Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack graph”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Faster-than-real-time Simulation with Demonstration for Resilient DER Integration

The US electric grid is facing operational, stability, and security challenges. Transmission system operators need some measure of visibility into distribution system renewable generation. Distribution system generation needs to support transmission system voltage. The grid is experiencing an expansion in measurement systems. How to take full advantage of this expansion and defend against attacks, both cyber and physical, poses additional challenges. The Faster-than-real-time Simulation with demonstration for Resilient DER Integration project set out to do the following: a. Flatten the voltage profile through the feeders and system for cost saving and voltage stabilization needs. b. Increase the amount of intermittent distributed energy resources (IDERs) that could be deployed on a utility feeder and provide 100% or more energy needed for the demands on that feeder, and c. based on an accurate model (Digital Twin) of the utilities system, be able to detect any abnormalities on the utilities distribution system. To manage the voltage and increase IDER penetration (a,b), Graph Trace Analysis is employed in a time-series, optimal power flow to coordinate the time-varying feedback control setpoints of a distribution feeder’s utility control devices. Under the coordinated control are a Load Tap Changing Transformer, a voltage regulator, and five switched capacitor banks. The feeder serves over 2000 customers, the feeder secondaries are modeled, and the feeder has 2.3 MW of PV generation, corresponding to a 17.4% penetration of PV generation. The feeder model has over 12,000 components, where every customer load bus and PV generator are modeled. The accuracy of the power flow solution is compared against historical meter voltage measurements, the improvement in conservation voltage reduction energy savings as a function of the coordinated control desired voltage profile is investigated, and the increase in PV penetration of the coordinated control over the existing control is presented. To achieve improved control performance while observing system operation constraints, bellwether Advanced Metering Infrastructure (AMI) voltage measurements are used to adjust the desired voltage profile used by the optimal power flow analysis. To detect and alleviate or negate attacks or failures on the distribution and transmission utility grids (c) the grid needs to be resilient and self-healing. In this project software was designed to do just that. At the center of the software is an Integrated System Model (ISM) that spans from transmission to secondary distribution. The ISM is employed in real-time abnormality detection, voltage stability forecasting, and multi-mode control. Testing results are presented for: 1—attacks on utility infrastructure; 2—energy savings from optimal control; 3—distribution system control response during a low voltage transmission system event; 4—cyber-attacks on PV inverters, where physical inverters are used in hard-ware-in-the-simulation-loop studies. Contributions of this work include real-time analysis that spans from three-phase transmission through secondary distribution; an approach for detecting abnormalities that employs measurements from three independent measurement systems; and a multi-mode distribution system control that responds to cyber-attacks, physical attacks, equipment failures, and transmission system needs.

Integrated System Model, Graph Trace Analysis, Adv↗

Information content in spectral calculations

Analytical procedures for extracting piecewise smooth solutions of hyperbolic systems from raw oscillatory data obtained by pseudospectral methods are developed. The validity of the approach is demonstrated for the case of linear problems with constant coefficients, and plausibility arguments are presented which indicate its applicability to nonlinear operators when the steady state has been achieved. Numerical results for the development of an oblique shock when a wedge is inserted at zero angle of attack into a uniform supersonic flow of an ideal gas (the time-dependent two-dimensional Euler equations discretized in space by the pseudospectral Chebyshev method) are presented in tables and graphs.

Abarbanel, S.↗

CONGO²: Scalable Online Anomaly Detection and Localization in Power Electronics Networks

