Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber incident”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Software Bill of Materials in the Nuclear Industry

Nuclear power plants (NPP) have thousands of digital assets throughout their facility. Typically, NPPs have asset and configuration management programs that capture the make, model, and version of a component. This information, however, usually only includes first- or second-tier components and does not capture the complete enumeration of software components and their dependencies within operational technology (OT) equipment. As seen with recent cyberattacks, this level of detail is insufficient for identifying if and where an exploitable vulnerability exists within a facility. A software bill of materials (SBOM) provides this detailed enumeration. Further, integrating SBOMs with vulnerability data sources and vulnerability attestation reports can provide improved awareness leading to better cyber risk management and incident response. Preferably, SBOMs are provided by the supplier; however, when an NPP already owns a device, it is less likely they will have a supplier provided-SBOM. Fortunately, SBOMs can be generated on installed digital assets. This paper provides an introduction to the U.S. Department of Energy Office of Nuclear Energy paper titled “Towards Software Bill of Materials in the Nuclear Industry,” which describes the SBOM ecosystem and provides a suggested approach to methodically and seamlessly integrate an SBOM program in an NPP.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Wheelbyte Incident Response [Slides]

Wheelbyte faced some challenges regarding cyber attacks. The company reported possible exfiltration of company and customer data, along with the sudden death of an employee.

97 MATHEMATICS AND COMPUTING↗

Canada-US Blended Cyber-Physical Security Exercise (Final Report)

The Canada-US Blended Cyber-Physical Exercise was a successful, first of its kind, multiorganization and multi-laboratory exercise that culminated years of complex system development and planning. The project aimed to answer three driving research questions, (1) How do cyberattacks support malicious acts leading to theft or sabotage [at a nuclear site]? (2) What are aspects of an effective combined cyber-physical response? (3) How to evaluate effectiveness of that response? Which derived the following primary objectives, 1. The May 2023 Cyber-Physical Exercise shall present a cyber-attack scenario that supports malicious acts leading to theft or sabotage. 2. The May 2023 Cyber-Physical Exercise shall define aspects of an effective combined cyber-physical response. 3. Analysis of the May 2023 Cyber-Physical Exercise shall evaluate the effectiveness of the incident response against pre-established exercise evaluation criteria. 4. Analysis of the May 2023 Cyber-Physical Exercise shall assess the effectiveness of the evaluation criteria itself. 5. Exercises shall be performed in a real-life environment. The team believes these objectives were met, and the evidence will be presented in this report. Due to the novelty of the exercise, there were several lessons learned that will be presented in this report.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

A Typing Discipline for High-Assurance Control Systems

This poster describes a typing discipline for high-assurance industrial systems based on three novel type systems. The first type system, information flow control (IFC), controls the flow of data through the system. The second system, dependent session types, restricts messages exchanged during the execution of a communication protocol to avoid dangerous states. The third system uses dimensional analysis to avoid subtle bugs that adversaries can exploit to cause the system to enter a dangerous state. This poster describes how a combination of these approaches can prevent sophisticated cyber attacks, such as the infamous Stuxnet incident, from occurring. In addition, we provide experimental evidence to support the claim that these approaches can be applied in control systems that are resource-constrained.

42 - ENGINEERING↗

Tensor Text-Mining Methods for Malware Identification and Detection, Malware Dynamics Characterization, and Hosts Ranking

Malware is one of the most persistent and costly cyber threats endangering reputation, confidentiality, integrity, and availability for organizations and national security. Consequently, many of the incident detection and prevention systems, and incident responders have begun to utilize machine learning as a helper in the fight against malware and other cyber threats. However, cyber defenders rely on interpretability and generalizability, yet the popular machine learning methods are black-box and often use traditional supervised solutions that do not generalize to novel malware. Therefore, there is a need to improve the existing solutions. At the same time, the majority of the prior research ignored essential evaluation criteria when reporting the results of their methods, which disables the safe reproducibility of the methods in a production environment. Tensor decomposition, on the other hand, enables interpretable unsupervised analysis of the large-scale data for the discovery of hidden patterns. Our findings, performed on real-world and large-scale experiments, show that tensor factorization-based methods yield performance results that surpasses or competes with existing supervised solutions with the added benefit of interpretability and generalizability. With the ability to analyze complex and large-scale data using tensors, we report results that reflect real-world production environments. We propose to develop new game- changing tools for malware identification and characterization that can trace malware evolution, rank the infected or malicious hosts, and streamline the work of incident response teams, malware analysts, and incident detection and prevention systems.

97 MATHEMATICS AND COMPUTING↗

Automatic recognition of intermittent failures - An experimental study of field data

A methodology is proposed for recognizing the symptoms of persistent problems in large systems. The system error rate is used to identify the error states among which relationships may exist. Statistical techniques are used to validate and quantify the strength of the relationship among these error states. As input, the approach takes the raw error logs containing a single entry for each error that is detected as an isolated event. As output, it produces a list of symptoms that characterize persistent errors. Thus, given a failure, it is determined whether the failure is an intermittent manifestation of a common fault or whether it is an isolated (transient) incident. The technique is shown to work on two CYBER systems and an IBM 3081 multiprocessor system. Comparisons to real failure/repair information obtained from field engineers show that, in about 85 percent of the cases, the error symptoms recognized by this approach correspond to real problems. The remaining 15 percent of the cases, although not directly supported by field data, are confirmed as being valid problems.

