chain BoM is a proactive way to understand the inherent vulnerabilities in the system and mitigate them in advance of being exploited. BoMs bolster the trust placed in the digital infrastructure and enhance software supply chain security by sustaining the management of component obsolescence and compliance, along with the seclusion of unsafe segments of a specific product. Adopting BoM tools is becoming increasingly important across various government sectors, as evidenced by the recent U.S. executive order on cybersecurity (NIST 2021). This paper aims to classify BoMs based on structure, functionality, component type, and architecture. The work also discusses case studies to further highlight the benefits of BoMs. In addition, it identifies missing pieces in existing BoM implementations so that future research may identify bounds on where it could expect to make improvements and directly enable researchers to identify promising areas for exploration. Further, the authors provide valuable recommendations to tool developers, researchers, and standardizing organizations (policymakers), additionally benefitting critical infrastructure owners and government executives. This aids in paving a path for future work, thereby, providing suggestions to determine a tool for consumers that best suit their needs.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity for the Operational Technology Environment (CyOTE)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop CyOTE. This research initiative addresses cybersecurity threats against operational technology (OT) networks by sharing intelligence about adversarial tactics and techniques with the energy sector. CyOTE improves the sector’s ability to detect anomalous behavior that indicates potential malicious cyber activity in OT networks.

99 GENERAL AND MISCELLANEOUS↗

Advanced Grid Operational Technology Edge-Level Threat Detection

This report presents a deployable solution to improve the cybersecurity situational awareness of the legacy SCADA system infrastructure in power grids. The main goal of this project is to provide system owners and operators a highly trusted, intelligent alarm system and comprehensive situational awareness of ongoing or potential cybersecurity threats on the grid network. The key contributions of this project include: (1) the development of software, the Intrusion Detection Visualizer for the Operational Technology Network (IViz-OT), to visualize and locate intrusions on the grid network; (2) testing the signature-based Hybrid Intrusion Detection for Energy Systems (HIDES) for different types of intrusions; (3) the integration of HIDES and IViz-OT into the visualization dashboard; and (4) real-time testing using a hardware-in-the-loop test bed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Uncrewed Aerial System Traffic Management Beyond Visual Line of Sight Multi Operator Technology Assessment Simulation

UAS Traffic Management (UTM) is a rapidly evolving space with increasing demand for regulation surrounding more complex operations. Beyond visual line of sight (BVLOS) operations are among these complex operations. The NASA UTM BVLOS sub-project is focusing on enabling more routine BVLOS operations through data collection for support of standards formulation. The Multi Operator Technology Assessment (MOTA) simulation is one of these activities that collects data on BVLOS operations within the same geographical area while sharing operational intents through a USS. Data collected includes workload, situation awareness, and usability on nominal and off-nominal operations. Results of this study are intended to provide recommendations for standards as well as provide insight on improvements to the systems under test. NASA intends to incorporate those improvements into their operations to support and updated BVLOS waiver from the FAA’s Near-Term Approval Process (NTAP).

Bryan J Petty↗

Uncrewed Aerial System Traffic Management Beyond Visual Line of Sight Multi Operator Technology Assessment Simulation

UAS Traffic Management (UTM) is a rapidly evolving space with increasing demand for regulation surrounding more complex operations. Beyond visual line of sight (BVLOS) operations are among these complex operations. The NASA UTM BVLOS sub-project is focusing on enabling more routine BVLOS operations through data collection for support of standards formulation. The Multi Operator Technology Assessment (MOTA) simulation is one of these activities that collects data on BVLOS operations within the same geographical area while sharing operational intents through a USS. Data collected includes workload, situation awareness, and usability on nominal and off-nominal operations. Results of this study are intended to provide recommendations for standards as well as provide insight on improvements to the systems under test. NASA intends to incorporate those improvements into their operations to support and updated BVLOS waiver from the FAA’s Near-Term Approval Process (NTAP).

