Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “IP networks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

45 records · Page 3

MARIAH PCAP data for Validation Demonstration

This dataset holds simulated PCAP (packet capture) data from the SCEPTRE validation demonstration model as a set of pairwise communications between devices via specific protocols. All connections should be assumed to be symmetric, as this data is an aggregation of the true PCAP. A mapping is also provided associating each IP address with its true device type.

cyber-physical system↗

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

Integrating System to Edge-of-Network Architecture and Management for SHINES (SEAMS) Technologies of High Penetration Grids

Consistent with the U.S. DOE’s EERE SHINES FOA objectives, the goal of this project was to enable integration from EMS to variable DER in a way that delivered visibility and opportunities for managing and controlling distributed resources using SEAMS technologies. This project implemented several SHINES technologies, which included: (1) three Stem battery systems; (2) six ConnectDER PV collars; (3) two E-Gear PV/Battery storage interfaces; and (4) eight Kitu smart inverter emulators. A Siemens Energy IP DEMS was deployed in a development environment and integrated with the SHINES technologies via OpenADR and IEEE 2030.5 protocols with documented architecture. In the case of IEEE 2030.5, a suite of technologies including a gateway, an API, software and a server from Kitu Systems (the Citadel, Convoy, Kitu Crosslink API, and Kitu Spark) were used to demonstrate that the utility could achieve visibility of distributed energy resources (DER) and control of single and multiple DER systems with a single command. The project also included a LCOE analysis of SHINES technologies compared to traditional system and circuit mitigation measures.

14 SOLAR ENERGY↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Distributed Intrusion Detection System using Semantic-based Rules for SCADA in Smart Grid

Cyber-physical system (CPS) security for the smart grid enables secure communication for the SCADA and wide-area measurement system data. Power utilities world-wide use various SCADA protocols, namely DNP3, Modbus, and IEC 61850, for the data exchanges across substation field devices, remote terminal units (RTUs), and control center applications. Adversaries may exploit compromised SCADA protocols for the reconnaissance, data exfiltration, vulnerability assessment, and injection of stealthy cyberattacks to affect power system operation. In this paper, we propose an efficient algorithm to generate robust rule sets. We integrate the rule sets into an intrusion detection system (IDS), which continuously monitors the DNP3 data traffic at a substation network and detects intrusions and anomalies in real-time. To enable CPS-aware wide-area situational awareness, we integrated the methodology into an open-source distributed-IDS (D-IDS) framework. The D-IDS facilitates central monitoring of the detected anomalies from the geographically distributed substations and to the control center. The proposed algorithm provides an optimal solution to detect network intrusions and abnormal behavior. Different types of IDS rules based on packet payload, packet flow, and time threshold are generated. Further, IDS testing and evaluation is performed with a set of rules in different sequences. The detection time is measured for different IDS rules, and the results are plotted. All the experiments are conducted at Power Cyber Lab, Iowa State University, for multiple power grid models. After successful testing and evaluation, knowledge and implementation are transferred to field deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

Using advanced data structures to enable responsive security monitoring

Write-optimized data structures (WODS), offer the potential to keep up with cyberstream event rates and give sub-second query response for key items like IP addresses. These data structures organize logs as the events are observed. To work in a real-world environment and not fill up the disk, WODS must efficiently expire older events. As the basis for our research into organizing security monitoring data, we implemented a tool, called Diventi, to index IP addresses in connection logs using RocksDB (a write-optimized LSM tree). In this work, we extended Diventi to automatically expire data as part of the data structures’ normal operations. We guarantee that Diventi always tracks the N most recent events and tracks no more than N + k events for a parameter k < N, while ensuring the index is opportunistically pruned. To test Diventi at scale in a controlled environment, we used anonymized traces of IP communications collected at SuperComputing 2019. We synthetically extended the 2.4 billion connection events to 100 billion events. We tested Diventi vs. Elasticsearch, a common log indexing tool. In our test environment, Elasticsearch saw an ingestion rate of at best 37,000 events/s while Diventi sustained ingestion rates greater than 171,000 events/s. Our query response times were as much as 100 times faster, typically answering queries in under 80 ms. Furthermore, we saw no noticeable degradation in Diventi from expiration. We have deployed Diventi for many months where it has performed well and supported new security analysis capabilities.

97 MATHEMATICS AND COMPUTING↗

Gold-in-copper at low *CO coverage enables efficient electromethanation of CO 2

The renewable-electricity-powered CO 2 electroreduction reaction provides a promising means to store intermittent renewable energy in the form of valuable chemicals and dispatchable fuels. Renewable methane produced using CO 2 electroreduction attracts interest due to the established global distribution network; however, present-day efficiencies and activities remain below those required for practical application. Here we exploit the fact that the suppression of *CO dimerization and hydrogen evolution promotes methane selectivity: we reason that the introduction of Au in Cu favors *CO protonation vs. C-C coupling under low *CO coverage and weakens the *H adsorption energy of the surface, leading to a reduction in hydrogen evolution. We construct experimentally a suite of Au-Cu catalysts and control *CO availability by regulating CO 2 concentration and reaction rate. This strategy leads to a 1.6× improvement in the methane:H 2 selectivity ratio compared to the best prior reports operating above 100 mA cm -2 . We as a result achieve a CO 2 -to-methane Faradaic efficiency (FE) of (56 ± 2)% at a production rate of (112 ± 4) mA cm -2 .

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Self-Sustainable IoT-Based Remote Sensing Powered by Energy Harvesting Using Stacked Piezoelectric Transducer and Thermoelectric Generator

We propose a self-powered remote multi-sensing system for traffic sensing which is powered by the collective energy harvested from the mechanical vibration of the road caused by the passing vehicles and from the temperature gradient between the asphalt of the road and the soil underneath. A stacked piezoelectric transducer converts mechanical vibrations into electrical energy and a thermoelectric generator harvests the thermal energy from the thermal gradient. Electrical energy signals from the stacked piezoelectric transducer and the thermoelectric generators are converted into usable DC power to recharge the battery using AC-DC and DC-DC converters working simultaneously. The multi-sensing system comprises an embedded system with a microcontroller that acquires data from the sensors and sends the sensory data to an IoT transceiver which transmits the data as RF packets to an ethernet gateway. The gateway converts the RF packets into Internet Protocol (IP) packets and sends them to a remote server. Laboratory and road-testing results showed over 98% sensory data accuracy with the system functioning solely powered by the energy harvested from the alternative energy sources. The successful maximum transmission distance obtained between the IoT, and the gateway was approximately 1 mile, which is a considerable transmission distance achieved in an urban environment. Successful operation of the self-powered multi-sensing system under both laboratory and road conditions contributes considerably to the fields of energy harvesting and self-powered remote sensing systems. The energy flow chart and efficiency for the steps in the system were found to be mechanical power from vehicles to the energy harvester of 0.25%, stacked PZT transducer efficiency was found to be 37%, and for the TEGs the efficiency is 11%. AC-to-DC and DC-to-DC converters’ efficiencies were found to be 90% and 11%. The wireless communication RF transceiver efficiency was found to be 62.5%.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