Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “forensics”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Vulcan-Forge: Architecture and Design of a Multi-Modal Forensic Analysis Plugin for CALDERA

Forge and VULCAN together describe an open-architecture cybersecurity analysis ecosystem that unifies forensic artifact processing, detection engineering, and vulnerability intelligence within integrated platforms. Forge operates as a plugin for MITRE CALDERA, ingesting diverse evidence formats—including EVTX, PCAP/PCAPNG, CSV, JSON, YAML, XML, binaries, and archives—to construct a unified artifact graph enriched with severity scoring, TLP classification, and audit trails. It provides subsystems for artifact parsing, streaming structured-data visualization, NetworkMiner-based packet inspection, PE/.NET binary analysis, and LLM-assisted triage and rule generation, with outputs validated against CCCS-YARA and pySigma schemas. VULCAN complements this by serving as a cybersecurity analyst platform that integrates a Neo4j knowledge graph, Qdrant vector retrieval, SSVC-based triage, and a local LLM to deliver CVE intelligence and forensic analysis through a multi-source ingest pipeline drawing from NVD, CISA KEV, EPSS, MITRE ATT&CK, and CAPEC. Together, they bridge structured threat intelligence with automated forensic analysis and detection workflows.

97 MATHEMATICS AND COMPUTING↗

Cloud forensics and incident response platform

A system, method, and device for cloud forensics and incident response is provided. In an embodiment, a computer-implemented method for performing cloud forensics and incident response includes intercepting, by a cloud incident response module (CIRM), communication between a virtual machine (VM) and a hypervisor. The method also includes extracting, by the CIRM, data from the communication between the VM and the hypervisor according to a forensic policy. Intercepting and extracting the data are transparent to the VM and to the hypervisor. Intercepting and extracting the data are independent of the VM and the hypervisor.

Urias, Vincent↗

Beyond Binary: Automated PLC Memory Forensics through RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and the evolution of industrial control systems (ICS) to adopt Internet-based technologies enhanced productivity, but have inadvertently increased their vulnerability to cyber-based malicious attacks. When an ICS system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies to safeguard against future instances. Memory forensics is critical in the analysis process to ascertain what occurred. To date, approaches to analyze the persistent memory in ICS devices are limited, and almost nonexistent for volatile memory. This paper proposes an automated methodology, COMA, for PLC memory dump analysis using computer vision and deep learning techniques. Specifically, COMA converts the sequences of bytes in a PLC memory dump to RGB pixels and creates a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. COMA then uses the trained model to automatically segment new memory images and extract forensic artifacts. We evaluate COMA on a Schneider Electric Modicon M221 PLC involving two cyber-based attack scenarios: (i) code injection and (ii) code modification. The empirical results show that COMA can successfully detect attack artifacts in memory dumps in both scenarios.

Asmar Awad, Rima↗

Towards generic memory forensic framework for programmable logic controllers

A Programmable Logic Controller (PLC) is a microprocessor-based controller that is used to automate physical processes in critical infrastructure and various other industries and manufacturing sectors. Initially, PLCs were completely isolated from the Internet, and cyber security was not incorporated at the time of development. The introduction of industry 4.0 and the evolution of ICS systems to communicate over public IP addresses from the Internet enhanced productivity and efficiency, but Internet connectivity exposed the systems and their vulnerabilities, which led to an increase in cyber attacks. When a system is sabotaged/compromised, security analysts need to get to the root cause of the attack as quickly as possible to recover the system. To do so, memory forensic analysis is critical to provide a unique insight into the run-time memory activities and extract a reliable source of evidence. In this paper, we analyze the memory structure of the Schneider Electric Modicon M221 PLC. To build a memory profile, we reverse engineer the communication protocol and conduct differential analysis to gain knowledge about the structure of the memory and the low-level representation of control logic instructions. We then identify dynamic and static memory regions by modifying different project fields and conducting differential analysis, which allows us to identify boundaries of critical memory structures and extract important forensic artifacts that can be found in the memory. The Python implementation of the memory profile can help reduce the time and effort required for manual analysis in case of cyber incident or system failure.

