Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Device Classification for Industrial Control Systems Using Predicted Traffic Features

To achieve a secure interconnected Industrial Control System (ICS) architecture, security practitioners depend on accurate identification of network host behavior. However, accurate machine learning based host identification methods depends on the availability of significant quantities of network traffic data, which can be difficult to obtain due to system constraints such as network security, data confidentiality, and physical location. In this work, we propose a network traffic feature prediction method based on a generative model, which achieves high host identification accuracy. Furthermore, we develop a joint training algorithm to improve host identification performance compared to separate training of the generative model and the classifier responsible for host identification.

97 MATHEMATICS AND COMPUTING↗

Analyzing Insider Risk Threat to the Internet of Things (IoT)

Recent technological advancement has created a growing convergence of innovation. From machine learning to ubiquitous computing to wireless networks and automation, the world is seeing new technology increasingly capable of connecting with each other. Devices and systems use open communications networks to interact, process information, and react. This is called the Internet of Things (IoT) and is comprised of physical devices that exchange data over networks, creating revolutionary possibilities. The most common way most people interact with an IoT is through ‘smart home’ products like Amazon’s Alexa, which use microphones, speakers, and phones to control a variety of devices, from lights and thermostats, to cameras, to appliances and vacuum cleaners. But the open nature of IoT networks—necessary for their ability to communicate and operate—also introduces privacy and security concerns. At a personal level, this might mean a hack into a home to steal private information, but when applied in broader industries like healthcare, transportation, manufacturing, or the military, this vulnerability can have serious consequences. As IoT usage and interconnectivity increases, so too does the susceptibility to malicious actors. And the entire system is only as secure as its least secure member. This creates particular risk and vulnerability to radiological material industries, as a competent insider adversary could utilize the IoT to potentially steal or access classified or sensitive information about employees, sites, or systems; or simply sabotage security or maintenance from a more remote—and less secure—device. The IoT relies on a secure network across the entire system, especially in transport which may lack the security of more permanent locations; if one device fails, it can create a ripple effect and an insider threat may seek to exploit that connectivity. While IoT benefits drive increased innovation and usage, there are also vulnerabilities an insider threat could exploit; this risk of an IoT to radiological material must be addressed in any mitigation effort.

Kinney, Justin↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Empowering Critical Infrastructure Communication with Secure 5G Private Networks

With the transformational New Radio- Unlicensed (NR-U), 5G network can be operated with unlicensed and shared spectrum. Private 5G networks without any licensed bands, which are both highly expensive and usually available to only large commercial wireless providers, can now be used for a whole range of new applications including smart factories, warehouses, connected cars and drones. 5G’s support of a) massive machine type communication (mMTC) for a large number of connected devices with b) ultra-reliable low latency communication (URLLC) capability when needed, and c) up to 20 times higher data rate with enhanced mobile broadband (eMBB) than previously available, enables new and powerful capabilities in a wireless network. While these capabilities are transformational, necessary security and reliability requirements have to be satisfied when used in critical infrastructure such as factories, power plants, water systems, ports, and other industrial facilities. 5G standards have introduced significant security improvement over 4G/LTE as well as mitigations for new attack surfaces created by changes in the 5G network. This talk will discuss these security improvements and whether they meet the security properties required for mission critical communication over wireless.

5G↗

CAST Technical Bulletin #004: Network Time Protocol Introduction

Network Time Protocol (NTP), as it traditionally generated and widely consumed, is a legacy system with known security vulnerabilities. The vulnerabilities can be mitigated by modern implementations of NTP that use internal and external redundancy for better accuracy and fault tolerance. Precision Time Protocol (PTP) is an alternative that uses master clocks inside secure networks to eliminate the known vulnerabilities of NTP.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS↗

Reactor System Facility Modification to Detect Compromised Human Machine Interfaces

This study focuses on a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture to aid in the discovery and mitigation of compromised Human Machine Interface (HMI)/Instrumentation & Control (I&C) based systems for modifying a prototypical reactor condition test facility called the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). This is achieved through a three-layered combination of network security solutions, hash-based algorithms, and blockchain technologies. Hash algorithms are mathematical functions used to generate a predetermined set of fixed-length values. They are widely used in computer security to verify the integrity of system information and data, both on a local network and the wider internet. Even small amounts of unauthorized system modification will cause the hash algorithm to output a set of characters that deviate significantly from its original value. Assisting secure hash functions, blockchain technology is a secure and distributed technology used to provide an immutable set of records replicated on all devices within a decentralized network. Blockchain offers a cost-effective solution to detect system compromise by providing a traceable breadcrumb trail of all network activity and data modification happening on a system. If both are used in conjunction with network monitoring tools, the integration of this three-pronged approach can become an asset in detecting suspected system compromises before any real damage can occur.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Countering Weapons of Mass Destruction Office (CWMD) Data Categorization Study: Chemical, Biological, Radiological, and Nuclear (CBRN) Detection Device Data