Rapid and accurate detection and localization of electronic disturbances simultaneously are important for preventing its potential damages and determining potential remedies. Existing anomaly detection methods are severely limited by the low accuracy, the expensive computational cost and the need for highly trained personnel. There is an urgent need for a scalable online algorithm for in-field analysis of large-scale power electronics networks. Here in this paper, we propose a fast and accurate algorithm for anomaly detection and localization of power electronics networks: stratified colored-node graph (CONGO2). This algorithm hierarchically models the change of correlated waveforms and then correlated sensors using the colored-node graph. By aggregating the change of each sensor with its neighbors’ inputs, we can spontaneously identify and localize the anomaly that cannot be detected by data collected from a single sensor. As our proposed method only focuses on the changes within a short time frame, it is highly computational efficient and only needs small data storage. Thus, our method is ideal for online and reliable anomaly detection and localization of large-scale power electronic networks. Compared to existing anomaly detection methods, our method is entirely data-driven without training data, highly accurate and reliable for wide-spectrum anomalies detection, and more importantly, capable of both detection and localization. Thus, it is ideal for infield deployment for large-scale power electronic networks. As illustrated by a distributed energy resources (DERs) power grid with 37-node, our method can effectively detect and localize various cyber and physical attacks.

42 ENGINEERING↗

Flow solution on a dual-block grid around an airplane

The compressible flow around a complex fighter-aircraft configuration (fuselage, cranked delta wing, canard, and inlet) is simulated numerically using a novel grid scheme and a finite-volume Euler solver. The patched dual-block grid is generated by an algebraic procedure based on transfinite interpolation, and the explicit Runge-Kutta time-stepping Euler solver is implemented with a high degree of vectorization on a Cyber 205 processor. Results are presented in extensive graphs and diagrams and characterized in detail. The concentration of grid points near the wing apex in the present scheme is shown to facilitate capture of the vortex generated by the leading edge at high angles of attack and modeling of its interaction with the canard wake.

Eriksson, Lars-Erik↗

Theoretical motions of hydrofoil systems

Results are presented of an investigation that has been undertaken to develop theoretical methods of treating the motions of hydrofoil systems and to determine some of the important parameters. Variations of parameters include three distributions of area between the hydrofoils, two rates of change of downwash angle with angle of attack, three depths of immersion, two dihedral angles, two rates of change of lift with immersion, three longitudinal hydrofoil spacings, two radii of gyration in pitching, and various horizontal and vertical locations of the center of gravity. Graphs are presented to show locations of the center of gravity for stable motion, values of the stability roots, and motions following the sudden application of a vertical force or a pitching moment to the hydrofoil system for numerous sets of values of the parameters.

Imlay, Frederick H↗

Systematic planning of moving target defence for maximising detection effectiveness against false data injection attacks in smart grid

Abstract Moving target defence (MTD) has been gaining traction to thwart false data injection attacks against state estimation (SE) in the power grid. MTD actively perturbs the reactance of transmission lines equipped with distributed flexible AC transmission system (D‐FACTS) devices to falsify the attacker's knowledge about the system configuration. However, the existing literature has not systematically studied what influences the detection effectiveness of MTD and how it can be improved based on the topology analysis. These problems are tackled here from the perspective of an MTD plan in which the D‐FACTS placement is determined. We first exploit the relation between the rank of the composite matrix and the detecting effectiveness. Then, we rigorously derive upper and lower bounds on the attack detecting probability of MTDs with a given rank of the composite matrix. Furthermore, we analyse existing planning methods and highlight the importance of bus coverage by D‐FACTS devices. To improve the detection effectiveness, we propose a novel graph theory–based planning algorithm to retain the maximum rank of the composite matrix while covering all necessary buses. Comparative results on multiple systems show the high detecting effectiveness of the proposed algorithm in both DC‐ and AC‐SE.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Collection And Analysis Of Telemetry For The Cyote Heuristic