97 MATHEMATICS AND COMPUTING↗

Adapting Nuclear Forensics from Light Water to Molten Salt Reactors: A Survey of Emerging Needs

Rising interest in molten salt reactors for commercial power production presents an opportunity to evaluate the techniques used to characterize materials of nuclear forensic interest. Since extensive research has been performed to identify and develop signatures of light water reactor (LWR) materials (e.g. uranium ore concentrates and uranium dioxide fuel pellets), we use this as a basis to explore possibilities for molten salt signature development. Through this comparative method, nuclear forensic signatures used today to identify the provenance of nuclear materials found out of regulatory control are adapted to molten salt reactor (MSR) fuel cycle materials. Radiological, elemental composition, isotopic composition, and model age signatures will likely not need large adaptations before being applied to MSR materials but may need to expand to be applicable to both thorium- and uranium-fueled systems. The liquid nature of molten salt fuel may erase signatures related to production and irradiation history that are informative for typical LWR materials. However, it may also lead to opportunities for new signatures, such as cooling rate–controlled morphology. Targets identified for further research include radiological attributes of fuel salts; elemental, chemical, and isotopic analysis of salts with differing production routes; morphological effects of various thermodynamic environments; and relevant fuel cycle radiochronometers. Additionally, the comparative nature of the proposed signatures implies a need for MSR-relevant databases and the production of salt standard reference materials.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Morphology and particle size (MaPS) exercise: testing the applications of image analysis and morphology descriptions for nuclear forensics

Image analysis techniques have been applied and shown to be a valuable tool in nuclear forensics analysis. The interlaboratory exercise reported here has tested quantitative and qualitative approaches for characterizing nuclear materials. Particle size, surface features and morphology descriptions were compared by four laboratories on a common image set generated by Scanning Electron Microscopy and Digital Light Microscopy. Quantitative analysis of the image sets through the Morphological Analysis for MAterials software highlighted the strength of image analysis, but also that the application of the software alone can introduce significant bias in the analysis. Qualitative morphology descriptions following the process outlined by Tamasi et al. (J Radioanal Nuclear Chem 307:1611–1619, 2015) were compared with a discussion on the robustness and reproducibility of the results. Finally, future work should continue to focus on proficiency and standardization of image analysis through continued exercises within the extended nuclear forensics community.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Updated uranium reference material 231 Pa/ 235 U consensus model ages for nuclear forensics

Radiochronometry provides the model age of nuclear materials, which is useful for understanding the production history of materials found outside of regulatory control. Certified reference materials (CRMs) are important for radiochronometry to increase confidence in measurement quality; however, the absence of 231 Pa/ 235 U CRMs necessitates that nuclear forensic laboratories measure the 231 Pa/ 235 U model ages of preexisting uranium reference materials. Here, in this work, new consensus 231 Pa/ 235 U model ages are reported from three nuclear forensic laboratories for three reference materials using current analytical methods. These updated consensus values can be used for quality control of 231 Pa/ 235 U model age measurements.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Actinide Science for Post Detonation Nuclear Forensic Analyses

Actinide and fission product separations, analyses, and solid material syntheses are key to supporting the development and testing of new nuclear forensic science technologies and for training nuclear emergency responders to effectively respond to nuclear emergency events. In this presentation, nuclear forensic scientist Dr. Mathew Snow will discuss a variety of technologies developed at Idaho National Laboratory (INL) and around the world for these applications. The presentation will include discussions of new approaches to rapid, high-efficiency chemical separations, sample preparation and analysis techniques for field-deployable actinide analyses, and techniques recently developed at INL for producing solid nuclear fallout simulant materials. An overview of the challenges confronting researchers in these area, along with possible opportunities, will also be provided.

Nuclear Forensics↗

Use of carbonyldiimidazole as a derivatization agent for the detection of pinacolyl alcohol, a forensic marker for Soman, by EI-GC–MS and LC-HRMS in official OPCW proficiency test matrices

Pinacolyl alcohol (PA), a key forensic marker for the nerve agent Soman (GD), is a particularly difficult analyte to detect by various analytical methods. In this work, we have explored the reaction between PA and 1,1'-carbonyldiimidazole (CDI) to yield pinacolyl 1H-imidazole-1-carboxylate (PIC), a product that can be conveniently detected by gas chromatography–mass spectrometry (GC–MS) and liquid chromatography-high-resolution mass spectrometry (LC-HRMS). Regarding its GC–MS profile, this new carbamate derivative of PA possesses favorable chromatographic features such as a sharp peak and a longer retention time (RT = 16.62 min) relative to PA (broad peak and short retention time, RT = 4.1 min). Additionally, the derivative can also be detected by LC-HRMS, providing an avenue for the analysis of this chemical using this technique where PA is virtually undetectable unless present in large concentrations. From a forensic science standpoint, detection of this low molecular weight alcohol signals the past or latent presence of the nerve agent Soman (GD) in a given matrix (i.e., environmental or biological). The efficiency of the protocol was tested separately in the analysis and detection of PA by EI-GC–MS and LC-HRMS when present at a 10 μg/mL in a soil matrix featured in the 44th PT and in a glycerol-rich liquid matrix featured in the 48th Official Organization for the Prohibition of Chemical Weapons (OPCW) Proficiency Test when present at a 5 μg/mL concentration. In both scenarios, PA was successfully transformed into PIC, establishing the protocol as an additional tool for the analysis of this unnatural and unique nerve agent marker by GC–MS and LC-HRMS.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Nuclear Forensics in Support of National Response Plans [Slides]