Pacific Northwest National Laboratory (PNNL) seeks to address critical questions related to chemical, biological, radiological, and nuclear (CBRN) detection devices. This research aims to enhance the security and understanding of these devices by investigating various aspects of their identification, communication, and functionality. The primary focus is on network security, malware detection, device identification, and intelligence gathering. CBRN data can be categorized in various ways depending on the purpose of CBRN detection devices and the specific context of the applications for analysis. Criteria that can be used to assist in this effort include but are not limited to data type, data protocol, source/destination, application, time, security, and content. This study will inform additional paths for data classification, data profiling, data mapping, and data modeling. This will help the Countering Weapons of Mass Destruction Office (CWMD) better understand their data and make informed decisions based on the insights gained from this study and their application. The CBRN Data Categorization study will include the identification of 5–10 different CBRN detection devices with unique characteristics for assessing and analyzing the data that is being produced by and transmitted from these devices.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Internship Presentation: Reactor System Facility Modification to Detect Compromised Human Machine Interfaces

This study presents a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture aimed at detecting and mitigating compromised Human Machine Interface (HMI) and Instrumentation & Control (I&C) systems within the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). The approach combines network security solutions, hash-based algorithms, and blockchain technologies to verify system integrity and provide an immutable record of network activity. This integrated three-pronged strategy enhances the detection of system compromises, enabling preemptive action before significant damage occurs.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Schema Elements for Granta Annual Report

Granta: Materials Intelligence, also known as Granta:MI or Granta, is a commercial database software by Ansys, Inc. that is utilized by the Nuclear Security Enterprise (NSE) to organize and store materials data relevant to the complex. The software was first adopted by individual sites in the early 2000’s, but in FY20, enterprise-wide licensing was purchased for the NSE by the Product Realization Integrated Digital Enterprise (PRIDE) program. Currently, there are 375 floating licenses available for users at all sites. There are also two shared instances of Granta; a classified production instance on the Enterprise Secure Network (ESN) and an unclassified development instance. Additionally, some individual sites such as Los Alamos National Laboratory (LANL), Lawrence Livermore National Laboratory (LLNL), Sandia National Laboratories (SNL), Kansas City National Security Campus (KCNSC), and Savannah River National Laboratory (SRNL) host their own local Granta instances on their own networks that, in general, only their employees can access.

36 MATERIALS SCIENCE↗

Automatic DDoS Attack Detection on SDNs: Preprint

Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks pose a serious threat to computing networks - especially to critical systems within the U.S. electrical grid. As attack mechanisms have increased in complexity and variety, more sophisticated detection mechanisms have become necessary to ensure network security. This paper explores the use of artificial intelligence to automate the process of detection and mitigation of DoS and DDoS attacks within the framework of Software-Defined Networking (SDN), to a high degree. Machine learning algorithms are trained to recognize DoS and DDoS attacks and are deployed in real-time to mitigate malicious network traffic. The results show a well-tuned gradient-boosted decision tree detecting DoS and DDoS attacks, as well as initial successful mitigation of attacks within an SDN framework.

cyber detection↗

Anonymization of Network Traces Data through Condensation-based Differential Privacy

Network traces are considered a primary source of information to researchers, who use them to investigate research problems such as identifying user behavior, analyzing network hierarchy, maintaining network security, classifying packet flows, and much more. However, most organizations are reluctant to share their data with a third party or the public due to privacy concerns. Therefore, data anonymization prior to sharing becomes a convenient solution to both organizations and researchers. Although several anonymization algorithms are available, few of them allow sufficient privacy (organization need), acceptable data utility (researcher need), and efficient data analysis at the same time. This article introduces a condensation-based differential privacy anonymization approach that achieves an improved tradeoff between privacy and utility compared to existing techniques and produces anonymized network trace data that can be shared publicly without lowering its utility value. Our solution also does not incur extra computation overhead for the data analyzer. A prototype system has been implemented, and experiments have shown that the proposed approach preserves privacy and allows data analysis without revealing the original data even when injection attacks are launched against it. When anonymized datasets are given as input to graph-based intrusion detection techniques, they yield almost identical intrusion detection rates as the original datasets with only a negligible impact.

97 MATHEMATICS AND COMPUTING↗

Open Source Intelligence for Cybersecurity Events via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes. We also examine the potential of OSINT for identifying the network protocols associated with specific events, which can aid in the mitigation procedures by informing operators if the vulnerability is exploitable given their system’s network configurations.

