Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Scalable Data Center Capacity for DOE's AI Prototype: A Rapidly Available Gigawatt Data Center for DOE

The multilaboratory Gigawatt Data Center working group was commissioned to identify approaches to rapidly establish federal data centers with scalable capacities up to 1,000 MW. These state-of-the-art facilities will serve as hubs for interdisciplinary collaboration, industry partnerships, and transformative applications of artificial intelligence. The proposed strategic shift includes facilitating multilaboratory collaboration, prioritizing operational efficiency, expanding public–private partnerships, optimizing investments, ensuring long-term contractual flexibility, supporting open science and secure data enclaves, and exploiting high-speed national networks. Owing to their extensive experience and best practices, the US Department of Energy national laboratories are uniquely positioned to lead this initiative. We recommend conducting a feasibility analysis to rapidly identify the optimal sites for this initiative, and the effort will likely involve private industry for design, construction, financing, and operational integration. We also propose establishing multiple geographically diverse sites to ensure energy resilience, high operational reliability, and a diverse user base, thereby effectively addressing the nation’s critical needs.

42 ENGINEERING↗

Energy Resilience for Mission Assurance, Agile Co-simulation for Cyber Energy System Security (ACCESS) Model Advancements for Resilience Analysis (Version 3, July 2023)

Agile Co-simulation for Cyber Energy System Security (ACCESS) is a co-simulation platform developed by Lawrence Livermore National Laboratory (LLNL). The primary high-level use-case for ACCESS is to study existing or new cyber-physical critical infrastructure systems, with a heavy emphasis on 1) systems that utilize communication networks, and 2) studies that seek to understand cyber-related system impacts. ACCESS is currently used for several energy system resilience projects at LLNL. In the Energy Resilience for Mission Assurance (ERMA) project, ACCESS is used in the Mod eling for Metric Calculation task (specifically, subtask 4.3, Communications and Cyber Modeling) to model and simulate the cyber and communication system aspects of Defense Critical Electric Infrastructure (DCEI) systems, with a focus on computing specific communication system metrics that can impact system resilience and mission performance. Simulated communication system per formance will be fed back to other ERMA system components so that mission performance can be evaluated holistically. This report describes several enhancements to the ACCESS platform that were implemented during the execution of the ERMA project in support of reslience analysis. This includes the addition of new models and subsystems, enhancements to existing models, and integration with external systems. The remainder of this report is structured as follows. In Section 2, a brief background description of the ACCESS platform is provided, including an outline of ACCESS components, example use cases, and a set of communication network resilience metrics that can be computed with ACCESS. Section 3 describes the ACCESS model enhancements for ERMA in detail. Finally, Section 4 briefly outlines future integration opportunities between ACCESS and project participant capabilities identified during the progression of the project.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Bayesian OED for Seismic Monitoring

SAND2024-13870O The Bayesian OED (Optimal Experiment Design) for Seismic Monitoring code provides the tools to analyze and optimize seismic monitoring networks using Bayesian OED. This method designs a utility function for experiments (network designs) using network analysis and network optimization. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Catanach, Thomas↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

HPC and Cloud Convergence Beyond Technical Boundaries: Strategies for Economic Sustainability, Standardization, and Data Accessibility

At the IEEE/ACM International Conference for High-Performance Computing, Networking, Storage, and Analysis (SC23), held in Denver, experts discussed the convergence of high-performance computing and cloud computing. Experts explored how this integration could address current scientific computing limitations, enhance computational capabilities, and foster global collaboration while focusing on economic, security, technical, and community challenges and opportunities.

97 MATHEMATICS AND COMPUTING↗

CIE Analysis Process for Engineered Systems

"CIE Analysis Process for Engineered Systems" outlines a comprehensive methodology for integrating Cyber-Informed Engineering (CIE) principles into both new and existing engineered systems. Sponsored by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER), the process aims to achieve cyber-informed decisions by producing functional security requirements for new systems and retrofitting existing systems to mitigate digital risks. The document details a step-by-step approach, including mission and function definition, digital asset awareness, consequence analysis, and mitigation analysis. It emphasizes the importance of documenting mechanical, electrical, programmable, and network components to protect system functions and provides examples and considerations for each step. The ultimate goal is to ensure that engineered systems remain resilient against cyber threats, maintaining safety, performance, and reliability.

42 - ENGINEERING↗

Implementation Aspects of Smart Grids Cyber-Security Cross-Layered Framework for Critical Infrastructure Operation

Communication networks in power systems are a major part of the smart grid paradigm. It enables and facilitates the automation of power grid operation as well as self-healing in contingencies. Such dependencies on communication networks, though, create a roam for cyber-threats. An adversary can launch an attack on the communication network, which in turn reflects on power grid operation. Attacks could be in the form of false data injection into system measurements, flooding the communication channels with unnecessary data, or intercepting messages. Using machine learning-based processing on data gathered from communication networks and the power grid is a promising solution for detecting cyber threats. In this paper, a co-simulation of cyber-security for cross-layer strategy is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection as well as identification of anomalies in the operation of the power grid. The framework is implemented on the IEEE 118-bus system. The system is constructed in Mininet to simulate a communication network and obtain data for analysis. A distributed three controller software-defined networking (SDN) framework is proposed that utilizes the Open Network Operating System (ONOS) cluster. According to the findings of our suggested architecture, it outperforms a single SDN controller framework by a factor of more than ten times the throughput. This provides for a higher flow of data throughout the network while decreasing congestion caused by a single controller’s processing restrictions. Furthermore, our CECD-AS approach outperforms state-of-the-art physics and machine learning-based techniques in terms of attack classification. The performance of the framework is investigated under various types of communication attacks.

cross-layered↗

Securely Aggregated Coded Matrix Inversion

Coded computing is a method for mitigating straggling workers in a centralized computing network, by using erasure-coding techniques. Federated learning is a decentralized model for training data distributed across client devices. In this work we propose approximating the inverse of an aggregated data matrix, where the data is generated by clients; similar to the federated learning paradigm, while also being resilient to stragglers. To do so, we propose a coded computing method based on gradient coding. We modify this method so that the coordinator does not access the local data at any point; while the clients access the aggregated matrix in order to complete their tasks. Here, the network we consider is not centrally administrated, and the communications which take place are secure against potential eavesdroppers.

