Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Technology and Operations”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Aggregate attack surface management for network discovery of operational technology

Interconnectivity has become a substratum of technology as the benefits of data-driven functionality are being realized in nearly all industries. Increased connectivity of Operational Technology (OT) exacerbates cyber risks because Industrial Control Systems (ICS) are becoming exposed to the Internet. These exposures are often done inadvertently through misconfigurations as additional network devices come online. Attack surface management (ASM) platforms can be used to identify vulnerabilities by performing external network discovery over the Internet using web spiders. These web spiders enable big data analytics of Internet of Things (IoT) devices as identifiable information of Internet-exposed equipment are archived in searchable databases that are made publicly available. There are a multitude of ASM service providers on the market. Here, this study was conducted to evaluate several commonly known tools to determine the aggregate attack surface of control systems. Queries were crafted by targeting commonly known manufacturers and communication protocols found in OT networks. Identified devices were that categorized based on technology types. Each query was replicated between several tools to target identical ICS equipment. Findings in this paper suggested a significant variance in the exposures discovered by each tool, but unique contributions were identified for each tool when a merged attack surface was derived. Therefore, all tools should be used in aggregate.

97 MATHEMATICS AND COMPUTING↗

OPERATIONAL TECHNOLOGY BEHAVIORAL ANALYTICS (OTBA) – A DATA-CENTRIC APPROACH FOR REDUCING CYBERSECURITY RISK

This paper provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company at Alabama Power’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.

Black, Clifton↗

Trade-off Analysis of Operational Technologies to Advance Cyber Resilience through Automated and Autonomous Response to Threats

The advancement of cyber resilience requires a preliminary stage of characterizing the trade-off space of mitigation options and how these might affect the stability and determinism of an operational technology (OT). This first step will set the stage for the proper cyber-secure and cyber-resilient design and confirm the affects that can be considered and approved by the OT and the security groups. To provide a baseline for this discussion, this paper provides a consideration of the cyberphysical interactions, possible mitigation steps against certain attacks and their corresponding affects that lend to the security design planning and evaluation process. As an integral part of the proposed scheme this work introduces the concept of systemwide fuzzer, i.e., a tool that manipulates the system state in an effort to determine mitigation response sequences that minimize detriments and maximize benefit in accordance with specified operational requirements.

97 MATHEMATICS AND COMPUTING↗

A Review of Technologies that can Provide a 'Root of Trust' for Operational Technologies

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims at providing a survey of technologies that have the potential to reduce exposure of sensitive networks and equipment to these attacks, thereby improving tamper resistance. The recent advances in the performance and capabilities of these technologies in recent years has increased their potential applications to reduce or mitigate exposure of the supply chain attack pathway. The focus being on providing an analysis of the benefits and disadvantages of smart cards, secure tokens, and elements to provide root of trust. This analysis provides evidence that these roots of trust can increase the technical capability of equipment and networks to authenticate changes to software and configuration thereby increasing resilience to some supply chain attacks, such as those related to logistics and ICT channels, but not development environment attacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Design and operations technologies - Integrating the pieces

As major elements of life-cycle costs (LCC) having critical impacts on the initiation and utilization of future space programs, the areas of vehicle design and operations are reviewed in order to identify technology requirements. Common to both areas is the requirement for efficient integration of broad, complex systems. Operations technologies focus on the extension of space-based capabilities and cost reduction through the combination of innovative design, low-maintenance hardware, and increased manpower productivity. Design technologies focus on computer-aided techniques which increase productivity while maintaining a high degree of flexibility which enhances creativity and permits graceful design changes.

Eldred, C. H.↗

An Overview of the Beacon Monitor Operations Technology

This paper summarizes the end-to-end design of a technology for low cost mission operations. Cost savings is achieved by reducing the total volume of downlinked engineering telemetry by decreasing the frequency of telemetry acquisition and the volume of data received per pass.

Cost Deep Space One Mission beacon monitor↗

The Advanced Technology Operations System: ATOS

Mission control systems supporting new space missions face ever-increasing requirements in terms of functionality, performance, reliability and efficiency. Modern data processing technology is providing the means to meet these requirements in new systems under development. During the past few years the European Space Operations Centre (ESOC) of the European Space Agency (ESA) has carried out a number of projects to demonstrate the feasibility of using advanced software technology, in particular, knowledge based systems, to support mission operations. A number of advances must be achieved before these techniques can be moved towards operational use in future missions, namely, integration of the applications into a single system framework and generalization of the applications so that they are mission independent. In order to achieve this goal, ESA initiated the Advanced Technology Operations System (ATOS) program, which will develop the infrastructure to support advanced software technology in mission operations, and provide applications modules to initially support: Mission Preparation, Mission Planning, Computer Assisted Operations, and Advanced Training. The first phase of the ATOS program is tasked with the goal of designing and prototyping the necessary system infrastructure to support the rest of the program. The major components of the ATOS architecture is presented. This architecture relies on the concept of a Mission Information Base (MIB) as the repository for all information and knowledge which will be used by the advanced application modules in future mission control systems. The MIB is being designed to exploit the latest in database and knowledge representation technology in an open and distributed system. In conclusion the technological and implementation challenges expected to be encountered, as well as the future plans and time scale of the project, are presented.

