Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

NREL Project CloudZero

The National Renewable Energy Laboratory's (NREL's) CloudZero project is evaluating the ability to reliably and securely manage complex energy systems from the cloud, identifying major technical and regulatory barriers to cloud adoption, suggesting new security controls and best practices for cloud applications, and empowering industry to embrace the cloud, where appropriate.

cloud↗

Cyber–physical vulnerability and resiliency analysis for DER integration: A review, challenges and research needs

High penetration of renewable and sustainable Distributed Energy Resources (DER) into the traditional distribution system requires a well-coordinated control strategy for the improvement of system-wide reliability and resiliency. Implementation of such a holistic control architecture requires a flexible, near real-time, and bi-directional communication framework for facilitating the participation of various agents in a multi-vendor heterogeneous smart grid. While the sustainability of energy generation is ensured, this exposes the smart grid to extrinsic cyber threats, and appropriate defense mechanism(s) must be deployed to guarantee continued reliability and resiliency of the power grid. Further, the comprehensive literature review presented in this paper discusses the latest trends in the DER control schemes with fast communication requirements and their accompanying cyber–physical vulnerabilities. These control schemes are compared and contrasted for various traits. A three-level DER system architecture has been depicted, facilitating the deployment of these control schemes. The current developments of standard communication protocols, key security mechanisms, and best practices along major standards and guidelines are explored. The impacts of different attack types with miscellaneous DER functions based on various control schemes and associated mitigation solutions are also provided. Finally, challenges and future research directions for limiting cyber-power susceptibility to enhance resiliency are summarized. The work presented here will help us enabling a cyber-resilient and sustainable smart electric grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Integration of the NCRC Database and Other INL Databases

The Nuclear Computational Resource Center provides a portal by which industry professionals, educational staff, students, national laboratory employees, and others may request access to certain engineering software tools. As the tools provided through the Nuclear Computational Resource Center portal are not open-source and freely available, a set of approvals are necessary before access is granted. All code recipients must be associated with an institution that has a license with Idaho National Laboratory for the code requested. Information about these licenses is controlled by Idaho National Laboratory’s Technology Deployment organization and housed in a Technology Deployment database. Those requesting code access who are not citizens of the United States must also have a security plan, mandated by Idaho National Laboratory policy. Security plans are managed by the International Access Program and are stored in an International Access Program database known as IFacts. Granting access to software thus depends on information stored in the Technology Deployment database and IFacts. In the past, no connection between the Nuclear Computational Resource Center portal and these databases existed, making checking the status of license agreements and security plans time consuming and error prone. This report demonstrates that the Nuclear Computational Resource Center portal now connects to both the Technology Deployment database and IFacts, greatly improving the ease of use of the Nuclear Computational Resource Center system for administrators, which leads to a better overall experience for those requesting code access.

99 GENERAL AND MISCELLANEOUS↗

Summer 2024 INL Intern Poster Session Submission - Brian Schumitz

This LRS submission is my poster for the INL Intern Poster Session, Summer 2024. Abstract: The Software Engineering and Cybersecurity Lab (SECL) at Montana State University has developed PIQUE, a system for evaluating software quality. PIQUE's adaptability allows for language-specific static-analysis operations, including a model for assessing cloud microservice ecosystems. These ecosystems often rely on Docker for efficient deployment and management of containerized services. Our research focuses on evaluating the network quality within these microservice ecosystems. To automate this process, we're utilizing Snort, an open-source intrusion detection system renowned for its ability to detect and log network traffic. By leveraging Snort's customizable rules, we aim to construct comprehensive testing methods for measuring and quantifying the network quality based on traffic between Docker containers. This research aims to enhance the overall security and reliability of cloud microservice ecosystems by providing automated and robust quality evaluation mechanisms, ultimately contributing to the advancement of software engineering practices in these environments

