Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “defense strategy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Detection of Stealthy False Data Injection Attacks in Unobservable Distribution Networks

In this paper, a composite scheme is proposed for detecting stealthy data manipulation attacks on distribution system which is unobservable with standard least squares based state estimators. This technique has three stages where the process of data imputation, voltage phasor estimation and the bad data detection are carried out in a systematic manner. The proposed approach is then integrated with moving target defense strategies which perturbs the network parameters to reveal stealthy false data injection attacks. The proposed approach is tested is validated on a three-phase, unbalanced 37-node distribution system and its results are presented. It is shown that the proposed approach has the ability to accurately detect the presence of FDI attacks using limited measurements (i.e., the test system is unobservable).

Rajasekaran, James K.↗

HUMAN-ARTIFICIAL INTELLIGENCE TEAMING FOR THE U.S. NAVY: DEVELOPING A HOLISTIC RESEARCH ROADMAP

With the ever-increasing deluge of data and demand for warfighters to make decisions upon its analysis, U.S. defense strategy has prioritized the development of artificial intelligence (AI)/machine learning (ML) systems that can analyze multi-source data streams and suggest courses of action. However, there is a history of systems that have failed to be adopted by the warfighter due not only to unsolved technical challenges, but also a lack of usability or contributions to mission effectiveness, perceived or otherwise. To avoid this, research into human-AI teaming shows promise for developing AI systems that work with frontline operators. A recent National Academies of Sciences, Engineering, and Medicine report (NASEM, 2022) presented 57 research objectives in this area; however, the U.S. Navy requires a more-focused set of priorities, as it is impossible to tackle every priority. A workshop involving 23 human factors scientists, computer scientists, and active-duty sailors was organized at the Naval Information Warfare Center Pacific, resulting in a set of five research priorities spanning near-, mid-, and far-term time frames. This panel will summarize the results of this workshop, with a focus on the big questions both going into this workshop and coming out of it. The panel participants come from government, academia, and industry, providing perspective from the different kinds of organizations required to accomplish these research goals.

Wong, Jason↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

You Can't Spell Integrated Deterrence Without 'E'

Instruments of national power include DIME (Diplomatic, Information, Military, and Economic). In light of the 2022 National Defense Strategy, when considering a fully integrated deterrence model, the US must leverage each and every one of these instruments; and in the case of China, especially the economic ‘E’. This paper highlights the current problems with the Sino-American economic relationship and proposes a solution that will enhance the competitive position and national power of the US.

99 GENERAL AND MISCELLANEOUS↗

Assessment of the High Flux Isotope Reactor Cybersecurity Initiative

Recent cyber-attacks on industrial control systems, and inadvertent exposure of nuclear plant systems to cyber-exploits underscore the need for plant operators to adopt and deploy cyber-security defense solutions made for industrial control systems. Of increasing concern is the fact that international cyber hackers are beginning to target critical infrastructure, and because these more modern controls systems depend on advanced use of digital systems, they are more vulnerable than ever before to cyber-attacks. Traditional cyber defense strategies and products that have been available for decades are tailored for use on IT or corporate networks but can cause interruptions and catastrophic damage when deployed on industrial control system networks. The Department of Energy (DOE) Office of Nuclear Energy established the Gateway for Accelerated Innovation in Nuclear (GAIN) program to provide private companies pursuing innovative nuclear energy technologies with access to the technical support necessary to move toward commercialization. One of these GAIN small business vouchers was awarded to Dragos, Inc. to enable collaboration with Oak Ridge National Laboratory (ORNL) to evaluate the Dragos Platform on a production nuclear reactor test bed, hence laying the path for future commercial adoption. The vision was to provide a guide for industrial operators on implementing an industrial monitoring solution and to show how these solutions can be deployed without causing safety and reliability issues. This report documents the results of the collaboration between ORNL and Dragos, Inc.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Science & Technology Review (April/May 2023)

NASA’s Double Asteroid Redirection Test (DART), featured beginning on p.4, has been a testament to Lawrence Livermore’s multidisciplinary expertise. For DART, the Laboratory developed planetary defense strategies, modeled materials and impacts, and utilized advanced machine learning to create and evaluate multitudes of impact scenarios—informing prediction and analysis of the intercept of a small spacecraft with a much larger asteroid of unknown properties. The success of the project heralds a bright future for space science and security work at the Laboratory.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Los Alamos National Laboratory Director's Strategic Resilience Initiative

