Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Contingency Analysis Based on Partitioned and Parallel Holomorphic Embedding

In the steady-state contingency analysis, the traditional Newton-Raphson method suffers from non-convergence issues when solving post-outage power flow problems, which hinders the integrity and accuracy of security assessment. In this paper, we propose a novel robust contingency analysis approach based on holomorphic embedding (HE). Here, the HE-based simulator provides theoretical convergence guarantee, which is desirable because it avoids the influence of numerical issues and provides a credible security assessment conclusion. In addition, based on the multi-area characteristics of real-world power systems, a partitioned HE (PHE) method is proposed with an interfacebased partitioning of HE formulation. The PHE method does not undermine the numerical robustness of HE and significantly reduces the computation burden in large-scale contingency analysis. The PHE method is further enhanced by parallel or distributed computation to become parallel PHE (P2HE). Tests on a 458-bus system, a synthetic 419-bus system and a large-scale 21447-bus system demonstrate the advantages of the proposed methods in robustness and efficiency.

42 ENGINEERING↗

Component based approach to modeling for model checking

This paper presents a portion of an overall research project on the generation of a software security assessment instrument to aid developers in assessing and assuring the security of software in the development and maintenance lifecycles.

security toolset model checking security safety fo↗

CLEAP Project: OR-SAGE Analysis for MT, UT, and CO States

The OR-SAGE tool is designed to use industry-accepted practices in screening sites and then employ the proper array of data sources through the considerable computational capabilities of GIS technology available at ORNL. The tool was developed to screen the potential for NPP siting on a national and regional basis. However, because of the tool granularity, it is often focused specifically on the immediate area around user sites of interest. If data center siting parameters can be added to OR-SAGE, the ability to evaluate data center siting on a localized scale will be beneficial.1 More than 60 data sets have been collected and processed by ORNL to develop exclusionary, avoidance, and suitability criteria for screening sites for a variety of power generation types, including nuclear power plants. Available site evaluation parameters include population density, slope, seismic activity, proximity to cooling-water sources, proximity to hazard facilities, avoidance of protected lands and floodplains, susceptibility to landslide hazards, and many others. All siting parameters should be considered as flags to inform siting decisions and should not be used to rule in or rule out any NPP site. Once data center siting parameters are identified, appropriate data sets will be collected and processed. The OR-SAGE process is very versatile. Essentially, OR-SAGE is a visual, relational database. The database partitions the contiguous United States, a total of 720 million hectares (~1.8 billion acres), into 100-m by 100-m (1 hectare or ~2.5 acre) cells. The database is tracking just under 700 million individual land cells. Successive suitability criterion is applied to each cell in the database. User-specified thresholds can be applied to each siting parameter data layer. In this manner, a variety of scenarios can be quickly and thoroughly evaluated. Data can be added and/or revised within OR-SAGE to address user interests. Siting security assessment capability is currently being added to OR-SAGE. Security is expected to be of concern at data centers whether it is collocated with a nuclear power generating technology or not. If data center is collocated with a nuclear power generating source, the security threat attractiveness level of both will likely increase. It will be of additional benefit if a potential data center site is also assessed for security vulnerability.

97 MATHEMATICS AND COMPUTING↗

Methods for the Enhancement of Security Probabilistic Risk Assessments

The US Department of Energy is exploring the methods associated with probabilistic risk assessment (PRA) and how they could be used to enhance physical security evaluations for nuclear facilities. A brief review of both international and US Nuclear Regulatory Commission physical security assessment methods is presented. From this review, and with an understanding of the technical elements associated with a traditional nuclear safety PRA, several observations are made pertaining to where physical security analysis methods could be enhanced. These observations principally support and enhance the answers within a physical security context to the risk triplet: (1) What can go wrong? (2) What is the likelihood? and (3) What are the consequences? Finally, benefits and technical challenges toward the development of a full security PRA are presented.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Model based verification of the Secure Socket Layer (SSL) Protocol for NASA systems

The National Aeronautics and Space Administration (NASA) has tens of thousands of networked computer systems and applications. Software Security vulnerabilities present risks such as lost or corrupted data, information theft, and unavailability of critical systems. These risks represent potentially enormous costs to NASA. The NASA Code Q research initiative 'Reducing Software Security Risk (RSSR) Trough an Integrated Approach' offers formal verification of information technology (IT), through the creation of a Software Security Assessment Instrument (SSAI), to address software security risks.

software security↗

Deep Learning Based Frequency Stability Assessment in Power Grid with High Renewables

Frequency stability assessment is one critical aspect of power system security assessment. Traditional N-1 screening method is based on the simulations of a few typical daily and seasonal operation scenarios. However, the increasing integration of inverter-based renewables and the retirement of conventional synchronous generators result in decreasing system inertia and growing complexity of system operating conditions. Selecting a few typical operation scenarios cannot cover all operating conditions, and the time-domain simulation of all operation conditions requires tremendous time. This paper proposes a more efficient frequency stability assessment method based on deep learning. The affinity propagation clustering algorithm is used to divide the dataset into different clusters, so the selected dataset for training can cover the diversified operating conditions as much as possible. Also, feature normalization is applied to both the training dataset and testing dataset in order to remove any unnecessary bias. Especially, trained model based on full dataset normalization has bounded error in the prediction. The case study on the reduced 240-bus WECC system demonstrates that the proposed method can predict accurate frequency nadir with limited training dataset. The deep learning model using the revised feature normalization can predict more accurate frequency nadir than that using the traditional feature normalization and has very small maximum prediction error.

