Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Domestic Extremism (Executive Summary)

Domestic extremism (DE) has been a growing concern in the U.S. in recent months, as illustrated in multiple bulletins from the Department of Homeland Security (DHS) warning law enforcement partners of the heightened threat. As concerns about these actors grows, it is important that facilities in the U.S. and internationally that protect critical assets, such as sensitive information, hazardous materials, or critical infrastructure, have effective methods in place to secure those assets. DE has challenged security systems through the danger of insider attack and violence, creating a new threat to be countered. In this effort, therefore, we used a literature review and focus group discussions with experts in critical asset security and extremism to understand the nature of the domestic extremist threat, to identify best practices in securing assets, recognize potential gaps in security measures to be corrected, and recommend actions for the Office of Radiological Security (ORS) to address DE with its partners.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Domestic Extremism: Countering the Threat Posed to Critical Assets

Domestic extremism has been a growing concern in the United States in recent months, as illustrated in multiple bulletins from the Department of Homeland Security (DHS) warning law enforcement partners of the heightened threat. As concerns about these actors grows, it is important that facilities in the U.S. and internationally that protect critical assets, such as sensitive information, hazardous materials, or critical infrastructure, have effective methods in place to secure those assets. DE has challenged security systems through the threat of insider attack and violence, creating a new threat to be countered in the Office of Radiological Security’s radiological source security mission. In this effort, we used a literature review and focus group discussions with experts in critical asset security and extremism to understand the nature of the domestic extremist threat, to identify best practices in securing assets, recognize potential gaps in security measures to be corrected, and recommend actions and next steps. Twenty-two subject matter experts participated in a series of five focus group sessions. Questions focused on definitions of domestic extremism, potential changes in the threat, best practices in securing facilities, assets, and personnel, and any perceived gaps. Upon completion of the focus groups, notes were analyzed thematically to identify any recurring patterns in the results. In addition, a review of academic, industry, and government literature was conducted to understand the threat, describe the process of radicalization to extremism, and to identify empirically informed practices in prevention and response. Results of this project demonstrated that further work is needed to define domestic extremism in law, regulation, and policy, to help the U.S. develop a consistent response to the threat within organizations. This is especially important, as SMEs emphasized the need for early intervention in prevention efforts, noting that organizations need clear guidance on when and how to intervene. In addition, the need for social media monitoring was discussed, although challenges remain to do so with appropriate respect for privacy and civil liberties concerns.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

A National Secure-by-Design Strategy

The US National Cybersecurity Strategy published March 2, 2023 uses plain language to communicate that the US is calling for a major change in how we prioritize the security of software systems used in critical infrastructure. It acknowledges that our current approach, which is essentially, “let the buyer beware,” leaves entities who are least able to assess or defend vulnerable software responsible for the impacts of designed-in weaknesses while the makers of the technology bear no liability. The strategy recommends a security-by-design approach, recommending that software vendors be held liable to uphold a “duty of care” to consumers and for systems to be designed to “fail safely and recover quickly” . For energy infrastructure, the strategy calls out the need to implement the National Cyber-Informed Engineering Strategy to achieve higher confidence security for energy infrastructures. The Idaho National Laboratory, a pioneer in cyber-informed engineering concepts, is at the forefront of organizations educating others in industry, academia, and government on how to apply these concepts to real-world challenges. In this brief, we'll outline some of the basic principles of security-by-design and offer examples of how, in a water sector context, they're being put into successful practice.