Become familiar with nuclear forensics methodologies in support of nuclear security investigations and how Los Alamos National Laboratory supports the development of sustainable global nuclear forensics capacities.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Summary of Forensic Examinations in Support of Breach Sealed Source Event at Harborview Medical Facility on 2 May 2019

On May 2, 2019, International Isotopes, Inc. (INIS), a subcontractor to Triad National Security, LLC (contractor for Los Alamos National Laboratory) breached a sealed radioactive source containing ~2800 Ci of the radioactive isotope cesium-137 ( 137 Cs) at the University of Washington Harborview Research and Training (HRT) Building in downtown Seattle while attempting to recover the source for the National Nuclear Security Administration’s (NNSA’s) Off-site Source Recovery Program (OSRP). The breach of the source resulted in the contamination of 13 personnel, all 7 floors of the building, and a release of material to the environment. A summary of root and contributing causes of the event was investigated and published by a joint investigation team (JIT) co-led by NNSA and Triad National Security, LLC. That investigation was supported by forensics examinations provided by Pacific Northwest National Laboratory. This report summarizes the results of those forensic examinations.

61 RADIATION PROTECTION AND DOSIMETRY↗

CWMD Nuclear Forensics Quarterly Report

Analysis and evaluation of nuclear debris is a key component to identify forensic signatures in a post-detonation environment. Currently, methods exist and are practiced in obtaining signatures from post-detonation debris. However, efforts to reduce the timeline in obtaining signatures is continuous within nuclear forensics research and will be forwarded by this research. This education and research project will explore combined material chemistry and separations of radionuclides to provide actionable signatures in less time than standard methods. The research will use the phase distribution of radionuclides in debris to develop targeted and rapid dissolution methods. These dissolution methods will be coupled with microfluidics to achieve samples suitable for analysis within reduced timelines.

and nuclear chemistry↗

Hyperspectral x-ray imaging mapping capabilities for nuclear forensics

Nuclear forensics relies on the integration of complementary signatures to constrain the origins and history of materials. Outcomes benefit from the timeliness and precision of the disparate methods that form typical analysis chains. Sample forms are often either minute in quantity or contain signatures like morphology or composition heterogeneity encoded on a microscale, so many analysis techniques focus on resolving signatures on ever-smaller length scales. The new hyperspectral x-ray imaging (HXI) instrument developed at Los Alamos National Laboratory seeks to improve the information available from scanning electron microscopy (SEM) x-ray spectrum analysis through superior spectral energy resolution vs. typical energy dispersive spectroscopy (EDS) systems in common use in nuclear forensics and other microanalysis fields. Based on arrays of transition-edge sensor (TES) microcalorimeter detectors, this instrument achieves a typical energy resolution of 7 eV full-width at half-maximum (FWHM) at 2 keV, opening new possibilities in trace element detection/analysis and chemical state determination through spectral shape shifts. We present here some of the first applications of the HXI instrument to actinide samples and discuss potential maturation of this nascent technology for future analysis pipelines.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Application of Ion Mobility Spectrometry (IMS) in forensic chemistry and toxicology with focus on biological matrices

The IMS (Ion Mobility Spectroscopy) instrument 'Ionscan' takes advantage of the fact that trace quantities of illicit drugs are adsorbed on dust particles on clothes, in cars and on other items of evidence. The dust particles are collected on a membrane filter by a special attachment on a vacuum cleaner. The sample is then directly inserted into the spectrometer and can be analyzed immediately. We show casework applications of a forensic chemistry and toxicology laboratory. One new application of IMS in forensic chemistry is the detection of psilocybin in dried mushrooms without any further sample preparation.