Dale, Dakota↗

Designing Secure and Resilient Cyber-Physical Systems Using Formal Models

This work-in-progress paper proposes a design methodology that addresses the complexity and heterogeneity of cyber-physical systems (CPS) while simultaneously proving resilient control logic and security properties. The design methodology involves a formal methods-based approach by translating the complex control logic and security properties of a water flow CPS into timed automata. Timed automata are a formal model that describes system behaviors and properties using mathematics-based logic languages with precision. Due to the semantics that are used in developing the formal models, verification techniques, such as theorem proving and model checking, are used to mathematically prove the specifications and security properties of the CPS. This work-in-progress paper aims to highlight the need for formalizing plant models by creating a timed automata of the physical portions of the water flow CPS. Extending the time automata with control logic, network security, and privacy control processes is investigated. The final model will be formally verified to prove the design specifications of the water flow CPS to ensure efficacy and security.

42 ENGINEERING↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

Dependable classical-quantum computing systems engineering

Increasing evidence suggests quantum computing (QC) complements traditional High-Performance Computing (HPC) by leveraging its unique capabilities, leading to the emergence of a new, hybrid paradigm, QHPC. However, this integration introduces new challenges, with dependability–defined by reproducibility, resiliency, and security and privacy–emerging as a central concern for building trustworthy systems that provide an advantage to the users. This paper proposes a framework for dependable QHPC system design, organized around these three pillars. We identify integration challenges, anticipate roadblocks, and highlight productive synergies across QC, HPC, cloud platforms, and network security. Drawing from both classical computing principles and quantum-specific insights, we present a roadmap for co-design that supports robust hybrid architectures. Our approach offers concrete metrics for assessing dependability, provides design guidance for engineers working at the QC-HPC interface, and surfaces new engineering questions around complexity, scale, and fault tolerance. Ultimately, designing for dependability is key to realizing practical, scalable QHPC systems and accelerating the broader quantum ecosystem capable of translating quantum promises into actual application delivery.

HPC↗

Smart Packaging for Critical Energy Shipment (SPaCES)

Recent technical advances have brought forth revolutionary Smart Packaging (SP) technology. SP incorporates multiple electronics, chemical, and mechanical sensing technologies into packaging materials, and utilizes them to monitor and display package content status. SP can also employ embedded micro actuators to react to undesirable package conditions such as moisture/temperature anomalies or harmful chemical reactions and neutralize it. When further integrated with wireless sensing and secure networking, SP provides wholistic system-wide remote situation awareness capability for real-time crisis management. Finally, we also see that SP can be further integrated with 3D printing technology to offer form-factor customization and application specific solutions suitable for DOE (Department of Energy) NNSA’s (National Nuclear Security Administration) R/N (radiological/nuclear) material shipment and management needs; this has the potential to improve safety, security, and overall operation process quality. This report surveys SP technology as the state of the art (SOTA) and analyzes how it can integrate with cybersecurity and 3D printing to address NNSA’s critical R/N material shipment and storage requirements. This report further presents our FY23/24 investigation plan describing project background, goal, motivation, proposed work, and statement of work and cost.

47 OTHER INSTRUMENTATION↗

Scalable edge clustering of dynamic graphs via weighted line graphs

Timestamped relational datasets consisting of records (or connections) between pairs of entities are ubiquitous in network science. For applications like peer-to-peer communication, email, various social network interactions, and computer network security, it is useful to organize these records into groups based on how and when they are occurring. Weighted line graphs offer a natural way to model how records are related in such datasets but for large real-world graph topologies, building and utilizing the line graph is prohibitively expensive. Here, we present the framework to cluster the edges of a dynamic graph via the associated line graph that contains two major contributions. The first is a method to work with the line graph implicitly and the second is a distributed scale implementation of an agglomerative hierarchical graph clustering algorithm. We outline a novel hierarchical dynamic graph edge clustering approach that efficiently breaks massive relational datasets into small sets of edges containing events at various timescales. This is in stark contrast to traditional graph clustering algorithms that prioritize highly connected (clique-like) community structures. Our approach relies on constructing a sufficient subgraph of a weighted line graph and applying a hierarchical agglomerative clustering. This approach is related to scalable techniques from spatial clustering, nonlinear-dimension reduction, topological data analysis, and draws particular inspiration from HDBSCAN. As an edge clustering, this method yields an overlapping node clustering. Our algorithm is parallelizable and we demonstrate efficient clustering of a billion-scale, real-world dynamic graph into small edge sets that correlate in topology and time. The entire clustering process for a graph with tens of billions of edges takes just a few minutes of run time on 256 nodes of a distributed compute environment. We argue how the output of the edge clustering is useful for a multitude of data visualization and powerful machine learning tasks, both involving the original massive dynamic graph data and metadata associated with the nodes and edges. Finally, we describe how this approach can be extended to dynamic hypergraphs and dynamic graphs/hypergraphs with unstructured data living on vertices and edges.

Data Analysis↗