Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “internet”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

IPv6 Tunneling and Translation Technologies Pilot

Based on the latest DOE (Department of Energy) milestones, Sandia needs to convert to IPv6 (Internet Protocol version 6)-only networks over the next 5 years. Our original IPv6 migration plan did not include migrating to IPv6-only networks at any point within the next 10 years, so it must necessarily change. To be successful in this endeavor, we need to evaluate technologies that will enable us to deploy IPv6-only networks early without creating system stability or security issues. We have set up a test environment using technology representative of our production network where we configured and evaluated industry standard translation technologies and techniques. Based on our results, bidirectional translation between IPv4 (Internet Protocol version 4) and IPv6 is achievable with our current equipment, but due to the complexity of the configuration, may not scale well to our production environment.

97 MATHEMATICS AND COMPUTING↗

Route Views Project (CRADA Final Report)

The Route Views Project (“Project”) was founded by the Advanced Network Technology Center at the University of Oregon to allow internet users to view global Border Gateway Protocol routing information from the perspective of the other locations around the Internet. It is a significant tool used in global research and education networks. It is an open source tool, maintained by the core Route Views team and serves as an aid for ESnet and other scientific and education network peers to operate these networks in an effective and efficient manner.

97 MATHEMATICS AND COMPUTING↗

Implementation of an ICS Ransomware Testbed: Scenarios, Variants, and Evaluation Methods

Ransomware attacks on Industrial Control Systems (ICS) have emerged as a formidable threat to the United States’ critical infrastructure, eliciting grave concerns regarding national security. In March 2023, the FBI Internet Crime Complaint Center (IC3) unveiled its 2022 Internet Crime Report, highlighting a concerning 870 complaints related to ransomware impacting U.S. critical infrastructure. Of the country's 16 critical infrastructure sectors, 14 encountered at least one ransomware attack. Notably, while the Healthcare and Public Health sector suffered the most, reporting 210 attacks, sectors pivotal to ICS networks and governmental organizations were also targeted: the Defense Industrial Base reported 1 attack, Water and Wastewater Systems 3, Chemical 19, Energy 15, Government Facilities 115, and Critical Manufacturing 157. For instance, a ransomware attack on a major chemical company could jeopardize not only its production but also pose environmental risks should systems controlling hazardous materials be compromised. In 2022, three ransomware variants predominantly targeted U.S. critical infrastructure: HIVE, with 87 attacks; ALPHV/BlackCat, with 114; and LOCKBIT, with 149. Several cyber-attacks, such as the MOVEit data breach in May 2023 and the Colonial Pipeline ransomware attack in May 2021, have been so impactful that they commanded national attention. The DarkSide hacking group's assault on the Colonial Pipeline, initiated on May 6th, 2021, stands as one of the most substantial and publicly acknowledged cyber-attacks against U.S. critical infrastructure. The group exploited an exposed Virtual Private Network (VPN) password, paving the way for initial intrusion and subsequent data theft. A mere day later, DarkSide unleashed a ransomware attack that compromised vital accounting and billing systems, prompting an immediate shutdown of the pipeline to mitigate further ransomware proliferation across its network. This crisis spurred a robust response from the U.S. president and regulators, culminating in a national emergency declaration related to the pipeline shutdown on May 9th, 2021. This incident mirrors the 2017 NotPetya ransomware attack that significantly impacted the shipping giant Maersk, highlighting an urgent need for fortified cybersecurity across various industries. Future incidents, akin to the Colonial Pipeline attack, could potentially be mitigated—or entirely averted—should government agencies and private entities scrutinize system vulnerabilities, exploring various ransomware types and entry points. Proactive measures, such as conducting experiments on VPN accounts or auditing passwords to pinpoint duplicate usage across diverse systems and software, might illuminate feasible entry points and vulnerability zones within an organization's systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Synchronic Web

The Synchronic Web is a distributed network for securing data provenance on the World Wide Web. By enabling clients around the world to freely commit digital information into a single shared view of history, it provides a foundational basis of truth on which to build decentralized and scalable trust across the Internet. Its core cryptographical capability allows mutually distrusting parties to create and verify statements of the following form: “I commit to this information—and only this information—at this moment in time.” The backbone of the Synchronic Web infrastructure is a simple, small, and semantic-free blockchain that is accessible to any Internet-enabled entity. The infrastructure is maintained by a permissioned network of well-known servers, called notaries, and accessed by a permissionless group of clients, called journals. Through an evolving stack of flexible and composable semantic specifications, the parties cooperate to generate synchronic commitments over arbitrary data. When integrated with existing infrastructures, adapted to diverse domains, and scaled across the breadth of cyberspace, the Synchronic Web provides a ubiquitous mechanism to lock the world’s data into unique points in discrete time and digital space. This document provides a technical description of the core Synchronic Web system. The distinguishing innovation in our design—and the enabling mechanism behind the model—is the novel use of verifiable maps to place authenticated content into canonically defined locations off-chain. While concrete specifications and software implementations of the Synchronic Web continue to evolve, the information covered in the body of this document should remain stable. We aim to present this information clearly and concisely for technical non-experts to understand the essential functionality and value proposition of the network. In the interest of promoting discourse, we take some liberty in projecting the potential implications of the new model.