42 ENGINEERING↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Systems Theory Principles and Complex Systems Engineering Concepts for Protection and Resilience in Critical Infrastructure: Lessons from the Nuclear Sector

Part of the Presidential Policy Directive 21 (PPD-21) (PPD 2013) mandate includes evaluating safety, security, and safeguards (or nonproliferation) mechanisms traditionally implemented within the nuclear reactors, materials, and waste sector of critical infrastructure—including a complex, dynamic set of risks and threats within an all-hazards approach. In response, research out of Sandia National Laboratories (Sandia) explores the ability of systems theory principles (hierarchy and emergence) and complex systems engineering concepts (multidomain interdependence) to better understand and address these risks and threats. Herein, this Sandia research explores the safety, safeguards, and security risks of three different nuclear sector-related activities—spent nuclear fuel transportation, small modular reactors, and portable nuclear power reactors—to investigate the complex and dynamic risk related to the PPD-21-mandated all-hazards approach. This research showed that a systems-theoretic approach can better identify inter-dependencies, conflicts, gaps, and leverage points across traditional safety, security, and safeguards hazard mitigation strategies in the nuclear reactors, materials, and waste sector. Resulting from this, mitigation strategies from applying systems theoretic principles and complex systems engineering concepts can be (1) designed to better capture interdependencies, (2) implemented to better align with real-world operational uncertainties, and (3) evaluated as a systems-level whole to better identify, characterize, and manage PPD-21's all hazards strategies.

42 ENGINEERING↗

Microgrid's Role in Enhancing the Security and Flexibility of City Energy Systems

Smart cities depend on flexible and secure energy systems to ensure resilient power for critical infrastructure; however, recent weather-related events and cyberattacks have highlighted weaknesses in our energy systems, with the potential for widespread economic and security impacts. As stated by the Executive Office of the President, "the resilience of the US electric grid is a key part of the nation's defense against severe weather." To address the energy delivery security challenge, microgrids are rising as a viable solution that enhances the flexibility and resilience of the distribution grid and boosts the reliability of the local supply for the end-user. Traditionally, high capital investment has been a barrier to large-scale adoption of microgrid technology. Understanding the flexibility and resilience benefits of microgrids and accounting for the associated value streams can make the microgrid's proposition economically viable. In this chapter, microgrids' utility and their potential to serve as a flexible and resilient resource for the utility grid by providing capabilities such as peak shaving, demand response, and frequency regulation is presented. Moreover, other value streams, such as (1) their ability to island during a disaster and sustain critical loads which makes them a robust resilience solution for end-users, in the event of the utility grid outage and (2) microgrids also provide a flexible platform for integrating distributed energy resources in conjunction with storage and conventional generation technologies, strengthen microgrid's role in reducing the over-arching goal of emission reduction. Given the myriad of benefits associated with microgrids, we present strategies which can be employed for making microgrid itself resilient against physical and cyberthreats by employing hardware, software, and personnel training solutions to operate the microgrid before, during, and after a potential disaster. This chapter, thus, provides a holistic study of the microgrid as a resilience resource, for the utility grid, and a self-contained end-user for the end-user.

cyber-physical system↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in urban air mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex infrastructures has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens’ safety and the efficiency of transportation networks. In response to these challenges, this paper presents a study on implementing a Host-Based Intrusion Detection System (HIDS) tailored explicitly to urban mobility environments’ unique demands. This study explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the urban mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organization’s overall cybersecurity posture. In conclusion, this paper highlights the significance of host-based intrusion detection in urban mobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Leveraging AI and Spatial Data to Unlock Pipeline Integrity Insights: NETL’s Advanced Infrastructure Integrity Model (AIIM)

Maintaining the integrity of natural gas infrastructure plays a critical role in ensuring energy security. Robust, data-driven foundational AI models for pipeline integrity can help address risk management and mitigation issues. Trusted foundational models can help with industry adoption and accelerate innovation by enhancing integrity predictions, reduce costs, and informing infrastructure build-out. The AIIM dashboard was released in 2022 and utilizes multi-ML models for ensemble-type insights. It was expanded to include analytics on reported incidents. It was developed as an ESRI Dashboard to support data visualization & interrogation and contains pipeline data and model results.

