Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “industrial control systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Systems and methods for monitoring traffic on industrial control and building automation system networks

Technologies relating to monitoring communications traffic to detect potential attacks on industrial control system networks and building automation system networks are described herein. In an embodiment, a monitoring device receives a plurality of communications from a control network. The monitoring device transmits the communications to a computing device. Based on the communications, the computing device generates a listing of devices that communicated by way of the control network over a period of time, and computes a volume of traffic between each pair of devices in the listing of devices. The computing device then outputs a graphical user interface (GUI) by way of display, the GUI comprising data indicative of the computed volumes of traffic, which may be indicative of a potential attack on the control network.

Jenkins, Chris↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Are System Baselines within OT Environments Feasible?

Critical infrastructure stakeholders need to baseline their systems to understand expected protocol communications.Baseline behaviors may vary based on operational context.Expected operations during a maintenance window, for example, may be different from normal operations.Furthermore, constructing system baselines for Industrial Control Systems (ICS) is difficult and time-consuming.ICS processes generate artifacts expressed across heterogeneous data sources such as network and device logs. There needs to be a corpus of data in order to develop and compare methods that evaluate the feasibility, performance, and generality of approaches to construct baselines for ICS events. Standalone repositories of network packet captures are insufficient to develop methods to classify or recognize operational events expressed across multiple data sources. Moreover, static data corpora do not enable researchers to compare the impact of changing the underlying system for which a baseline is being constructed and this limits the ability to evaluate the performance of system baselines given system changes (e.g. patches, configuration, maintenance events). In order to address these limitations within the community, this talk intends to promote discussion about the state of the practice of constructing baselines. In this manner, we can continue to understand requirements within industry that are not being met by current approaches to baseline construction. This talk builds on two previous talks on the topic of system baselines for OT environments. First, Weaver co-presented at the RSA Conference ICS Sandbox with Dan Gunter. The talk confirmed the need within industry to construct baselines across multiple types of data sources relative to the semantics of specific business processes. Second, Weaver presented at IEEE Security and Privacy Workshop on Language-Theoretic Security.

02 PETROLEUM↗

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING↗

Inter-Domain Fusion for Enhanced Intrusion Detection in Power Systems: An Evidence Theoretic and Meta-Heuristic Approach

False alerts due to misconfigured or compromised intrusion detection systems (IDS) in industrial control system (ICS) networks can lead to severe economic and operational damage. However, research using deep learning to reduce false alerts often requires the physical and cyber sensor data to be trustworthy. Implicit trust is a major problem for artificial intelligence or machine learning (AI/ML) in cyber-physical system (CPS) security, because when these solutions are most urgently needed is also when they are most at risk (e.g., during an attack). To address this, the Inter-Domain Evidence theoretic Approach for Inference (IDEA-I) is proposed that reframes the detection problem as how to make good decisions given uncertainty. Specifically, an evidence theoretic approach leveraging Dempster–Shafer (DS) combination rules and their variants is proposed for reducing false alerts. A multi-hypothesis mass function model is designed that leverages probability scores obtained from supervised-learning classifiers. Using this model, a location-cum-domain-based fusion framework is proposed to evaluate the detector’s performance using disjunctive, conjunctive, and cautious conjunctive rules. The approach is demonstrated in a cyber-physical power system testbed, and the classifiers are trained with datasets from Man-In-The-Middle attack emulation in a large-scale synthetic electric grid. For evaluating the performance, we consider plausibility, belief, pignistic, and general Bayesian theorem-based metrics as decision functions. To improve the performance, a multi-objective-based genetic algorithm is proposed for feature selection considering the decision metrics as the fitness function. Finally, we present a software application to evaluate the DS fusion approaches with different parameters and architectures.

42 ENGINEERING↗

Language-Theoretic Data Analysis to Support ICS Protocol Baselining

Critical infrastructure stakeholders need to baseline their systems to understand expected protocol communications. Baseline behaviors may vary based on operational context. Expected operations during a maintenance window, for example, may be different from normal operations. Furthermore, constructing system baselines for Industrial Control Systems (ICS) is difficult and time-consuming. ICS processes generate artifacts expressed across heterogeneous data sources such as network traffic and device logs. This paper explores the hypothesis that such ICS artifacts form a language in the language-theoretic sense. From a theoretical perspective, the variety of implementations of ICS protocols and constrained environment of OT networks provide a rich application domain for language-theoretic approaches. We present several use cases related to the practical construction of system baselines: grammars for data fusion, language dialects for device fingerprinting, and security automata for system baselining