The Director’s Strategic Resilience Initiative was created late in 2019 in recognition of the changing geo-political climate. The renewed strategic competition between Russia, China, and the United States, noted in the 2018 National Defense Strategy and the 2018 Nuclear Posture Review, put great power rivalry and competition at the forefront of national security considerations. At the same time, Russian President Vladimir Putin’s March 1, 2018, speech and China’s October 1, 2019, National Day Military Parade, underscored the nuclear dimensions of this new strategic competition. Accompanying this changed strategic environment are rapid advances in an expansive array of relevant technological sectors including affordable and comprehensive global communication and reconnaissance assets, autonomous vehicles, quantum computing, advanced manufacturing, and artificial intelligence.

99 GENERAL AND MISCELLANEOUS↗

Generative Artificial Intelligence Tools for Red Teams

This document analyzes the role of Generative Artificial Intelligence (GenAI) tools in cybersecurity, particularly for red teaming. While GenAI accelerates initial security assessments, its effectiveness wanes with complexity, necessitating experienced assessors. The review critiques marketing claims, highlights ethical concerns regarding uncensored models for cybercrime, and advocates for a robust defense strategy supported by skilled professionals.

97 MATHEMATICS AND COMPUTING↗

In Search of Strategic Advantage: Understanding the Landscape of Technology Competition

In an era of seemingly ever-increasing global tensions, technology competition is often mentioned as a pathway for U.S. and allied success. The opening arguments are often very simple. “This is the most important struggle of the 21st century.” “We cannot afford to lose this competition.” “The United States must not fall behind in this race.” “We must be faster, more agile, more committed, more thoughtful than our competitors.” Competition around a particular technology is described as a once in a generational struggle with immense stakes. “This is a Sputnik moment” is a common analogy. The solutions proposed are fairly straightforward – more of everything. We should spend more money. We should build more widgets or more factories. We should innovate more. We should focus more. We should attract more talent. We should file more patents. We should produce more PhDs. If we do more of everything, we will have more technology than our opponents, they will see our technological advantage, they will not challenge us, and therefore we will win. If we fail to do these things, we will lose. To paraphrase Homer Simpson, in national security policy discussions technology competition has become the cause of, and solution to, all of life’s problems. And yet, beyond doing more across the board technology competition is not at all simple. First, it is a concept increasingly muddled together with other big issues such as innovation policy, national defense strategy, great power competition, allied cooperation, public-private partnerships, and a host of other issues. Certain policies, systems, coalitions, and so on may be excellent for tackling one challenge, but far less optional for others. Second, it is inherently dynamic, an action-reaction cycle between multiple players. A brilliant opening move can be squandered or successfully countered in subsequent moves. Third, there are limits to what you can do - limited time, limited financial resources, limited human capital, and limited knowledge of what lies ahead. One is forced to choose.

99 GENERAL AND MISCELLANEOUS↗

Cybersecurity Considerations for Grid-Connected Batteries with Hardware Demonstrations

The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.

25 ENERGY STORAGE↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗

Lunar dust transport and potential interactions with power system components

The lunar surface is covered by a thick blanket of fine dust. This dust may be readily suspended from the surface and transported by a variety of mechanisms. As a consequence, lunar dust can accumulate on sensitive power components, such as photovoltaic arrays and radiator surfaces, reducing their performance. In addition to natural mechanisms, human activities on the Moon will disturb significant amounts of lunar dust. Of all the mechanisms identified, the most serious is rocket launch and landing. The return of components from the Surveyor 3 provided a rare opportunity to observe the effects of the nearby landing of the Apollo 12 Lunar Module. The evidence proved that significant dust accumulation occurred on the Surveyor at a distance of 155 m. From available information on particle suspension and transport mechanisms, a series of models was developed to predict dust accumulation as a function of distance from the lunar module. The accumulation distribution was extrapolated to a future Lunar Lander scenario. These models indicate that accumulation is expected to be substantial even as far as 2 km from the landing site. Estimates of the performance penalties associated with lunar dust coverage and photovoltaic arrays are presented. Because of the lunar dust adhesive and cohesive properties, the most practical dust defensive strategy appears to be the protection of sensitive components from the arrival of lunar dust by location, orientation, or barriers.