Advanced Infrastructure Integrity Model (AIIM)↗

Dynamics of Water, Climate, and Infrastructure

Climate and its impacts on the natural environment, and on the ability of the natural environment to support population and the built environment, stands as a threat multiplier that impacts national and global security. The Water Intersections with Climate Systems Security (WICSS) Strategic Initiative is designed to improve understanding of water’s role in, among other topics, the connection of critical infrastructure to climate in light of competing national and global security interests (including transboundary issues and stability), and identifying research gaps aligned with Sandia, and Federal agency priorities. With this impetus in mind, the WICSS Strategic Initiative team conceptualized a causal loop diagram (CLD) of the relationship between and among climate, the natural environment, population, and the built environment, with an understanding that any such regionally focused system must have externalities that influence the system from beyond its’ control, and metrics for better understanding the consequences of the set of interactions. These are discussed in light of a series of worldviews that focus on portions of the overall systems relationship. The relationships are described and documented in detail. A set of reinforcing and balancing loops are then highlighted within the context of the model. Finally, forward-looking actions are highlighted to describe how this conceptual model can be turned into modeling to address multiple problems described under the purview of the Strategic Initiative.

54 ENVIRONMENTAL SCIENCES↗

Cyber Infrastructure for the Smart Electric Grid

As electric power systems undergo a transformative upgrade with the integration of advanced technologies to enable the smarter electric grid, professionals who work in the area require a new understanding of the evolving complexity of the grid. Cyber Infrastructure for the Smart Electric Grid delivers a comprehensive overview of the fundamental principles of smart grid operation and control, smart grid technologies, including sensors, communication networks, computation, data management, and cyber security, and the interdependencies between the component technologies on which a smart grid's security depends. The book offers readers the opportunity to critically analyze the smart grid infrastructure needed to sense, communicate, compute, and control in a secure way.

communication networks↗

An editorial to the Special Issue on “Severe climate Risks”

The history of this Special Issue (https://www.sciencedirect.com/special-issue/10JD7LNJNQ0) indirectly dates back to the early 1990s, when the signature of the United Nations Framework Convention on Climate Change kicked-off an international political process based on one overarching and foundational principle: to avoid “dangerous anthropogenic interference with the climate system” at the global level. More than three decades later, such a principle remains central, though complementary aims made their way through the climate negotiation process, such as the importance of ensuring equity and justice, to give just one example here. Scientific knowledge also considerably progressed and we know more about the range of risks that climate change imposes and will continue to impose to the biosphere and humankind, worldwide and at all territorial levels. It is also clear that societal responses to these risks —“climate adaptation” as we know it— are increasingly happening, but definitely not at the pace of climate risk trends (Berrang-Ford et al., 2021, Erisken et al., 2021, Olazabal and Ruiz De Gopegui, 2021, Magnan et al., 2023a, Reckien et al., 2023, UNEP, 2023). As a result, concerns have emerged over the recent years in both the scientific and policy arenas around the idea that societies may not be able to address all climate risks, and that limits to adaptation and induced residual risks need to be considered more seriously. Such concerns further highlight the continuing importance of the imperative to minimise dangerous anthropogenic interference with the climate system, at any scale. But what does “dangerous interference” mean? How can we decide that we are entering the “dangerous” space, compared to a broader range of climate risks that would qualify as problematic but not necessarily “dangerous”? Who should make such a decision? Which conditions drive risk severity over time, including in the future? And what would be the environmental, economic, social and cultural implications of prioritising some climate risks over others? The Intergovernmental Panel on Climate Change (IPCC) was a pioneer in addressing such questions through the development of the “Key Risks” framing that describes those climate risks having the potential to become dangerous or “severe” over the course of this century (Schellnhuber et al., 2006, Schneider et al., 2007, Oppenheimer et al., 2014, O’Neill et al., 2022). The Fifth and Sixth assessment cycles (AR5 and AR6) went a step further by identifying about 120 Key Risks across regions and sectors, and clustering them into 8 “Representative Key Risks” covering a range of geographical systems (low-lying coasts, and to terrestrial and ocean ecosystems), sectors (critical infrastructure, living standards, human health, food security, and water security) and human dimensions (peace and mobility) (Oppenheimer et al., 2014, O’Neill et al., 2022). This Special Issue was born of the efforts of a range of authors, during the development of the IPCC AR6 main Assessment Report between 2019 and 2022, to characterise Key Risks and Representative Key Risks, and advance knowledge on what shapes “severe climate risks” conceptually as well as in the real-world. The series of papers forming this Special Issue is not intended to cover the topic exhaustively, but rather to give readers an overview through the following narrative: defining “severe climate risks” is highly challenging (Magnan et al., 2023b), but knowledge is expanding on the driving climate hazards (Tebaldi et al., 2023) and their implications on geographical systems, sectors and human dimensions, using here food security (Mirzabaev et al., 2023), human mobility (Gilmore et al., 2024) and peace (Buhaug et al., 2023) as illustrative examples. The overall intention is to support especially decision-makers, whatever the scale or sector considered, in asking severity-driven questions to identify sector- and context-specific “priority” risks from climate change.