Kaufeler, J.-F.↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗

Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT)

Module-OT is a bump- in- the- wire solution acting as a secure conduit for data between devices or systems across a network. Using the latest in open-source cryptographic libraries, all defined communications undergo authentication, authorization, and encryption. The core system can be easily installed through industry standard processes, and the use of popular open-source packages allows for it to be customizable customized by the developer community or deployed in unique embedded environments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Shuttle Imaging Radar-C mission operations - Technology test bed for Earth Observing System synthetic aperture radar

The mission operations for the Space Radar Lab (SRL), particularly in the areas of real-time replanning and science activity coordination, are presented. The two main components of SRL are the Shuttle Imaging Radar-C and the X-Band Synthetic Aperture Radar. The Earth Observing System SAR will be a multispectral, multipolarization radar satellite that will provide information over an entire decade, permitting scientists to monitor large-scale changes in the earth's environment over a long period of time.

Trimble, J. P.↗

Model Driven Deception for Defense of Operational Technology Environments

Due to the strong integration of real-world physics, OT deception platforms must operate differently than traditional IT deceptions. For instance, turning off a valve will be detected downstream by other sensors because the flow will reduce and stop. Additionally, controllers and applications leverage data from sensors to send control commands to each other. A believable deception must be integrated with the system to project the effects of events. An attack will likely attempt to control the physical process in a negative manner. To make the attacker believe they are achieving their objective, it must predict the effects of these actions, to a reasonable degree. Our approach to simulating a model to generate realistic decoy behavior is explored including description of two approaches: a physics model-based approach and a data driven approach. The performance of two machine learning techniques are investigated in their ability to learn a good enough model of the physics of the system.

97 MATHEMATICS AND COMPUTING↗

Network Slicing for Federated Learning in Operational Technology Environment

Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments are essential to modern infrastructure, facing challenges in ensuring low-latency, high-throughput communication while mitigating cyber threats. This paper presents a framework integrating Federated Learning (FL) and network slicing with Quality of Service (QoS) to enable real-time monitoring without disrupting OT operations. Leveraging digital twin technology and Network Function Virtualization (NFV), the architecture supports predictive analytics and Industry 4.0 requirements. FL facilitates decentralized model training, preserving data privacy and scalability, though it introduces potential throughput constraints. Network slicing addresses this by creating dedicated virtualized segments optimized for performance and security. Advanced fault tolerance at the container and instance levels enhances system reliability. The proposed architecture ensures high throughput, low latency, and secure orchestration for real-time anomaly detection in OT networks. Performance evaluations validate its efficiency in throughput, deployment, and learning accuracy, providing a robust foundation for future ICS automation and data-driven decision-making.

Delgado, Brian G. Rodiles [University of Texas at ↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗

On-orbit demonstration of automated closure and capture using ESA-developed proximity operations technologies and an existing, serviceable NASA Explorer Platform spacecraft

The European Space Agency (ESA) has been working to develop an autonomous rendezvous and docking capability since 1984 to enable Hermes to automatically dock with Columbus. As a result, ESA with Matra, MBB, and other space companies have developed technologies that are also directly supportive of the current NASA initiative for Automated Rendezvous and Capture. Fairchild and Matra would like to discuss the results of the applicable ESA/Matra rendezvous and capture developments, and suggest how these capabilities could be used, together with an existing NASA Explorer Platform satellite, to minimize new development and accomplish a cost effective automatic closure and capture demonstration program. Several RV sensors have been developed at breadboard level for the Hermes/Columbus program by Matra, MBB, and SAAB. Detailed algorithms for automatic rendezvous, closure, and capture have been developed by ESA and CNES for application with Hermes to Columbus rendezvous and docking, and they currently are being verified with closed-loop software simulation. The algorithms have multiple closed-loop control modes and phases starting at long range using GPS navigation. Differential navigation is used for coast/continuous thrust homing, holdpoint acquisition, V-bar hopping, and station point acquisition. The proximity operation sensor is used for final closure and capture. A subset of these algorithms, comprising the proximity operations algorithms, could easily be extracted and tailored to a limited objective closure and capture flight demonstration.

Hohwiesner, Bill↗

Reconfigurable Network Slicing Orchestration in Network Function Virtualization Compatible Operational Technology Environment

The ongoing transition to Industry 4.0, which is characterized by increased inter-connectivity of cyber-physical systems, requires having time-sensitive, high throughput, and secure transfer of critical data in industrial sites. In this context, network slicing emerges as a critical tool to ensure timely data delivery by provisioning the network resources to cater to specific applications’ requirements and mitigating potential cyber attacks. To address these challenges, this paper aims to tackle two key questions essential for the successful implementation of network slicing in industrial environments. First, it investigates architectural considerations for developing a network infrastructure capable of supporting network slicing functionalities effectively. The proposed approach significantly improves deployment efficiency over traditional manual configurations. Second, it delves into the automated orchestration process, elucidating the steps and components involved in transitioning from a static network management approach to dynamically leverage network function virtualization schemes for creating network slices in ad-hoc manner. The system demonstrates high throughput suitable for production-level solutions and maintains exceptionally low latency, making it ideal for ultra-reliable low-latency communications. Even with increased network demands, the system remains stable, with effective Quality of Service (QoS) management, ensuring reliable performance under varying conditions. The proposed architecture outlines the necessary components, services, and communication protocols required for a production-level orchestrator for network segmentation in SCADA environments.

Rodiles Delgado, Brian G.↗