97 MATHEMATICS AND COMPUTING↗

DGaaS: GPU as a Service on Distributed Computing System

In the rapidly evolving landscape of scientific computing, Graphics Processing Units (GPUs) have become indispensable for their unparalleled ability to handle parallel tasks in complex calculations, simulations, and data analysis. Their utility is further magnified in machine learning and AI applications, where they significantly accelerate model training and predictive analytics. Within this context, the Triton Inference Server emerges as a pivotal open-source tool, specializing in AI inferencing and optimizing GPU utilization across various platforms and frameworks. This paper presents an in-depth study on distributed High Throughput Computing (HTC), specifically focusing on the HTCondor framework and its resource provisioning tools, GlideinWMS and HEPCloud. These systems enable large-scale scientific experiments like CMS and DUNE to efficiently access and utilize vast computational resources. The paper explores the core architectural components of GlideinWMS, including jobs, user pools, and worker nodes, and discusses their integration with GPUs and the Triton server. The primary aim of this research is to develop a solution that optimizes GPU utilization by leveraging Glideins and containers. This approach allows computational jobs, particularly those involving AI models, to use GPUs only when essential, thereby facilitating efficient sharing of limited GPU resources. To validate this architecture, the study conducted three key tests involving custom scripts, container-based servers, and Triton server deployments. However, the study faces challenges, notably in locating the Triton server and ensuring secure remote access. To address these issues, future work will focus on developing a proxy mechanism and enhancing security protocols. In conclusion, this study offers a comprehensive roadmap for effective and efficient GPU utilization in distributed High Throughput Computing. It aims to contribute significantly to the scientific community by solving pressing problems and implementing robust solutions in collaboration with the GlideinWMS and HEPCloud teams. The research sets the stage for a more efficient, scalable, and cost-effective paradigm in scientific computing.

97 MATHEMATICS AND COMPUTING↗

Scenario Exploration and Timeline Analysis for Advanced Reactors [Slides]

Slides created to discuss the report "Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements" (August 2022 INL/ RPT-22-68664) for an upcoming DOE security workshop. Advanced reactors will be able to use risk insights for many design aspects. We need realistic scenarios for input into the licensing basis safety-case. These scenarios must include timing and physics. We need to automate the safety-case creation as much as possible.

97 MATHEMATICS AND COMPUTING↗

A 5G Enabled Adaptive Computing Workflow for Greener Power Grid

5G wireless technology can deliver higher data speeds, ultra low latency, more reliability, massive network capacity, increased availability, and a more uniform user experience to users. It brings additional power to help address the challenges brought by renewable integration and decarbonization. In this paper, a 5G enabled adaptive computing workflow tool has been presented that consists of various computing resources, such as 5G equipment, edge computing, cluster, Graphics processing unit (GPU) and cloud computing, with two examples showing technical feasibility for edge-grid-cloud interaction for real-time monitoring, security assessment, and forecasting. Benefiting from the high data transmission speed and massive connection capability of 5G, the workflow shows its potential to seamlessly integrate various applications at distributed and/or centralized locations to build more complex and powerful functions, with better flexibility.

5G technology, computational workflow, edge comput↗

Massively scalable workflows for quantum chemistry: BigChem and ChemCloud

Electronic structure theory, i.e., quantum chemistry, is the fundamental building block for many problems in computational chemistry. Here we present a new distributed computing framework (BigChem), which allows for an efficient solution of many quantum chemistry problems in parallel. BigChem is designed to be easily composable and leverages industry-standard middleware (e.g., Celery, RabbitMQ, and Redis) for distributed approaches to large scale problems. BigChem can harness any collection of worker nodes, including ones on cloud providers (such as AWS or Azure), local clusters, or supercomputer centers (and any mixture of these). BigChem builds upon MolSSI packages, such as QCEngine to standardize the operation of numerous computational chemistry programs, demonstrated here with Psi4, xtb, geomeTRIC, and TeraChem. BigChem delivers full utilization of compute resources at scale, offers a programable canvas for designing sophisticated quantum chemistry workflows, and is fault tolerant to node failures and network disruptions. We demonstrate linear scalability of BigChem running computational chemistry workloads on up to 125 GPUs. Finally, we present ChemCloud, a web API to BigChem and successor to TeraChem Cloud. ChemCloud delivers scalable and secure access to BigChem over the Internet.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Transportation Secure Data Center: Frequently Asked Questions for Data Owners/Contributors