54 ENVIRONMENTAL SCIENCES↗

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a method for consequence-driven risk analysis, enabling utilities to prioritize and mitigate potential threats effectively. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

99 GENERAL AND MISCELLANEOUS↗

Signal-Based Fast Tripping Protection Schemes for Electric Power Distribution System Resilience

This report is a summary of a 3-year LDRD project that developed novel methods to detect faults in the electric power grid dramatically faster than today’s protection systems. Accurately detecting and quickly removing electrical faults is imperative for power system resilience and national security to minimize impacts to defense critical infrastructure. The new protection schemes will improve grid stability during disturbances and allow additional integration of renewable energy technologies with low inertia and low fault currents. Signal-based fast tripping schemes were developed that use the physics of the grid and do not rely on communication to reduce cyber risks for safely removing faults.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Visual Analytic Platform for Interactive Validation of Human Mobility Simulations

Human mobility insights guide domain experts in an array of decisions, including critical infrastructure design, disaster response, epidemic modeling, national security, and policy making. Due to the inherent noise and privacy concerns in real-world individual-level mobility data, it is often preferred to leverage simulators that generate synthetic mobility data instead. However, it is critical to inspect and validate the output of such simulators to ensure the synthetic data is aligned with the characteristics of the population and the area of interest known to domain experts. While there exist many quantitative approaches for validating synthetic data, we argue it is also important to also validate such data qualitatively to capture aspects that are known to domain experts but difficult to quantify. In this work, we demonstrate a visual analytic platform that empowers domain experts to interact with their simulation outputs along spatial and temporal dimensions. By augmenting automated techniques and human skills, our visual analytic platform is a step towards interactive capabilities for model steering and quality control of mobility simulators.

Monadjemi, Shayan↗

Systems-To-Atoms (S2A): enabling hydrogen for climate security

The project addresses a critical gap in hydrogen infrastructure by integrating system-level energy models with atomic-scale material simulations in a unified Systems-to-Atoms (S2A) framework. The motivation stems from the need to develop efficient, cost-effective, and durable hydrogen transport and utilization technologies to support decarbonization of hard-to-electrify sectors such as heavy-duty transportation. Current system models lack awareness of material performance mechanisms, while material-scale models do not account for system-level usage and variability. To bridge this divide, the team developed a co-simulation capability linking techno-economic analyses, reactor/process-flow modeling, and molecular-scale catalysis simulations. Applied to hydrogen delivery in California, the framework enabled comparative evaluations of compressed, cryogenic, and liquid organic hydrogen carrier (LOHC) pathways, highlighting how catalyst operation and unit process efficiency influence overall performance. The results demonstrate that no single material or transport mode is universally optimal; instead, heterogeneous solutions tuned to specific operational contexts deliver better performance. The project delivers a new capability for cross-scale material co-design, advancing hydrogen infrastructure readiness and informing DOE and LLNL missions in climate and energy resilience.

organic↗

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS↗

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a framework for consequence-driven applied risk analysis, enabling utilities to prioritize and mitigate potential threats effectively, and responsibly deploy cloud applications. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