97 MATHEMATICS AND COMPUTING↗

Autonomous Intelligence Measurements and Sensor Systems (AIMS): Gaussian Processes in Remote Sensing: Literature Review

Power grid resilience and reliability is crucial to supporting critical infrastructure. Service interruptions can have devastating consequences to communication, emergency, and transportation services, just to name a few. In addition to infrastructure, power services are crucial to everyday life. Nearly every element of modern-day living relies on a stable and functioning power grid - heating and cooling systems to lighting, refrigeration, telecommunications, and internet access. Interruptions in the power supply can range from minor inconveniences, such as the temporary loss of internet or television services, to more significant problems, like the inability to access medical equipment or emergency services during critical situations. As climate conditions worsen, the reliability of the power grid becomes even more significant. Extreme weather events, such as hurricanes, wildfires, or severe storms, can cause serious damage to power infrastructure, leading to prolonged power outages. Rising temperatures and changing weather patterns can strain the grid, resulting in increased demand for electricity, stressing transmission and distribution systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Precursor Analysis Report: SQL Slammer Worm Infection of Davis-Besse Nuclear Power Plant 2003

The SQL Slammer Worm Infection of Davis-Besse Nuclear Power Plant 2003 Precursor Analysis Report leverages publicly available information about Davis-Besse’s 2003 cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. On 25 January 2003, the SQL Slammer worm infected more than 90% of vulnerable hosts and crashed the internet in 10 to 15 minutes, making it one of the fastest spreading worms in history. SQL Slammer is a fileless, memory-resident worm that remotely exploits a stack-based buffer overflow vulnerability on local hosts to intensively scan and rapidly self-propagate across the internet. The worm infected approximately 300,000 unpatched hosts running Microsoft Structured Query Language (SQL) Server 2000 or Microsoft Desktop Engine (MSDE) 2000 with SQL Server Resolution Service. The SQL Slammer worm indirectly infected FirstEnergy’s Davis-Besse nuclear power plant by first infecting a consultant’s company network server and then propagating through an external misconfigured connection into Davis-Besse’s site network. The infection caused major network congestion, slow performance, data overloads, and the inability of local hosts to communicate with each other, which eventually caused a loss of availability and a loss of view when the Safety Parameter Display System (SPDS) and Plant Process Computer (PPC) crashed. At the time of the infection, the plant was already offline, the digital monitoring systems had redundant analog backups, and the plant control and safety functions were not affected, so there were no concerns of a safety breach. However, this incident resulted in many lessons learned and spawned important discussions about cybersecurity’s role in nuclear safety and electric power reliability regulation, policy, and guidance. Researchers and analysts identified 10 unique techniques utilized during the attack with a total of 640 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Eight of the identified techniques used during Davis-Besse cyber attack were precursors to the triggering event. Analysis identified 596 observables associated with these precursor techniques, 428 of which were assessed to have an increased likelihood of being perceived in the 331 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber↗

A System of Agents for Supporting Optimization and Control of a Connected Community

The residential sector consumes a significant portion of the electricity sold in the United States. Above 60% of the energy used in the sector is used to operate heating, ventilation, and air conditioning (HVAC) systems and water heating (WH) systems. With the increase of intelligence in the grid and the new decision and control options enabled by the Internet of Things; control of these devices can be used to support the grid. Therefore, this article presents a scalable multiagent system for optimizing HVAC and WH systems while maintaining comfort. It allows a utility to orchestrate the shifting of energy from critical periods without direct control, but instead by using a price signal. The architecture, optimization formulation, implementation strategy and results from an implementation project are discussed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Autonomous Wireless Technology Detection in Seamless IoT Applications