The Transportation Secure Data Center is a centralized repository for detailed transportation data from travel and transit surveys and studies conducted across the nation. It makes vital transportation data broadly available to users while preserving the privacy of survey participants. Hundreds of datasets from surveys and studies of household travel and transit passenger travel are archived in the TSDC, including surveys and studies conducted by state departments of transportation, metropolitan planning organizations, transit agencies, cities, and other public agencies. Detailed data from travel surveys and studies are extremely valuable for research purposes. However, the fine-grained information they contain could potentially be misused to identify individual travelers, so access to these data should only be granted with safeguards in place to protect participant privacy. The TSDC was created to address this challenge and to relieve public agencies from the burden of archiving their data and responding to data requests.

33 ADVANCED PROPULSION SYSTEMS↗

Agent-Based Coordination Scheme for PV Integration (ABC4PV)

Renewables and especially photovoltaics (PV) have benefitted significantly from a host of incentives and policies targeted toward enhanced integration and adoption of specific energy technologies. However, with the push to move forward into a subsidy-free market framework, behind-the-meter residential PV applications have generally struggled to retain their value (unlike utility scale and commercial projects) [1]. This project focused on developing control-theoretic solutions aimed at improving the integration and interaction of behind-the-meter residential PV with other distribution system assets (controllable and non-controllable) to enhance the integrated value of residential PV. To this end, a suite of decentralized control methodologies have been developed to enable effective coordination and control of behind-the-meter residential load customers’ PV, battery storage systems (BSS), controllable loads and other similar assets within a distribution feeder. This interaction aims at procuring energy savings and, thus, energy bill savings. The main source of savings is drawn from reducing the effect of demand charge pricing and is realized at the feeder level, assuming community level interaction and management among the aforementioned assets. Optimal control of the assets is implemented with a distributed optimization methodology, leveraging consensus-based algorithms. The results gathered from the optimal control simulations demonstrates that the savings can be duly achieved and the algorithm decision times (to dynamically control asset set points, for example) are fast. As for the overall efficiency of PV+BSS systems, to procure energy savings from curtailment of the demand charge pricing effects, the optimal control is set up so as to minimize the variance of the load for all customers, throughout a feeder and throughout time in a rolling horizon scheduling with model predictive control. The control takes into account inter-temporal electrochemical storage (battery) degradation costs: specifically, we have developed a long-term lifetime model for the BSS that weighs in the effect of the degradation factor in the dispatch formulations, thus, a considerable operating cost that affects energy decision making. The levelized cost of energy (LCOE – redefined for the purpose of quantifying asset integration effectiveness through the customers’ energy cost) is shown to be below the threshold set for the combined PV+BSS topology of $ 0.14/kWh for multiple cases of PV penetration all the way up to 50%, provided that a policy of shared ownership of and savings is in place. Further, the LCOE calculated for the case before the deployment PV+BSS systems is also achievable, i.e. the deployment of PV+BSS, if planned and scheduled optimally. will have no effect on customers’ energy costs. From the control methodology viewpoint, the developed consensus-based algorithms are shown to converge for a wide range of problem cases (spanning normal operating scenarios and contingencies), guaranteeing dispatch solutions under forecasting errors, communication break-downs and cyber-security attacks. The proposed control solutions are scalable and real-time implementable, with dispatch computations and device set-point updates converging in less than 2s in most practical instances of the above events.

14 SOLAR ENERGY↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

Y-12 Groundwater Protection Program Data Management Plan

This Data Management Plan (DMP) describes the processes in place to ensure the integrity of groundwater monitoring information collected by the U.S. Department of Energy (DOE), National Nuclear Security Administration (NNSA), Y-12 National Security Complex (Y-12), Groundwater Protection Program (GWPP). This information includes program plans, reports, and computer systems used to capture monitoring station information and analytical data. The primary computer system used by the GWPP is the Groundwater Information Management System (GIMS). Procedures used to ensure the integrity of the data are included in this document by reference.