Bryan J Petty↗

Micro Baselines for Operational Technology Environments

Critical infrastructure stakeholders need to baseline their networks to understand expected communications. Top-down approaches to baselining rely on observables that are generally available but lack properties upon which traditional statistical tools depend. We propose to construct micro-baselines: signatures within operational networks based on observables associated with specific events. Such observables are informed by precursor analysis reports of historical cyber attacks on operational environments developed by Cybersecurity for Operational Technology Environments (CyOTE). Baseline measurements depend upon context beyond the cyber domain. An energy plant's baseline running in the summer may statistically differ from a similar facility in a colder region. Domain knowledge must be integrated to apply general micro-baselining algorithms to a facility-specific context. Therefore, we propose to explore the feasibility of transferring micro baselining algorithms across different facilities. Facilities that implement the same processes in different geographic locations will be compared relative to observable measurements used in micro-baselining for comparable events. One evaluation approach would condition or augment dynamic observables measured within a facility network testbed with additional observables derived from geographic context or infrastructure dependencies such as those provided by the All-Hazards Analysis tool.

97 MATHEMATICS AND COMPUTING↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Augmenting LLM-Based Agents for Improved Performance in Pentesting and Commissioning Operational Technology in Critical Infrastructure

Artificial intelligence (AI), and more specifically large language models (LLMs) have the potential for use in penetration testing (“pentesting”) against devices, networks, and computer systems in information technology (IT). We explore the possibility of extending pentesting from IT systems to operational technology (OT) systems, which are more obscure than IT systems in their protocols and design. A challenge therefore exists when applying pretrained LLMs to OT systems as corpora are likely to underrepresent OT systems in comparison to other more prevalent systems. We evaluate augmentations of LLMs with various methods, especially retrieval augmented generation (RAG), to improve performance of the LLMs in the OT domain. In addition to pentesting, some of the testing of these OT devices may include commissioning to ensure that the newly installed devices work correctly. Our framework may also be applied in such cases.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Engineering Services in a Mission Critical Environment: Engineering Services - Science and Technology Operations’ Infrastructure Support at Los Alamos National Laboratory

As an engineering team within a facilities-driven organization, Engineering Services – Science and Technology Operations (ES-STO), supports Los Alamos National Laboratory (LANL), playing a pivotal role in the U.S. nuclear stockpile mission. This report outlines ES-STO’s contributions through the installation of crucial systems such as HVAC units, compressors, and scientific specialty equipment, as well as providing expert consultation to optimize laboratory operations. ES-STO’s goal is to ensure that LANL's infrastructure and research facilities are aligned with mission-critical needs, supporting both operational efficiency and safety in the nuclear stockpile management and maintenance. This report discusses the installation processes, ongoing consultations, and the significant impact of our efforts on national security objectives.

42 ENGINEERING↗

Operational Technology Behavioral Analytics (OTBA) (Final Technical Report DE-FE0031640)

This final report provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company Services, Inc. at Alabama Power Company’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

20 FOSSIL-FUELED POWER PLANTS↗

Aggregate attack surface management for network discovery of operational technology

Interconnectivity has become a substratum of technology as the benefits of data-driven functionality are being realized in nearly all industries. Increased connectivity of Operational Technology (OT) exacerbates cyber risks because Industrial Control Systems (ICS) are becoming exposed to the Internet. These exposures are often done inadvertently through misconfigurations as additional network devices come online. Attack surface management (ASM) platforms can be used to identify vulnerabilities by performing external network discovery over the Internet using web spiders. These web spiders enable big data analytics of Internet of Things (IoT) devices as identifiable information of Internet-exposed equipment are archived in searchable databases that are made publicly available. There are a multitude of ASM service providers on the market. Here, this study was conducted to evaluate several commonly known tools to determine the aggregate attack surface of control systems. Queries were crafted by targeting commonly known manufacturers and communication protocols found in OT networks. Identified devices were that categorized based on technology types. Each query was replicated between several tools to target identical ICS equipment. Findings in this paper suggested a significant variance in the exposures discovered by each tool, but unique contributions were identified for each tool when a merged attack surface was derived. Therefore, all tools should be used in aggregate.

97 MATHEMATICS AND COMPUTING↗