CATCH CLI focuses on gathering telemetry data, storing it in the Neo4j database, querying for Mitre ATT&CK patterns, and creating STIX 2.1 reports. Key Components: Analysis Modules: Analyze data to detect attack patterns. GoSTOTS Collection Engines: Collect telemetry data. These tools can be used together or individually. Analysis modules rely on data from specific engines to identify attack patterns. Source Code Organization: Engines: CATCH/catch/cmd/collection Modules: CATCH/catch/cmd/analysis CGUI Overview CATCH Graphical User Interface (CGUI) offers a graphical shell to execute CATCH CLI, allowing easy editing of: Analysis Modules Database configurations Profiles (collection and device settings) Neo4j Overview Neo4j is a graph database using the Cypher query language, storing data in JSON. It seamlessly integrates with STIX 2.1 data for: Data Submission: CATCH Collection Engines Data Querying: Analysis Modules CATCH modifies STIX 2.1 data for Neo4j submission and reverts it back during querying. STIG Overview Structured Threat Intelligence Graph (STIG) is a tool for creating, editing, querying, analyzing, and visualizing threat intelligence using STIX 2.1 and storing data in Neo4j. Usage Tools can be run: Manually (CLI): Refer to CATCH documentation User Interface: Run ./cgui/CGUI or go run ./cgui/ Additional Information Logging System: Detailed in the config documentation Further Documentation: Available for CATCH and CGUI

Madsen, MichaelJ. [Idaho National Laboratory (INL)↗

Pressure distribution over an NACA 23012 airfoil with an NACA 23012 external-airfoil flap

Report presents the results of pressure-distribution tests of an NACA 23012 airfoil with an NACA 23012 external airfoil flap made in the 7 by 10-foot wind tunnel. The pressures were measured on the upper and lower surfaces at one chord section on both the main airfoil and on the flap for several different flap deflections and at several angles of attack. A test installation was used in which the airfoil was mounted horizontally in the wind tunnel between vertical end planes so that two-dimensional flow was approximated. The data are presented in the form of pressure-distribution diagrams and as graphs of calculated coefficients for the airfoil-and-flap combination and for the flap alone.

Wenzinger, Carl J↗

The climatic effects of nuclear war

The effects of various US-USSR nuclear-exchange scenarios on global climate are investigated by means of computer simulations, summarizing the results of Turco et al. (1983) and follow-up studies using 3D global-circulation models. A nuclear-scenario model is used to determine the amounts of dust, smoke, radioactivity, and pyrotoxins generated by a particular type of nuclear exchange (such as a general 5,000-Mt exchange, a 1,000-Mt limited exchange, a 5,000-Mt hard-target counterforce attack, and a 100-Mt attack on cities only): a particle-microphysics model predicts the evolution of the dust and smoke particles; and a radiative-convective climate model estimates the effects of the dust and smoke clouds on the global radiation budget. The findings are presented in graphs, diagrams, and a table. Thick clouds blocking most sunlight over the Northern Hemisphere midlatitudes for weeks or months and producing ground-temperature reductions of 20-40 C, disruption of global circulation patterns, and rapid spread of clouds to the Southern Hemisphere are among the 'nuclear-winter' effects predicted for the 5,000-Mt baseline case. The catastrophic consequences for plant, animal, and human populations are considered, and the revision of superpower nuclear strategies is urged.

Turco, R. P.↗

Quasi-steady flight to quasi-steady flight transition for abort landing in a windshear - Trajectory optimization and guidance

Trajectory optimization and trajectory-guidance problems for abort-landing maneuvers in the presence of low-altitude wind shear are investigated by means of numerical simulations, with a focus on methods designed to achieve quasi-steady flight recovery (final values of the relative velocity, path inclination, and angle of attack equal to those for quasi-steady steepest climb). The derivation of the governing equations is outlined; the modeling techniques are explained; and results for a B-727 transport aircraft approaching a sea-level airfield at temperature 100 F are presented in extensive tables and graphs and characterized in detail. The techniques developed are shown to be effective in restoring the aircraft to stable quasi-steady flight.

Miele, A.↗

An experimental investigation of a cold jet emitting from a body of revolution into a subsonic free stream

An experimental program was undertaken to determine the pressure distribution induced on aerodynamic bodies by a subsonic cold jet exhausting normal to the body surface and into a subsonic free stream. The investigation was limited to two bodies with single exhaust jets a flat plate at zero angle of attack with respect to the free-stream flow and a cylinder, fitted with a conical nose, with the longitudinal axis alined with the free-stream flow. Experimental data were obtained for free-stream velocity to jet velocity ratios between 0.3 and 0.5. The experimental data are presented in tabular form with appropriate graphs to indicate pressure coefficient contours, pressure coefficient decay, pitching-moment characteristics, and lift characteristics.