54 ENVIRONMENTAL SCIENCES↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

IRI Technology Landscape – A survey of re-usable components and methodologies

This document describes technical implementation details on network access schemes connecting API-driven workflows to supercomputer centers. API-driven workflows are a central theme in connected computing, since they bring the terminal-mainframe' access pattern present since the 1970s up to the task of interfacing with modern web browser technologies. Both security (HTTPS/TLS/IPSec/VPNs/public key cryptography/digital signatures) and network protocol stacks (HTTP-REST APIs, tokens, gRPC, SRTP) have evolved to the point where implementing API-driven workflows is possible using stable, secure off-the-shelf software.

97 MATHEMATICS AND COMPUTING↗

Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements

Next-generation reactors will be able to use risk to inform and performance base the licensing of many aspects of the reactor, facility, and site design, including attributes of physical security. There are several factors related to security, including site topography, reactor design, and physical protection system components, to consider when designing the physical protection system into the overall facility design and plan of operation. With the versatility of advanced reactors, especially micro reactors, methods are needed to simplify and quickly evaluate potential timelines for designing a site configuration. This report describes an approach to generate qualitative and quantitative insights using a risk-informed simulation. The modeling process is described in detail, focusing on three aspects: (1) the facility mission time (the time required to control the plant until safe), (2) the attacker timeline (the time to potential sabotage), and (3) the response timeline (the time to counter the facility attack). The modeling capabilities also are extended to include facility physical phenomena such as thermal-hydraulics and heat transfer to capture realistic representation of dynamic changes to a facility. While the plant models and examples are hypothetical and do not represent a real facility, these modeling approaches could be used for future security-by-design engineering in advanced reactors. The outputs and insights from the modeling approach may be used to modify and optimize the security posture of a facility by efficiently making modifications to the model and seeing the overall impact from the modification. Lastly, use of the approach described in this report can also provide the technical basis for a physical protection program, describing how the facility and security strategy will cope with off-normal events.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

National-Tribal Critical Infrastructure Protection: Collaboration for Extraordinary National Security Benefit

This paper examines national and tribal collaborative opportunities to get ahead of the critical infrastructure insecurity problem. Recommendations are viewed through the lens of the Sandia Labs Tribal Cyber-Energy initiative and national security projects. Recommendations include 1) Collaboratively address national priority and shared challenges to gain faster and better solutions to national priority problems on a smaller yet comprehensive American Indian and Alaskan Native sovereign single-point of authority scale 2) Utilize newer standards-based technologies to provide scalable, capable, and manageable solutions for greatly expanded and connected national critical infrastructures 3) Employ Cyber-Physical-Resilient design preliminary analysis to define concept- to-disposition design requirements for preemptive critical infrastructure risk mitigation and baked-in security; 4) Develop data-centric protection to provide increased information asset protection as data shifts from data-owner operated on-premises infrastructure to virtual service provider data-steward owned and operated off-premises infrastructure; and 5) Balance shared solutions with the National Institute of Science and Technology (NIST) Cybersecurity and Risk Management frameworks, and the System Security Engineering Guidelines. As yet unallocated federal funding would support research, development, the timely application of National-Tribal critical infrastructure protection, and critical infrastructure Cyber disruption response and recovery with extraordinary mutual benefits for the foreseeable future. The Critical Infrastructure Insecurity Problem: Rapid modernization and expansive connectivity are due to advances in Information and Communications Technologies that have sweeping cyber impact across all critical infrastructure sectors. Supervisory Control and Data Acquisition and Industrial Control Systems are particularly impacted as systems long separated from the Internet are now being connected and computerized. Virtualization and mobility create a Data Everywhere-User Anywhere paradigm that has evaporated the enterprise network perimeter. There are multi-front technological challenges at play, where long depended on technologies simply don't scale to current needs resulting in a digital dichotomy of competing old and new standards. New standards-based technologies scale but are not as well-known or as widely deployed, which leaves decision makers, stakeholders, and the workforce in a quandary, caught mid-stream between the technological past and the virtual future. Rapid and expansive cyber threat accompanies disruptive change in connectivity and computational dependencies. A lack of action will exacerbate the problem if new technologies roll out without baked-in security design. The Risk: If National-Tribal CIP collaboration to design in security is not done, then an ongoing state of insufficient bolt-on security and elevated threat exposure will remain for years to come.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