Iyer, Ravishankar K.↗

Lessons Learned for Responsible Use of Cloud in the Cirrus Project, Following the CrowdStrike Outage Event

A disruption in CrowdStrike’s Falcon cybersecurity platform on July 19th, 2024, caused worldwide chaos. This event highlights the imperative need for cloud security measures for networks that are critically reliant on cloud technology. This incident negatively impacted air travel, government networks, and critical infrastructure sectors such as hospitals and financial institutions. While no electric utilities had a physical impact, and few had an IT impact, there were issues created by loss of cloud services, and other interrelated industries. For utilities and energy distribution organizations, understanding and mitigating these risks is essential. The Cirrus tool offers a strategic solution engineered to weave cloud integration seamlessly into the fabric of operational management, thereby enhancing resilience and streamlining efficiency in the face of digital challenges.

25 ENERGY STORAGE↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity for Digital Energy Infrastructure : Trends, Threats, and Cyber-Informed Engineering

This presentation discusses the rise in digital energy infrastructure and associated threats. It covers an in-depth risk assessment of digital energy equipment and provides real world examples of threats, vulnerabilities, and known incidents. Research conducted by INL assessing and addressing these risks follows, concluding with a dive into Cyber-Informed Engineering (CIE) and it's application to digital energy infrastructure, using battery energy storage systems (BESS) as an example.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Three-dimensional flow over a conical afterbody containing a centered propulsive jet - A numerical simulation

The supersonic flow field over a body of revolution incident to the free stream is simulated numerically on a large, array processor (the CDC Cyber 205). The configuration is composed of a cone-cylinder forebody followed by a conical afterbody from which emanates a centered, supersonic propulsive jet. The free-stream Mach number is 2, the jet-exit Mach number is 2.5, and the jet-to-free-stream static pressure ratio is 3. Both the external flow and the exhaust are ideal air at a common total temperature. The thin-layer approximation to the time-dependent, compressible, Reynolds-averaged Navier-Stokes equations are solved using an implicit finite-difference algorithm. The data base, of 5 million words, is structured in a 'pencil' format so that efficient use of the array processor can be realized. The computer code is completely vectorized to take advantage of the data structure. Turbulence closure is achieved using an empirical algebraic eddy-viscosity model. The configuration and flow conditions correspond to published experimental tests and the computed solutions are consistent with the experimental data.

Deiwert, G. S.↗

Three-dimensional flow over a conical afterbody containing a centered propulsive jet: A numerical simulation

The supersonic flow field over a body of revolution incident to the free stream is simulated numerically on a large, array processor (the CDC CYBER 205). The configuration is composed of a cone-cylinder forebody followed by a conical afterbody from which emanates a centered, supersonic propulsive jet. The free-stream Mach number is 2, the jet-exist Mach number is 2.5, and the jet-to-free-stream static pressure ratio is 3. Both the external flow and the exhaust are ideal air at a common total temperature.

Deiwert, G. S.↗

Cyber-Threat Assessment for the Air Traffic Management System: A Network Controls Approach

Air transportation networks are being disrupted with increasing frequency by failures in their cyber- (computing, communication, control) systems. Whether these cyber- failures arise due to deliberate attacks or incidental errors, they can have far-reaching impact on the performance of the air traffic control and management systems. For instance, a computer failure in the Washington DC Air Route Traffic Control Center (ZDC) on August 15, 2015, caused nearly complete closure of the Centers airspace for several hours. This closure had a propagative impact across the United States National Airspace System, causing changed congestion patterns and requiring placement of a suite of traffic management initiatives to address the capacity reduction and congestion. A snapshot of traffic on that day clearly shows the closure of the ZDC airspace and the resulting congestion at its boundary, which required augmented traffic management at multiple locations. Cyber- events also have important ramifications for private stakeholders, particularly the airlines. During the last few months, computer-system issues have caused several airlines fleets to be grounded for significant periods of time: these include United Airlines (twice), LOT Polish Airlines, and American Airlines. Delays and regional stoppages due to cyber- events are even more common, and may have myriad causes (e.g., failure of the Department of Homeland Security systems needed for security check of passengers, see [3]). The growing frequency of cyber- disruptions in the air transportation system reflects a much broader trend in the modern society: cyber- failures and threats are becoming increasingly pervasive, varied, and impactful. In consequence, an intense effort is underway to develop secure and resilient cyber- systems that can protect against, detect, and remove threats, see e.g. and its many citations. The outcomes of this wide effort on cyber- security are applicable to the air transportation infrastructure, and indeed security solutions are being implemented in the current system. While these security solutions are important, they only provide a piecemeal solution. Particular computers or communication channels are protected from particular attacks, without a holistic view of the air transportation infrastructure. On the other hand, the above-listed incidents highlight that a holistic approach is needed, for several reasons. First, the air transportation infrastructure is a large scale cyber-physical system with multiple stakeholders and diverse legacy assets. It is impractical to protect every cyber- asset from known and unknown disruptions, and instead a strategic view of security is needed. Second, disruptions to the cyber- system can incur complex propagative impacts across the air transportation network, including its physical and human assets. Also, these implications of cyber- events are exacerbated or modulated by other disruptions and operational specifics, e.g. severe weather, operator fatigue or error, etc. These characteristics motivate a holistic and strategic perspective on protecting the air transportation infrastructure from cyber- events. The analysis of cyber- threats to the air traffic system is also inextricably tied to the integration of new autonomy into the airspace. The replacement of human operators with cyber functions leaves the network open to new cyber threats, which must be modeled and managed. Paradoxically, the mitigation of cyber events in the airspace will also likely require additional autonomy, given the fast time scale and myriad pathways of cyber-attacks which must be managed. The assessment of new vulnerabilities upon integration of new autonomy is also a key motivation for a holistic perspective on cyber threats.