The ever-increasing use of Internet of Things (IoT) devices results in the implementation of multiple wireless technologies that would not only cater their data rate requirements but also support various applications. To optimize the energy efficiency and security of the wireless transmission, it is imperative to identify the wireless technologies in various IoT implementations. Many of the existing approaches are based on measuring only the receiving signal strength indicator (RSSI). However, such approaches may not work well because of transmit power control and complex channel variations among different wireless technologies. In this article, we propose an autonomous wireless detection scheme that considers multiple distinguishable physical (PHY)-layer settings for real-time identification of wireless technologies for real-time applications. Specifically, the proposed scheme relies on the PHY-layer measurements of the targeted spectrum. Transmission settings, such as bandwidth, carrier frequency, and RSSI are estimated from the raw in-phase and quadrature-phase (I/Q) measurements. In addition, a symbol-level extraction scheme is implemented to extract unique features of modulation settings. These aforementioned features are applied to a machine learning process to identify the received wireless technologies. Compared with raw I/Q measurements, the extracted features are much simplified and, thus, the machine learning classifier can be designed with a simple structure for fast processing on IoT nodes. Finally, the proposed schemes are primarily evaluated theoretically, followed by implementing them on a USRP software-defined radio (SDR)-based hardware testbed. The evaluation results demonstrate high accuracy in the real-time detection of different wireless technologies for seamless IoT applications.

42 ENGINEERING↗

Model Residuals as Shields: A Two-Level Formulation to Defend Smart Grids From Poisoning Attacks

The advancement of smart grids presents both vast opportunities and heightened cybersecurity risks. Data-driven defense mechanisms, though designed as a shield against these threats, can fall prey to poisoning attacks. We delve into regression settings, underscoring the imperative to fortify defenses against a spectrum of poison ratios, notably those above 0.5—an issue scarcely addressed in prior studies. Recognizing the susceptibilities of smart grids and their manipulable sensors, we exploit the very intent of poisoning attacks, compromising model accuracy, as our defense mechanism. Our proposed two-level optimization framework discerns between poisoned and authentic data based on model residuals, outperforming or matching existing methods in 72% to 77% of precision and 75% to 80% of recalls across various poisoning attacks, poison ratios, and datasets. Once the authentic data are identified, the trained model is adaptable for a variety of applications. Comprehensive evaluations on different smart grid datasets, pitted against myriad poisoning schemes, validate our methodology’s edge over existing methods. Here, we also shed light on the implications of model misspecification originating from temporal auto-correlation, a common feature in Internet of Things and smart grid data.

Adversarial machine learning (ML)↗

Advanced Data Science Model for Detecting Intelligent Malware

This study focused on developing a robust artificial intelligence (AI) model capable of detecting and characterizing advanced malware in Internet of Things (IoT) devices using network data. By analyzing network traffic with various machine learning (ML) models, our AI model can identify and characterize malicious activities to significantly improve malware detection accuracy and reliability as compared to traditional methods. The developed AI/ML model was trained using network data from IoT devices, leveraging classifiers such as Random Forest, Gradient Boosting, AdaBoost, and others to optimize detection performance. This project demonstrates a scalable framework for real-time malware detection and characterization in IoT networks, capable of identifying infected devices and facilitating the necessary steps to remove or isolate them, thereby preventing further infections. Although digital twin (DT) integration is not yet implemented in the current model, it represents a promising future enhancement. By creating a virtual replica of physical IoT devices, DT technology would allow for real-time monitoring and analysis without directly accessing operational technology, thus reducing the risk of compromising or reducing the performance of actual devices. This integration would further enhance the security of IoT ecosystems, combining AI technology to better flag and detect indications of malware-infected devices within a nuclear system environment.

42 ENGINEERING↗

Cyber Labeling for Energy Industrial IoT

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security and Emergency Response (CESER), at the request of the Deputy National Security Advisor for Cyber and Emerging Technologies, Anne Neuberger, initiated research in 2023 to develop a cybersecurity labeling proof-of-concept for energy products to expand on the Federal Communications Commission’s (FCC) proposed U.S. Cyber Trust Mark program. DOE mobilized researchers from six National Laboratories to develop and gather feedback on a proof-of concept label for solar inverters and smart meters, which serve as representative products for market-facing energy sector Industrial Internet of Things (IIoT). This report details the research team’s process across two phases and the resulting findings, which include challenges facing cyber labeling programs and recommendations to implement an expanded IIoT cyber labeling program in the U.S.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

Smart Building Technology Training Modules for Academic and Professional Education