24 POWER TRANSMISSION AND DISTRIBUTION↗

Real-Time Automated pH Control within Batch Processes Relying on Raman pH Measurement

Nuclear fission is an energy source that can provide consistent power with very low associated carbon emissions. However, management of the used nuclear fuel is an important aspect of the application of nuclear power. Recycling of useful components from used fuel is an attractive option, but this involves chemical processing of the fuel. Possible chemical separation technologies that might be used in this regard are sensitive to solution pH. Raman spectroscopy is a promising technique for monitoring the pH of solutions in real time. Classical pH probes are too fragile to be used in the harsh environments encountered in nuclear fuel processing. Raman probes are robust and can withstand these harsh environments to track pH. Coupled with chemometric analysis, the demonstration of the use of Raman spectroscopy to track and predict the pH in carboxylate-buffered systems is made possible. Utilizing this spectroscopy in conjunction with Programmable Logic Controllers mimics industrial control systems used in many modern industrial settings. This showcases a pragmatic approach toward leveraging Raman spectroscopy and chemometric model outputs as inputs for a real-time control system. The model to predict pH created by chemometrics proved to be successful in tracking pH. The optimal pH for TALSPEAK extraction of lanthanides and actinides from aqueous solution is known to proceed in a narrow pH range of around pH = 2.8 ± 0.1. This study uses Raman optical monitoring and automated control to return and maintain solution pH within this range after acid or base perturbations move the solution pH well outside this region. Root-mean-square errors show that pH changes measured using Raman spectroscopy on the batch process solution are reliably measured and used to automatically correct and maintain solution pH. Measurement of solution pH tracks favorably with electrochemical pH probe comparison measurements. As a result, the ability to showcase Raman spectroscopy paired with chemometrics analysis acts as a durable, better alternative data source compared to traditional pH probes to optimize the separation efficiency in the used nuclear fuel processing.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Upgrade of hardware controls for the STAR experiment at RHIC

The STAR experiment has been delivering significant physics results for more than 20 years. Stable operation of the experiment was achieved by using a robust controls system based on the Experimental Physics and Industrial Control System (EPICS). Now an object-oriented approach with Python libraries, adapted for EPICS software, is going to replace the procedural-based EPICS C libraries previously used at STAR. Advantages of the new approach include stability of operation, code reduction and straightforward project documentation. The first two sections of this paper introduce the STAR experiment, give an overview of the EPICS architecture, and present the use of Python for controls software. Therefore, specific examples, as well as upgrades of user interfaces, are outlined in the following sections.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Integrating 5G Technology for Improved Process Monitoring and Network Slicing in ICS

Industrial Control Systems (ICS) are crucial for monitoring physical processes that support essential cyber-enabled services like power generation. The use of proprietary communication and lack of effective intrusion detection mechanisms pose constraints for efficient operation. Therefore, there is a need to modernize these systems with decentralized technologies like Edge Computing and 5G. However, integrating 5G and Edge Computing into large-scale ICS networks presents implementation and performance challenges. To address these challenges, this paper proposes an integrated ICS architecture that combines 5G and Edge Computing technologies with traditional ICS protocols. The objective is to minimize implementation and operational difficulties while improving the monitoring of physical processes and enabling robust intrusion detection. The proposed architecture outlines the necessary components, services, and communication protocols required for the integration of 5G and Edge Computing.

Aguayo, Jared M.↗

Towards 5G-Enabled Operational Technology for Process Monitoring and Network Slicing

Cyber-Physical Systems (CPS) are deployed to monitor physical processes in critical cyber-enabled services like power generation. However, CPS ecosystems are typically designed without robust security. While it is important to ensure optimal performance of the Operational Technology (OT) environments, security cannot be overlooked. To modernize traditional OT services, 5G technology is being integrated. 5G technology offers low latency and high availability, making it a suitable infrastructure for managing and monitoring physical processes. How-ever, integrating 5G mechanisms into large-scale OT networks introduces new implementation and performance challenges. Therefore, this paper presents a 5G-enabled CPS architecture (5G-CPS) that describes the necessary components, services, and communication protocols and conducts feasibility study to integrate 5G technology in industrial control system networks to understand the performance merits. The 5G-CPS architecture aims to minimize implementation and operational challenges associated with integrating 5G technology into constrained OT.