97 MATHEMATICS AND COMPUTING↗

Fracture Network Prediction Using Physics-based Machine Learning Algorithms

In recent years, systematic CO2 injection into geological reservoirs across the U.S. has gained traction as a strategy to mitigate greenhouse gas emissions. This approach necessitates precise monitoring to ensure secure containment, minimize risks, and optimize storage management. Our study leverages machine learning (ML) techniques to advance the understanding of CO2 injection processes, focusing on the Illinois Basin. Over a three-year injection period, we analyzed microseismic data, identifying 19 temporal intervals with significant bottom-hole pressure changes. By partitioning microseismic events into these intervals and estimating b-values, we revealed over 100 clusters of events related to fracture initiation or reactivation. Advanced spatial analysis highlighted horizontally-oriented fractures along the NNW-SSE axis. This quantification of fracture networks informs dynamic injection scheduling, work-over strategies, and risk assessments, enhancing carbon capture, utilization, and storage (CCUS) operations. Additionally, our methodology offers valuable insights for oil and gas operations and geothermal development, supporting fracture-based monitoring and risk mitigation.

Kumar, Abhash↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Securing Inverter Communication: Proactive Intrusion Detection and Mitigation System to Tap, Analyze, and Act

The electric grid has undergone rapid, revolutionary changes in recent years; from the addition of advanced smart technologies to the growing penetration of distributed energy resources (DERs) to increased interconnectivity and communications. However, these added communications, access interfaces, and third-party software to enable autonomous control schemes and interconnectivity also expand the attack surface of the grid. To address the gap of DER cybersecurity and secure the grid-edge to motivate a holistic, defense-in-depth approach, a proactive intrusion detection and mitigation system (PIDMS) device was developed to secure PV smart inverter communications. The PIDMS was developed as a distributed, flexible bump-in-the-wire (BITW) solution for protecting PV smart inverter communications. Both cyber (network traffic) and physical (power system measurements) are processed using network intrusion monitoring tools and custom machinelearning algorithms for deep packet analysis and cyber-physical event correlation. The PIDMS not only detects abnormal events but also deploys mitigations to limit or eliminate system impact; the PIDMS communicates with peer PIDMSs at different locations using the MQTT protocol for increased situational awareness and alerting. The details of the PIDMS methodology and prototype development are detailed in this report as well as the evaluation results within a cyber-physical emulation environment and subsequent industry feedback.

14 SOLAR ENERGY↗

Cybersecurity Assessment in DER-rich Distribution Operations: Criticality Levels and Impact Analysis

The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.

Maharjan, Manisha↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

Development of a Cloud-based Application to Enable a Scalable Risk-informed Predictive Maintenance Strategy at Nuclear Power Plants

Light-water reactor operations and maintenance (O&M) costs are prohibitively high, thus contributing to the premature decommissioning of nuclear power plants (NPPs). This is partly due to how the equipment is monitored. In recent years, cloud computing has emerged as a dominant technology by virtue of its low costs, computing and storage adaptability, and ability to host applications over numerous types of virtual infrastructures. Cloud computing can be a cost-effective alternative to onsite storage and diagnostics. This paper conducts a techno-economic assessment of a provisional cloud deployment architecture for a NPP predictive monitoring (PdM) system. The cloud-based monitoring system would enable maintenance and diagnostics (M&D) analysts and other authorized plant users to remotely monitor equipment functionality so as to enable PdM practices and early detection of faults. The Microsoft Azure cloud platform is included in the proposed cloud architecture to provide data processing and storage, sensor device networking, and database management; however, this analysis could be extended to other cloud computing service providers as well. For the techno-economic assessment, technical feasibility is measured in terms of network performance metrics such as response time, latency, and throughput, whereas economic feasibility is measured in terms of operational costs and capital expenditures. Finally, this report covers certain regulatory and security aspects that may concern licensees looking to implement cloud computing. The report focuses on the integration of sensor database storage, the application of cloud resources to PdM, and the identification of technological and economic hurdles associated with moving to a cloud-computing-based architecture.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

Mapping Critical Vulnerabilities in Natural Gas Pipeline Systems through Network Centrality and GIS Analytics

Natural gas plays a central role in the US energy landscape, providing 43% of electricity generation in 2023. Its exclusive recovery ability on pipelines for transmission underscores the importance of understanding the disruption recovery ability of this infrastructure. This study employs a network-based analytical framework integrating geographic information systems (GIS) with multiple centrality measures—betweenness, closeness, degree, and eigenvector—to pinpoint key segments and evaluate the structural robustness of the national pipeline network. Pipelines are grouped by System ID and Operator ID to capture variations across organizational and physical structures. The analysis reveals uneven patterns of network influence, where certain pipelines function as critical connectors or dominant hubs. Spatial mapping highlights geographic dependencies and potential chokepoints, offering a clear view of where targeted risk prevention measures would be most effective. The findings provide practical guidance for prioritizing maintenance, enhancing system robustness, and mitigating risks to ensure a stable and secure energy supply. Future research will expand the framework to incorporate dynamic operational data and real-time network behavior.

Peterson, Steven [ORNL] (ORCID:0000000287672998)↗