Katzan, Cynthia M.↗

Asteroid Redirect Robotic Mission: Robotic Boulder Capture Option Overview

The National Aeronautics and Space Administration (NASA) is currently studying an option for the Asteroid Redirect Robotic Mission (ARRM) that would capture a multi-ton boulder (typically 2-4 meters in size) from the surface of a large (is approximately 100+ meter) Near-Earth Asteroid (NEA) and return it to cislunar space for subsequent human and robotic exploration. This alternative mission approach, designated the Robotic Boulder Capture Option (Option B), has been investigated to determine the mission feasibility and identify potential differences from the initial ARRM concept of capturing an entire small NEA (4-10 meters in size), which has been designated the Small Asteroid Capture Option (Option A). Compared to the initial ARRM concept, Option B allows for centimeter-level characterization over an entire large NEA, the certainty of target NEA composition type, the ability to select the boulder that is captured, numerous opportunities for mission enhancements to support science objectives, additional experience operating at a low-gravity planetary body including extended surface contact, and the ability to demonstrate future planetary defense strategies on a hazardous-size NEA. Option B can leverage precursor missions and existing Agency capabilities to help ensure mission success by targeting wellcharacterized asteroids and can accommodate uncertain programmatic schedules by tailoring the return mass.

Mazanek, Daniel D.↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

PSA 2025 DPRA for Cyber Optimization

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Evaluating defense options should include quantitative evaluation of overall effectiveness to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation and have difficulty with time dependent scenarios. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related integrity is a requirement set by the U.S. Nuclear Regulatory Commission. But companies are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want reliability analysis while optimizing cost, which requires more than safety modeling methods. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with timing and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues such as state-base explosion found in Markov-based tools. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies.

97 - MATHEMATICS AND COMPUTING↗

Autonomous Cyber Defense Against Dynamic Multi-strategy Infrastructural DDoS Attacks

Dynamic Infrastructural Distributed Denial of Service (I-DDoS) attacks constantly change attack vectors to congest core backhaul links and disrupt critical network availability while evading end-system defenses. To effectively counter these highly dynamic attacks, defense mechanisms need to exhibit adaptive decision strategies for real-time mitigation. This paper presents a novel Autonomous DDoS Defense framework that employs model-based reinforcement agents. The framework continuously learns attack strategies, predicts attack actions, and dynamically determines the optimal composition of defense tactics such as filtering, limiting, and rerouting for flow diversion. Our contributions include extending the underlying formulation of the Markov Decision Process (MDP) to address simultaneous DDoS attack and defense behavior, and accounting for environmental uncertainties. We also propose a fine-grained action mitigation approach robust to classification inaccuracies in Intrusion Detection Systems (IDS). Additionally, our reinforcement learning model demonstrates resilience against evasion and deceptive attacks. Evaluation experiments using real-world and simulated DDoS traces demonstrate that our autonomous defense framework ensures the delivery of approximately 96 - 98% of benign traffic despite the diverse range of attack strategies.

Dutta, Ashutosh↗

Digital Biosecurity Pilot Project

Security models for the bioeconomy have largely been developed on risk profiles borrowed from the financial industry and, in some cases, industrial control systems. The bioeconomy, however, has unique characteristics that require domain-specific knowledge of the risks to environmental, health and economic impact from directly targeted attacks. Key questions need to be assessed and answered for any facility engaged in bioproduction. These include: how much technical information must the attacker possess in order to target a specific process or facility? Which processes cause the largest economic impact if disrupted? Can an attacker lead companies down the wrong path of research, leading to irrecoverable losses of time, resources and capital? Can attackers disrupt venture capital strategies and affect financial returns? What are the resources required to attack key workflows, and subsequently what is the cost of defense? What strategies are effective against such attackers, and what are their cost? Can government provide an active role in assurance of material, process and results for critical bioeconomic infrastructure?

59 BASIC BIOLOGICAL SCIENCES↗