Aguayo, Jared M.↗

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

A review of artificial intelligence applications in manufacturing operations

Abstract Artificial intelligence (AI) and machine learning (ML) can improve manufacturing efficiency, productivity, and sustainability. However, using AI in manufacturing also presents several challenges, including issues with data acquisition and management, human resources, infrastructure, as well as security risks, trust, and implementation challenges. For example, getting the data needed to train AI models can be difficult for rare events or costly for large datasets that need labeling. AI models can also pose security risks when integrated into industrial control systems. In addition, some industry players may be hesitant to use AI due to a lack of trust or understanding of how it works. Despite these challenges, AI has the potential to be extremely helpful in manufacturing, particularly in applications such as predictive maintenance, quality assurance, and process optimization. It is important to consider the specific needs and capabilities of each manufacturing scenario when deciding whether and how to use AI in manufacturing. This review identifies current developments, challenges, and future directions in AI/ML relevant to manufacturing, with the goal of improving understanding of AI/ML technologies available for solving manufacturing problems, providing decision‐support for prioritizing and selecting appropriate AI/ML technologies, and identifying areas where further research can yield transformational returns for the industry. Early experience suggests that AI/ML can have significant cost and efficiency benefits in manufacturing, especially when combined with the ability to capture enormous amounts of data from manufacturing systems.

Plathottam, Siby Jose↗

Engineering Out Industry 4.0 Cyber Risk Presentation for EnCyCriS

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

99 GENERAL AND MISCELLANEOUS↗

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

Real time heat load calculation software based on EPICS for Fermilab PIP-II CM tests

Fermilab has a project to improve the proton beam energy which is called PIP-II (the 2nd Proton Improvement Plan). There is a superconducting linear accelerator, LINAC, to improve the proton beam power and the LINAC consists of 5 types of cryomodules (CM), 1 HWR CM, 2 SSR1 CM, 4 SSR2 CM, LB650 CM, and HB650 CM. The prototypes of these cryomodules are being tested at Fermilab’s CryoModule Test Facility (CMTF). Heat load measurements are an important part of the prototype CM testing. The CMTF cryogenic control system was developed based on the ACNET (Accelerator Control NETwork) for CM testing for other projects, but the PIP-II cryogenic control system will be implemented using the Experimental Physics and Industrial Control System (EPICS). As part of the prototype CM testing campaign an EPICS based control system has been implemented at CMTF. This EPICS cryogenic control system includes real time heat load calculation software utilizing the Fortran implementation of Hepak. This paper details the real time heat load calculation software developed for the prototype CM testing including the first results from the HB 650 CM.

Yoon, S. [Fermilab]↗

Real time heat load calculation software based on EPICS for Fermilab PIP-II CM tests

Fermilab has a project to improve the proton beam energy which is called PIP-II (the 2nd Proton Improvement Plan). There is a superconducting linear accelerator, LINAC, to improve the proton beam power and the LINAC consists of 5 types of cryomodules (CM), 1 HWR CM, 2 SSR1 CM, 4 SSR2 CM, LB650 CM, and HB650 CM. The prototypes of these cryomodules are being tested at Fermilab’s CryoModule Test Facility (CMTF). Heat load measurements are an important part of the prototype CM testing. The CMTF cryogenic control system was developed based on the ACNET (Accelerator Control NETwork) for CM testing for other projects, but the PIP-II cryogenic control system will be implemented using the Experimental Physics and Industrial Control System (EPICS). As part of the prototype CM testing campaign, an EPICS based control system has been implemented at CMTF. This EPICS cryogenic control system includes real-time heat load calculation software utilizing the Fortran implementation of Hepak. This paper details the real time heat load calculation software developed for the prototype CM testing including the first results from the HB650 CM.

Yoon, S. [Fermilab]↗

Mu2e DAQ and slow control systems

The Mu2e experiment at the Fermilab Muon Campus will search for the coherent neutrinoless conversion of a muon into an electron in the feld of an aluminum nucleus with a sensitivity improvement by a factor of 10,000 over existing limits. The Mu2e Trigger and Data Acquisition System (TDAQ) uses otsdaq as the online Data Acquisition System (DAQ) solution. Developed at Fermilab, otsdaq integrates both the artdaq DAQ and the art analysis frameworks for event transfer, fltering, and processing. otsdaq is an online DAQ software suite with a focus on fexibility and scalability and provides a multiuser, web-based, interface accessible through a web browser. The data stream from the detector subsystems is read by a software flter algorithm that selects events which are combined with the data fux coming from a Cosmic Ray Veto System. The Detector Control System (DCS) has been developed using the Experimental Physics and Industrial Control System (EPICS) open source platform for monitoring, controlling, alarming, and archiving. The DCS System has been integrated into otsdaq. A prototype of the TDAQ and the DCS systems has been built at Fermilab’s Feynman Computing Center. In this paper, we report on the progress of the integration of this prototype in the online otsdaq software.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