Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Industrial Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Industrial noise control: Some case histories, volume 1

A collection of solutions to industrial noise problems is presented. Each problem is described in simple terms, with noise measurements where available, and the solution is given, often with explanatory figures. Where the solution rationale is not obvious, an explanatory paragraph is usually appended. As a preface to these solutions, a short exposition is provided of some of the guiding concepts used by noise control engineers in devising their solutions.

Hart, F. D.↗

ADROC: An Emulation Experimentation Platform for Advancing Resilience of Control Systems

Cyberattacks against industrial control systems have increased over the last decade, making it more critical than ever for system owners to have the tools necessary to understand the cyber resilience of their systems. However, existing tools are often qualitative, subject matter expertise-driven, or highly generic, making thorough, data-driven cyber resilience analysis challenging. The ADROC project proposed to develop a platform to enable efficient, repeatable, data-driven cyber resilience analysis for cyber-physical systems. The approach consists of two phases of modeling: computationally efficient math modeling and high-fidelity emulations. The first phase allows for scenarios of low concern to be quickly filtered out, conserving resources available for analysis. The second phase supports more detailed scenario analysis, which is more predictive of real-world systems. Data extracted from experiments is used to calculate cyber resilience metrics. ADROC then ranks scenarios based on these metrics, enabling prioritization of system resources to improve cyber resilience.

97 MATHEMATICS AND COMPUTING↗

Real time computations of cryogenic He properties

The Fermilab PIP-II (proton improvement plan - II) project is being constructed at Fermilab to deliver $800\,MeV$ protons of $>1\,MW$ beam power to replace the present LINAC and provide protons to the remainder of the existing accelerator complex. The new LINAC consists of a warm front end, 23 superconducting RF cryomodules, and a beam transfer line to the existing complex. The cryomodules (CMs) are to be tested at Fermilab's CryoModule Test Facility (CMTF).An important measurement in cryogenic testing is the heat load of each CM. Traditionally, at Fermilab, these measurements were made collecting archived data offline and analyzing it. The new control system for PIP-II is being developed with the EPICS (Experimental Physics and Industrial Control System) framework, which allows us to compute the heat load in real time using the HePak library.We are exploring other $He$ properties, such as flow, where flow meters are not available, which can also be calculated in real time and fed back to the cryogenics engineers.This paper details the real time heat load calculation and $He$ flow software developed for CM testing at CMTF, as well as the first results from the prototype HB650 CM. Future plans for 2-phase $LHe$ flow will also be outlined.

Hanlet, Pierrick [Fermilab]↗

Precursor Analysis Report: Cyber Attack on Thyssenkrupp Blast Furnace 2014

The Cyber Attack on Thyssenkrupp Blast Furnace 2014 Precursor Analysis Report leverages publicly available information about the Thyssenkrupp Steel Mill cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. In December 2014, the German Government’s Federal Office for Information Security (BSI) released a report detailing a cyber attack on a German steel mill that occurred earlier that year, though exact dates and details of the attack were not revealed. While the report did not specify the name of the company, multiple sources identified the victim as one of Europe’s largest steel manufacturers, Thyssenkrupp AG. Further, Thyssenkrupp announced on 16 May of that year that Europe’s largest blast furnace, “Schwelgern 2,” located at its facility in Duisburg, Germany, would be offline for several weeks for repairs and upgrades, suggesting Schwelgern 2 was likely the target of the attack. The attack began in early 2014, when adversaries infiltrated the victim steel mill’s Information Technology (IT) network via a spearphishing campaign, then worked their way into the Operational Technology (OT) environment, where they executed software that caused denial of service, denial of control, and eventually a loss of control. This led to the blast furnace shutting down without proper safety procedures, resulting in catastrophic physical damage. No lives were lost in the incident, but ThyssenKrupp suffered $4 million in damage to the blast furnace and an additional $6 million in lost revenue. The adversaries required specialized knowledge and expertise in steel production, which enabled them to compromise a variety of internal systems and components across both IT and OT networks. The attack also demonstrated detailed knowledge of the industrial control systems (ICS) and production processes being used. This combination resulted in one of the earliest known publicly reported cybersecurity incidents resulting in physical damage to ICS equipment. Researchers and analysts identified 19 unique techniques (used in a sequence of 20 steps) utilized during the attack with a total of 454 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Fifteen of the identified techniques used during the Thyssenkrupp cyber attack were precursors to the triggering event. Analysis identified 369 observables associated with these precursor techniques, 316 of which were assessed to have an increased likelihood of being perceived in the 120 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING↗

Risk Analysis for Remote Operation of Microreactors

Microreactors are a subset of advanced nuclear reactors that can be factory fabricated, transportable, and self-regulating. They have the potential to be used in microgrids, rural and remote areas, or emergency response applications, replacing fossil fuel sources like diesel generators and enabling sustainable energy generation. In order to make microreactor operation cost-effective, it is likely that remote communications will be needed to reduce the number of personnel required to be on site. While remote operation of energy generation and other industrial control systems is common in other industries, it is not yet adopted in the nuclear community and has many perceived and actual risks. In this paper, the severity of the risks introduced by remote operations for microreactors are explored. The primary changes in the operations involve the addition of a remote communications network and a certification system for data and controls. These changes lend themselves to considerations of cyber risks, whether unintentional or adversarial, but the assessment considers not just cyber risks introduced, but also how physical and human factors-based risks will impact the remote operations system and change the overall risk profile. This initial assessment indicates that there are standard cyber and mitigation measures that can be put in place so the risk of doing remote operations does not dramatically increase compared to local operations. This evaluation is a critical step in the process of evaluating if remote operations of microreactors is a suitable solution to meet future sustainable grid needs

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Importance of residence-time control of industrial screw-conveying reactors: Application to dilute-acid hydrolysis of biomass