Complex Networks↗

AR4IR (Automated Reasoning for Incident Response) [SWR-24-103]

A basic formal methods tool with the ability to aid and/or automate a utilities’ incidence response and instills confidence that the proposed action satisfies the system’s physical constraints, the organization’s cyber policies, and will not cause violations of technical standards.

Etigowni, Sriharsha [National Renewable Energy Lab↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because it can aid in both cybersecurity analysis and the evaluation of other cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

cyber-physical systems↗

Project: Corbomite - Product: ConsoleWorks REACT

TDi Technologies presents ConsoleWorks REACT, an advanced platform designed to tackle the complexities of cyber and operational risk assessment. This comprehensive solution goes beyond asset-focused approaches by considering the impact of both assets and people have on the security and operation of critical infrastructure, specifically targeting preventing gird mis-operation by evaluating real-time human interaction or commands with critical assets. The hypothesis suggests that by integrating the assessment of user commands into the overall risk assessment process, organizations can make more informed decisions, prioritize resources effectively, and respond promptly to potential threats. This hypothesis forms the basis for the development of a proactive and holistic risk management approach that is more comprehensive and context aware than traditional models which only look at assets, patch levels, configuration and threat intel by collecting that information off the network vs directly from the asset, human, and human interaction all in real-time. ConsoleWorks' unique man-in-the-middle architecture is a key feature that sets it apart in the cybersecurity landscape. This architecture enables the real-time observation, enforcement, and commands or interaction risk transparency of user interaction with critical infrastructure to be risk mitigated and audited as they are aggregated with device and human risk factors for a more comprehensive risk threat score across a device or group of devices. This architecture allows ConsoleWorks to act as a secure intermediary between users and critical assets, monitoring all interactions and ensuring that only authorized commands are sent to the asset to be executed. This not only enhances security but also provides a comprehensive audit trail of all user activities, contributing to compliance efforts and facilitating incident investigation and risk management. By integrating this unique architecture with our comprehensive risk assessment methodology, ConsoleWorks REACT provides a powerful solution for managing cyber and operational risks, enabling organizations to maintain a robust security posture and effectively mitigate potential threats. To that end, the primary objective of this project was to research and develop a robust solution that enables the energy industry to mitigate the risks associated with human actions that can compromise the security or operations of assets critical to energy delivery, generation, transmission and operation. ConsoleWorks REACT plays a pivotal role in achieving this goal by leveraging its unique capabilities to monitor and track all user activity. Through its Zero Trust approach, which emphasizes continuous verification, the platform ensures secure access to assets and serves as the centralized human response and notification platform for addressing cyber and operational issues.

97 MATHEMATICS AND COMPUTING↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because they can aid in both cybersecurity analysis and the evaluation of cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

alfalfa↗

Independent Review of the Proof-of-Concept Cyber100 Compass Cybersecurity Risk Tool

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), and Office of Electricity (OE) commissioned the National Renewable Energy Laboratory (NREL) to develop a method and tool to enable electric utilities to understand and manage the risk of cybersecurity events that can lead to physical effects like blackouts. This tool, called Cyber100 Compass, uses cybersecurity data elicited from cybersecurity experts, then incorporates that data into a tool designed to be usable by cybersecurity non-experts who understand the system itself. The tool estimates dollar-valued risks for a current or postulated future electric power digital control configuration, in order to enable utility risk planners to prioritize among proposed cybersecurity risk mitigation options. With the development of the Cyber100 Compass tool for quantification of future cyber-physical security risks, NREL has taken an initial bold step in the direction of enabling and indeed encouraging electric utilities to address the potential for cybersecurity incidents to produce detrimental physical effects related to electric power delivery. As part of the Cyber100 Compass development process, DOE funded NREL to seek out an independent technical review of the risk methodology embodied in the tool. NREL requested this review from Sandia National Laboratories, and made available to Sandia a very late version of the project report, as well as NREL personnel to provide clarification and to respond to questions. This paper provides the result of the independent review activity.

97 MATHEMATICS AND COMPUTING↗