Bernhard, Werner↗

Forensic Analysis of Compromised Computers

Directory Tree Analysis File Generator is a Practical Extraction and Reporting Language (PERL) script that simplifies and automates the collection of information for forensic analysis of compromised computer systems. During such an analysis, it is sometimes necessary to collect and analyze information about files on a specific directory tree. Directory Tree Analysis File Generator collects information of this type (except information about directories) and writes it to a text file. In particular, the script asks the user for the root of the directory tree to be processed, the name of the output file, and the number of subtree levels to process. The script then processes the directory tree and puts out the aforementioned text file. The format of the text file is designed to enable the submission of the file as input to a spreadsheet program, wherein the forensic analysis is performed. The analysis usually consists of sorting files and examination of such characteristics of files as ownership, time of creation, and time of most recent access, all of which characteristics are among the data included in the text file.

Wolfe, Thomas↗

Device-Centric Ransomware Detection using Machine Learning-Based Memory Forensics for Smart Inverters

Ransomware attacks are the fastest-growing form of cyberattacks worldwide. Recently, ransomware attacks have targeted industrial control systems (ICSs), including power grids. Lessons learned from recent incidents in ICSs show that ransomware groups can deliver ransomware into not only the organization’s control servers, but also the operational technology (OT) devices such as smart inverters and smart grid devices. This paper proposes a machine learning (ML)- based memory forensics method enabling the detection of ransomware binaries stored in the memory of a commercial smart inverter. Device firmware binary files are extracted from a Serial Peripheral Interface (SPI) flash memory, and samples of both benign and ransomware binaries are generated by a binary manipulation method and a real-world ransomware encryption, separately. A deep transfer learning (DTL) method is used to retrain a convolutional neural network (CNN)-based ransomware detection algorithm using the generated samples. The experimental result validates that the proposed ML-based memory forensics method can accurately detect ransomware files.

97 MATHEMATICS AND COMPUTING↗

A Machine Learning Method for the Forensics Attribution of Separated Plutonium

Plutonium (Pu) source attribution would be a powerful tool to support nuclear nonproliferation efforts. This capability to find the source of a Pu sample would act as a deterrent to smuggling efforts, and also help regulatory agencies verify declared nuclear activities. Work at Texas A&M University yielded a nuclear forensics methodology, which is capable of determining separated Pu’s reactor of origin, fuel burnup, and the time since irradiation (TSI)—three parameters of interest. The methodology used a set of ten intra-element isotopic ratios found in separated Pu, which was compared to a library of isotopic ratio values produced using neutronics simulations for reactors of interest. By calculating the probability that unknown Pu sample’s isotopic ratio set matched a set in the library, the methodology could predict the three parameters of interest of the sample. One shortcoming of this methodology was an inability to correctly attribute spoofed Pu, where Pu sourced from two different reactors or two different fuel burnup levels are mixed. A new methodology to rectify this vulnerability using machine learning (ML) technique is developed, instead of the maximum likelihood calculation previously used and the results are satisfactory. The ML approach leverages the existing simulated data for training the algorithm, but use them efficiently by only using intra-element isotope ratios that contribute to the attribution one of the three parameters at a time. Previously, all isotope ratios were used to attribute all three parameters together. The new methodology attributes the Pu parameters in three steps, one for each parameter, rather than resolving all of the three parameters simultaneously like the previous maximum likelihood approach. First, a support vector machine classifier with a set of seven isotopic ratios finds the reactor of origin and a set of regression models trained using gaussian process predicts the burnup with a different set of seven isotopes. Finally, TSI is calculated analytically using decay equations. Thus far, the new methodology is capable of attributing pure Pu samples and has been validated using experimental data. The next step will to be augment the classifier training data set with spoofed Pu data.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Exploring the use of thorium isotope compositions and concentrations as nuclear forensic signatures for uranium ore concentrates

This interlaboratory study measured thorium concentrations and isotope compositions in uranium ore concentrates from different geographical locations to examine whether thorium impurities may be useful forensic signatures for uranium ore concentrates found out of regulatory control. Measured 230 Th/ 232 Th in fifteen uranium ore concentrates record over three orders of magnitude of compositional variation. Results demonstrate that 230 Th/ 232 Th used in combination with U/Th ratios resulted in a unique signature for individual uranium ore concentrates from different processing locations. Data presented here suggest potential for 230 Th/ 232 Th and U/Th to be used as comparative signatures to investigate the provenance of seized uranium ore concentrates.

38 RADIATION CHEMISTRY, RADIOCHEMISTRY, AND NUCLEA↗