affinity propagation↗

Leverage demand-side policies for energy security

Energy security is a top priority for governments, companies, and households because energy systems and the critical functions that they support are threatened by disruptions from wars, pandemics, climate change, and other shocks (1). More often than not, governments rely on policies focused on energy supply to enhance energy security while generally ignoring demand-side possibilities. Further, the indicators traditionally used to measure energy security are also tilted toward the supply side; this fails to capture the full spectrum of vulnerability to energy crises. Energy security assessments need to reflect the wider benefits of security related interventions more accurately. To that end, we develop a systematic approach to measuring the energy security impacts of policy interventions that explicitly considers energy demand (buildings, transport, and industry). Here, we determine that demand-side actions outperform conventional supply-side approaches at making countries more resilient. Energy demand links more directly than supply to the satisfaction of critical social functions and human well-being that are at the core of energy security. Yet, demand-side perspectives tend to be neglected or underrepresented in analysis and policy debates on energy security. Factors that contribute to this supply-side bias include the traditional sectoral organization of industries and policy institutions along fuels (coal, oil, and gas) and energy forms (electric utilities) as well as the decentralized and multivaried activities characteristic of energy demand (from vehicles to household appliances to manufacturing and more), which leads to a multitude of actors and institutional fragmentation. The basic fundamentals of energy systems and markets, where demand and supply are intricately linked, have also not yet risen from vague awareness to a central organizing principle among policy-makers for structuring the energy security discourse.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cybersecurity and Infrastructure Security Agency (CISA) Infrastructure Security Division (ISD) Assessment Prioritization Project

The Cybersecurity and Infrastructure Security Agency’s Infrastructure Security Division (CISA ISD) manages a diverse portfolio of assessments across the nation’s critical infrastructure sectors. These assessments—ranging in type, scope, and complexity—are essential for identifying vulnerabilities and strengthening national security. However, the wide variation in assessment offerings and the increasing demand for limited resources have highlighted the need for a transparent, structured approach to prioritizing assessment activities. To address this challenge, CISA ISD partnered with Lawrence Livermore National Laboratory (LLNL) to review current assessment methodologies, analyze existing prioritization practices, and develop a comprehensive, national-security-focused prioritization framework. This report summarizes the project’s approach, key findings, and actionable recommendations for enhancing ISD’s assessment program.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Improving the Cyber Resiliency and Security Posture of Public Power (Final Report)

The key objective of Improving the Cyber Resiliency and Security Posture of Public Power (Project) was to develop a culture of cyber resiliency and security within the public power community. The relative smaller size and unique structure of community-owned electric utilities can sometimes present challenges in immediate recognition of threats and the escalation of potential incidents. The Project offered targeted education, coordination, capability building, and resources to help the public power community better understand, install, and implement cyber and physical resiliency and security systems. The American Public Power Association (APPA) accelerated efforts to develop resources for and with the public power community to understand and implement resiliency, cybersecurity and cyber-physical solutions, including refining and improving the adoption of advanced control concepts. The Project consisted of four major multi-pronged tasks which included: 1) Advance cyber resiliency and security assessments; 2) Conduct, evaluate, and use the results of onsite vulnerability assessments; 3) Research, evaluate, deploy, and integrate both commercial and pre-commercial security technologies; and 4) Research, evaluate, and implement information sharing mechanisms.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Requirements and Recommendations for a Physical Attack Characterization Framework