Ousterhout, D. S.↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

A Novel Framework to Quantify Power Grid Resilience

The quantification of an operating power grid’s resilience is highly significant today, given its criticality as an enabler of other infrastructures, complexity, and the threat it faces due to a wide range of detrimental events, from extreme climate to cyber attacks. Currently, there exist no standardized definitions and metrics for measuring the resilience of an operating grid. In this paper, we introduce a novel resilience quantification framework and demonstrate a method to measure the flexibility towards topological/structural changes due to potential failures in the power grid to assess operational resilience. We start with the state estimation data from a large utility and use the graph analysis methods and power flow simulation tools to compute the identified resilience parameters.

Yoginath, Srikanth↗

Visualizing Comparisons of Bill of Materials

Protecting critical infrastructure from cyber attacks, natural disasters, and other disruptions is a priority of the U.S. Government. Critical infrastructure includes providing electricity to homes and businesses, supplying natural gas for heating, and producing renewable energy sources. A loss of these services, as seen in the Solarwinds supply chain attack in 2020 , Texas snowstorm of 2021, the Colonial Pipeline cyber incident of 2021, and the Washington power substation attacks in 2022 result in high costs to consumers, disruption of everyday life, and even death. To protect the infrastructure, we first have to know what equipment we are protecting. The complexity of distributed manufacturing and development coupled with the increasing prevalence of cyber and supply chain attacks necessitates a greater understanding of the hardware and software components that comprise equipment in critical infrastructure. When a vulnerability in a single software library can have disastrous consequences, it is vital to understand critical equipment and systems at a granular level. This need has led to increased energy around the development and incorporation of bill-of-materials (BOM) into existing asset management practices to aid in mitigating, and responding to future attacks \cite{noauthor_software_nodate}. While much of the current research is devoted to creating BOMs, it is equally important to develop methodologies for leveraging BOMs to answer questions, such as: How has my software changed? Are two pieces of equipment equivalent? Does this piece of equipment that just arrived match my historical information? In this work, we demonstrate how BOMs can be represented by graph structures. We then describe how these structures can be fed into a graph comparison algorithm to produce a novel interactive visualization that allows us to not only identify differences in BOMs, but show exactly where they are in the product.

Jones, Rebecca D.↗

Optimal penetration landing trajectories in the presence of wind shear

Aircraft penetration landing in the presence of strong-to-severe wind shear is investigated analytically. The optimal-control problem for vertical-plane trajectories is considered, using angle of attack as one control parameter with either (1) a power setting (PS) which remains constant at its preshear value, (2) a PS which increases to its maximum value, or (3) a PS which is controlled (as the second parameter). The problem formulation is explained in detail, and numerical results obtained with the primal sequential gradient-restoration algorithm of Miele and Wang (1986) are presented in extensive tables and graphs. It is found that the touchdown requirements can only be satisfied by optimal trajectories using scheme (1) (but only at low altitudes) or scheme (3); the characteristics of the latter trajectories are explored.

Miele, A.↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

Quasi-steady flight to quasi-steady flight transition in a windshear - Trajectory guidance

The control (via the angle of attack) of the vertical flight of an aircraft taking off at maximum power in a horizontal wind shear with downdraft is investigated analytically. Optimal trajectories to recover the initial path inclination or to recover quasi-steady flight (the relative values of the velocity, path inclination, and angle of attack) are derived using a Chebyshev approach and shown to be nearly identical in the shear but divergent after the shear. These results are then applied to construct a trajectory-guidance control comprising a variable-gamma guidance scheme for the shear trajectory, a constant-gamma guidance scheme for the immediate postshear trajectory, and a constant-rate-of-climb guidance scheme for the aftershear trajectory. Numerical results demonstrating the near-optimal performance of the control are presented in tables and graphs.

Miele, A.↗