Horizontal screw reactors are utilized in biorefineries for acid-catalyzed hydrolysis of xylan, which is a multi-step chemical reaction requiring accurate residence-time control. However, it is difficult to obtain online analytical measurement of reactant species. In this work, a residence-time distribution (RTD) is exhibited whose characteristics influence species yields. Sensitivity of product yield to RTD was investigated to understand the relative importance of operating control vs. inherent reactor dispersion. We find that reactor operation using a commonly used theoretical residence-time relationship can result in substantial yield losses. Instead, a model that accounts for the actual reactor RTD provides much improved results. The dispersion caused by reactor conditions only slightly hinders achieving theoretical optimal xylose yield (less than 3% yield loss for coefficient of variation less than 0.35), provided a validated RTD model is used to target the desired mean residence-time. In contrast, neglecting to account for the RTD by using the simplistic theoretical calculation results in xylose yields that are as much as 16% lower than the theoretical maximum.

09 BIOMASS FUELS↗

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Integrating 5G Technology for Improved Process Monitoring and Network Slicing in ICS

Industrial Control Systems (ICS) are crucial for monitoring physical processes that support essential cyber-enabled services like power generation. The use of proprietary communication and lack of effective intrusion detection mechanisms pose constraints for efficient operation. Therefore, there is a need to modernize these systems with decentralized technologies like Edge Computing and 5G. However, integrating 5G and Edge Computing into large-scale ICS networks presents implementation and performance challenges. To address these challenges, this paper proposes an integrated ICS architecture that combines 5G and Edge Computing technologies with traditional ICS protocols. The objective is to minimize implementation and operational difficulties while improving the monitoring of physical processes and enabling robust intrusion detection. The proposed architecture outlines the necessary components, services, and communication protocols required for the integration of 5G and Edge Computing.

Aguayo, Jared M.↗

Towards 5G-Enabled Operational Technology for Process Monitoring and Network Slicing

Cyber-Physical Systems (CPS) are deployed to monitor physical processes in critical cyber-enabled services like power generation. However, CPS ecosystems are typically designed without robust security. While it is important to ensure optimal performance of the Operational Technology (OT) environments, security cannot be overlooked. To modernize traditional OT services, 5G technology is being integrated. 5G technology offers low latency and high availability, making it a suitable infrastructure for managing and monitoring physical processes. How-ever, integrating 5G mechanisms into large-scale OT networks introduces new implementation and performance challenges. Therefore, this paper presents a 5G-enabled CPS architecture (5G-CPS) that describes the necessary components, services, and communication protocols and conducts feasibility study to integrate 5G technology in industrial control system networks to understand the performance merits. The 5G-CPS architecture aims to minimize implementation and operational challenges associated with integrating 5G technology into constrained OT.

Aguayo, Jared M.↗

Changing effects of external forcing on Atlantic–Pacific interactions

Recent studies have highlighted the increasingly dominant role of external forcing in driving Atlantic and Pacific Ocean variability during the second half of the 20th century. This paper provides insights into the underlying mechanisms driving interactions between modes of variability over the two basins. We define a set of possible drivers of these interactions and apply causal discovery to reanalysis data, two ensembles of pacemaker simulations where sea surface temperatures in either the tropical Pacific or the North Atlantic are nudged to observations, and a pre-industrial control run. We also utilize large-ensemble means of historical simulations from the Coupled Model Intercomparison Project Phase 6 (CMIP6) to quantify the effect of external forcing and improve the understanding of its impact. A causal analysis of the historical time series between 1950 and 2014 identifies a regime switch in the interactions between major modes of Atlantic and Pacific climate variability in both reanalysis and pacemaker simulations. A sliding window causal analysis reveals a decaying El Niño–Southern Oscillation (ENSO) effect on the Atlantic as the North Atlantic fluctuates towards an anomalously warm state. The causal networks also demonstrate that external forcing contributed to strengthening the Atlantic's negative-sign effect on ENSO since the mid-1980s, where warming tropical Atlantic sea surface temperatures induce a La Niña-like cooling in the equatorial Pacific during the following season through an intensification of the Pacific Walker circulation. The strengthening of this effect is not detected when the historical external forcing signal is removed in the Pacific pacemaker ensemble. The analysis of the pre-industrial control run supports the notion that the Atlantic and Pacific modes of natural climate variability exert contrasting impacts on each other even in the absence of anthropogenic forcing. The interactions are shown to be modulated by the (multi)decadal states of temperature anomalies of both basins with stronger connections when these states are “out of phase”. We show that causal discovery can detect previously documented connections and provides important potential for a deeper understanding of the mechanisms driving changes in regional and global climate variability.

54 ENVIRONMENTAL SCIENCES↗

Handbook for industrial noise control

The basic principles of sound, measuring techniques, and instrumentation associated with general purpose noise control are discussed. Means for identifying and characterizing a noise problem so that subsequent work may provide the most efficient and cost effective solution are outlined. A methodology for choosing appropriate noise control materials and the proper implementation of control procedures is detailed. The most significant NASA sponsored contributions to the state of the art development of optimum noise control technologies are described including cases in which aeroacoustics and related research have shed some light on ways of reducing noise generation at its source.

Source record↗

AFTI/F-16 DFCS development summary - A report to industry multimode control law design

The primary goal of the AFTI/F-16 program is to develop a reliable triplex digital multimode flight control system; this system is to be tailored to optimize fighter performance and capable of six-degree-of-freedom decoupled aircraft control. The multiple digital control law configurations arrived at through flight testing are presented. The changes in these designs from the results of flight tests establish that flight testing is an integral part of the development process. The flight test results are analyzed here from the standpoint of pilot comments and resulting control law design modifications.

Toles, R. D.↗