This study seeks to identify existing frameworks or develop requirements and recommendations for a new framework that can consistently characterize physical attacks, analogous to MITRE ATT&CK®. MITRE ATT&CK is widely used across government, research organizations, and the cyber security community to characterize cyber attack tactics, techniques, and procedures (TTPs) in a consistent and commonly understood manner. While physical attack taxonomies, methodologies, and other tools for evaluating physical security do exist, many are sector and/or facility-type specific—and therefore not able to provide comparable scenarios across sectors—or are more focused on security assessment instead of the characterization of attacks themselves. A MITRE ATT&CK analog for physical attacks on critical infrastructure would provide a common language and structure for analysis of physical attacks. Existing attack characterization methodologies do not robustly address cyber-physical security risks. To fully understand a facility’s security needs, it is important to understand the entire vulnerability landscape from both a physical and a cyber perspective. To underscore this need, organizations such as the Cybersecurity and Infrastructure Security Agency (CISA) are calling for a coordinated approach to cyber and physical security, which they refer to as cyber and physical security convergence. A physical attack characterization framework that could be used jointly with MITRE ATT&CK would help support a more robust analysis in support of convergence, enabling the consistent characterization of attacks that utilize both cyber and physical tactics and techniques. This could provide analysts and stakeholders with a clearer understanding of how security mitigations deployed in the physical realm impact security risks in the cyber realm, and vice versa. In this study, the project team evaluates existing physical security taxonomies and methodologies to assess whether an existing method can be used to create a “physical half” of MITRE ATT&CK. This study then provides requirements and recommendations for a framework that can leverage aspects of existing methodologies. The goal of the final framework is for it to be widely adopted and referenced, regardless of critical infrastructure sector, facility type, or facility components. This study also identifies applicable use cases for when and how a framework could be applied across the various critical infrastructure sectors for a variety of attack types or motivations. Through a literature review of existing security-focused methodologies and taxonomies, engagement with relative stakeholders, evaluation of potential physical attack framework use cases, and subsequent identification of requirements, this study identified the following key findings and recommendations: There is a need for a new physical attack characterization framework; A physical attack framework should be interoperable with the MITRE ATT&CK framework; A physical attack framework should be broadly applicable, but with detailed tactics, techniques, and procedures that encompass the entire attack path; A physical attack framework should be based on observed or feasible events; A physical attack framework should adapt features from existing methodologies, frameworks, and taxonomies; A physical attack framework should be owned, overseen, and maintained by one organization.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Tailoring NIST Security Controls for the Ground System: Selection and Implementation -- Recommendations for Information System Owners

The National Aeronautics and Space Administration (NASA) invests millions of dollars in spacecraft and ground system development, and in mission operations in the pursuit of scientific knowledge of the universe. In recent years, NASA sent a probe to Mars to study the Red Planet's upper atmosphere, obtained high resolution images of Pluto, and it is currently preparing to find new exoplanets, rendezvous with an asteroid, and bring a sample of the asteroid back to Earth for analysis. The success of these missions is enabled by mission assurance. In turn, mission assurance is backed by information assurance. The information systems supporting NASA missions must be reliable as well as secure. NASA - like every other U.S. Federal Government agency - is required to manage the security of its information systems according to federal mandates, the most prominent being the Federal Information Security Management Act (FISMA) of 2002 and the legislative updates that followed it. Like the management of enterprise information technology (IT), federal information security management takes a "one-size fits all" approach for protecting IT systems. While this approach works for most organizations, it does not effectively translate into security of highly specialized systems such as those supporting NASA missions. These systems include command and control (C&C) systems, spacecraft and instrument simulators, and other elements comprising the ground segment. They must be carefully configured, monitored and maintained, sometimes for several years past the missions' initially planned life expectancy, to ensure the ground system is protected and remains operational without any compromise of its confidentiality, integrity and availability. Enterprise policies, processes, procedures and products, if not effectively tailored to meet mission requirements, may not offer the needed security for protecting the information system, and they may even become disruptive to mission operations. Certain protective measures for the general enterprise may not be as efficient within the ground segment. This is what the authors have concluded through observations and analysis of patterns identified from the various security assessments performed on NASA missions such as MAVEN, OSIRIS-REx, New Horizons and TESS, to name a few. The security audits confirmed that the framework for managing information system security developed by the National Institute of Standards and Technology (NIST) for the federal government, and adopted by NASA, is indeed effective. However, the selection of the technical, operational and management security controls offered by the NIST model - and how they are implemented - does not always fit the nature and the environment where the ground system operates in even though there is no apparent impact on mission success. The authors observed that unfit controls, that is, controls that are not necessarily applicable or sufficiently effective in protecting the mission systems, are often selected to facilitate compliance with security requirements and organizational expectations even if the selected controls offer minimum or non-existent protection. This paper identifies some of the standard security controls that can in fact protect the ground system, and which of them offer little or no benefit at all. It offers multiple scenarios from real security audits in which the controls are not effective without, of course, disclosing any sensitive information about the missions assessed. In addition to selection and implementation of controls, the paper also discusses potential impact of recent legislation such as the Federal Information Security Modernization Act (FISMA) of 2014 - aimed at the enterprise - on the ground system, and offers other recommendations to Information System Owners (ISOs).

GOVERNANCE↗

Experimental Setup for Grid Control Device Software Updates in Supply Chain Cyber-Security

Supply chain cyberattacks that exploit insecure third-party software are a growing concern for the security of the electric power grid. These attacks seek to deploy malicious software in grid control devices during the fabrication, shipment, installation, and maintenance stages, or as part of routine software updates. Malicious software on grid control devices may inject bad data or execute bad commands, which can cause blackouts and damage power equipment. This paper describes an experimental setup to simulate the software update process of a commercial power relay as part of a hardware-in-the-loop simulation for grid supply chain cyber-security assessment. The laboratory setup was successfully utilized to study three supply chain cyber-security use cases.

Keller, Joseph↗

System security in the space flight operations center

The Space Flight Operations Center is a networked system of workstation-class computers that will provide ground support for NASA's next generation of deep-space missions. The author recounts the development of the SFOC system security policy and discusses the various management and technology issues involved. Particular attention is given to risk assessment, security plan development, security implications of design requirements, automatic safeguards, and procedural safeguards.

Wagner, David A.↗