Smart building technologies are a new suite of resources that improve building energy efficiency and resilience, reduce carbon emissions, and provide load flexibility to the grid. However, in both college curricula and building professionals’ continuing education, there is a lack of systematic instruction on smart building technologies–topics that include smart building concepts, key components, smart building controls, “Internet of Things” (IoT) devices, and how to integrate multiple energy systems including distributed energy resources (DER). This major gap in smart building education prevents stakeholders from understanding and adopting smart building technologies in building design and operations. Slipstream leads a DOE-funded project developing a semester-long smart building curriculum for college students and adapting the contents into 16 training videos for building professionals and the general public. The education and training cover the drivers and benefits of smart building technologies, key building energy systems, the latest sensor technologies and IoT devices, and focus on topics related to smart building controls (i.e., energy management information systems, smart building control platforms, cybersecurity, grid-interactive-efficient buildings (GEBs), smart building control methods, and occupant-centric control. This paper describes the project approach, provides outlines of the training materials, and identifies lessons learned in creating the content. We also suggest ways to scale the instruction of smart building concepts to empower the workforce to accelerate the adoption of smart building technologies in the real world.

99 GENERAL AND MISCELLANEOUS↗

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Reinforcement Learning for Intelligent Building Energy Management System Control *

A building energy management system (BEMS) is a computer-based system designed to monitor and control a building's energy needs. Modern BEMS rely on the sensing and connectivity capabilities of Internet of Things (IoT) technology to intelligently adjust the energy consumption to reduce cost while respecting the consumers' preferences. Increasingly, control decisions are made based on predictions by models trained using supervised machine learning methods, which still requires control policies to be formulated in a rule-based fashion. When using reinforcement learning (RL) instead, control policies are learned by observing the utility in terms of cost and comfort associated with actions such as a change in the heating system's setpoint. The resulting RL-based controllers can capture not only the dynamics of the building and the associated electrical devices, but also fluctuations in electricity prices and user demand, avoiding the need to combine multiple predictive models with tailored control policies. This chapter will provide an overview of RL-based approaches for BEMS. After sketching the taxonomy of general RL methods, we discuss the implications of relying on the individual methods in a BEMS context. Existing work applying RL is presented along the key devices controlled by BEMS systems. Finally, we summarize the state-of-the-art and sketch limitations and open research directions.

Kotevska, Olivera↗

Smart connected worker edge platform for smart manufacturing: Part 1—Architecture and platform design

Abstract The challenge of sustainably producing goods and services for healthy living on a healthy planet requires simultaneous consideration of economic, societal, and environmental dimensions in manufacturing. Enabling technology for data driven manufacturing paradigms like Smart Manufacturing (a.k.a. Industry 4.0) serve as the technological backbone from which sustainable approaches to manufacturing can be implemented. Unfortunately, these technologies are typically associated with broader and deeper factory automation that is often too expensive and complex for the small and medium sized manufacturers (SMMs) that comprise the majority of manufacturing business in the USA and for whom their most valuable asset are the people whose jobs automation while replace. This paper describes an edge intelligent platform to integrate internet‐of‐things technologies with computing hardware, software, computational workflows for machine learning, and data ingestion, enabling SMMs to transition into smart manufacturing paradigms by leveraging the intelligence of their people. The platform leverages consumer grade electronics and sensors (affordable and portable), customized software with open source software packages (accessible), and existing communication network infrastructures (scalable). The software systems are implemented via Kubernetes orchestration of Docker containerization to ensure scalability and programmability. The platform is adaptive via computational workflow engines that produce information from data by processing with low‐cost edge computing devices while efficiently accessing resources of cloud servers as needed. The proposed edge platform connects workers to technological resources that provide computational intelligence (i.e., silicon‐based sensing and computation for data collection and contextualization) to enable decision making at the edge of advanced manufacturing.

Kim, Yoon G.↗

Dual-Phase Malicious User Detection Scheme for IM-OFDMA Systems Using IQ Imbalance

Physical-layer security techniques have contributed to the achievement of various security objectives in an efficient and lightweight manner. Thus, these techniques have been widely considered for limited-resource networks such as Internet of Things networks. Among the different security objectives, malicious user detection by exploiting physical-layer parameters has demonstrated efficient performance. In this work, malicious user detection in the recently proposed index modulation-based orthogonal frequency division multiple access (IM-OFDMA) is addressed. The proposed malicious user detection scheme exploits the hardware impairments, especially the in-phase and quadrature imbalance parameters, for both legitimate and malicious users to design a dual-phase efficient detection scheme. The proposed scheme accounts for the special characteristics of IM-OFDMA transmission that are different from other multiple-access techniques. The performance of the proposed scheme was evaluated considering detection probability and false alarm probability performance metrics. Moreover, closed-form expressions of these metrics were derived for both phases and were validated by Monte Carlo simulation results under different configurations of IM-OFDMA systems.

Alaca, Ozgur [ORNL] (ORCID:0000000153713758)↗