Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “intrusion detection systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Assessing Methodologies for Detecting Water Intrusion in Wall Systems: Phase 2

Studies by the University of Florida, the Environmental Protection Agency (EPA) and the U.S. Department of Housing (HUD) have revealed that there is a substantial fraction of commercial and residential buildings that have been exposed to moisture resulting in damage or durability problems. Water intrusion into building envelope components leads to a variety of undesirable conditions such as mold, wood rot, corrosion, and aesthetic damage. Tests methods that are presently used to evaluate the amount of water intrusion into a building envelope component are usually qualitative in nature. For example, ASTM E 331, Standard Test Method for Water Penetration of Exterior Windows, Curtain Walls, and Doors by Uniform Static Air Pressure Difference requires that you “observe and record points of water leakage, if any.” This test was originally developed to assess the performance of fenestration products but is commonly adapted to evaluate other enclosure assemblies. However, when it is typically used for walls, this procedure is limited to recognizing if the moisture is visually observable from the backside side of the sheathing. It does not address moisture that is absorbed in the layers of the building envelope component, which could impact the durability of the assembly. Clearly a quantitative means of determining water penetration would improve the quality of this type of test and assist with better understanding the resultant impact on enclosure assemblies. In 2018-20, Oak Ridge National Laboratory, in conjunction with the Air Barrier Association of America, initiated a research project to address this issue. The purpose of that study was to evaluate nine different methods of detecting moisture intrusion through a wall assembly. air and water barrier. The wall assemblies included metal frame construction faced with gypsum sheathing and both self-adhered and fluid applied air and water barriers (AWB) were evaluated for this exercise. This project did not test the efficacy of the different AWBs, rather, fasteners were purposely installed in various ways to foster water penetration and activate the different methods of detection. Each detection method was evaluated for five features that included simplicity of use, cost of implementation, whether the method was quantitative or subjective, accuracy, and applicability. A scale of green/yellow/red was used to assess each feature where green was acceptable, yellow was borderline, and red was not to be pursued at this time. This report covers additional research that has been undertaken to extend the activities initiated in this earlier project with refinements for specific detection methods and considerations for expansion related to field versus laboratory testing standards.

42 ENGINEERING↗

Designing an Intrusion Detection for an Adjustable Speed Drive System Controlling a Critical Process

In this article, we address the cyber-security problem of industrial control systems (ICSs) when their sensor measurements may be compromised due to an attacker who has intercepted those measurements via a network. We introduce a general-purpose method “Dynamic Watermarking (DW)” to detect potential cyber-intrusions on speed sensor measurements within industrial control systems, which deploy an adjustable speed drive (ASD) to control a critical process. The DW method is injecting a random private low-amplitude signal with a zero mean Gaussian distribution, “watermark”, into one of the input phase voltages powering the ASD system. The watermark signal propagates through the system including pulse width modulation (PWM) power conversion stage and motor, then ultimately appears in the speed sensor measurements. By deploying two statistical DW tests with two proper thresholds, the system can detect potential cyber-intrusions or unobservable cyber-attacks such as replay attacks and false data injection attacks (FDIA). The DW method tested on a laboratory-scale ASD system experimentally to protect the system against cyber-intrusions. This system, powered by a commercial PWM drive operating at 208 V, 3-phase, and 3.7 kW, served as our experimental platform.

42 ENGINEERING↗

Anonymization of Network Traces Data through Condensation-based Differential Privacy

Network traces are considered a primary source of information to researchers, who use them to investigate research problems such as identifying user behavior, analyzing network hierarchy, maintaining network security, classifying packet flows, and much more. However, most organizations are reluctant to share their data with a third party or the public due to privacy concerns. Therefore, data anonymization prior to sharing becomes a convenient solution to both organizations and researchers. Although several anonymization algorithms are available, few of them allow sufficient privacy (organization need), acceptable data utility (researcher need), and efficient data analysis at the same time. This article introduces a condensation-based differential privacy anonymization approach that achieves an improved tradeoff between privacy and utility compared to existing techniques and produces anonymized network trace data that can be shared publicly without lowering its utility value. Our solution also does not incur extra computation overhead for the data analyzer. A prototype system has been implemented, and experiments have shown that the proposed approach preserves privacy and allows data analysis without revealing the original data even when injection attacks are launched against it. When anonymized datasets are given as input to graph-based intrusion detection techniques, they yield almost identical intrusion detection rates as the original datasets with only a negligible impact.

97 MATHEMATICS AND COMPUTING↗

Advanced Grid Operational Technology Edge-Level Threat Detection

This report presents a deployable solution to improve the cybersecurity situational awareness of the legacy SCADA system infrastructure in power grids. The main goal of this project is to provide system owners and operators a highly trusted, intelligent alarm system and comprehensive situational awareness of ongoing or potential cybersecurity threats on the grid network. The key contributions of this project include: (1) the development of software, the Intrusion Detection Visualizer for the Operational Technology Network (IViz-OT), to visualize and locate intrusions on the grid network; (2) testing the signature-based Hybrid Intrusion Detection for Energy Systems (HIDES) for different types of intrusions; (3) the integration of HIDES and IViz-OT into the visualization dashboard; and (4) real-time testing using a hardware-in-the-loop test bed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

On the Limits of EM Based Detection of Control Logic Injection Attacks In Noisy Environments

The difficulty in applying traditional security mechanisms in Industrial Control System (ICS) environments makes a large portion of these mission-critical assets vulnerable to cyber attacks. Therefore, there is a dire need for the development of novel security mechanisms specifically designed to protect such critical systems. Recently a lot of attention has been given to mechanisms that exploit the EM emanations of devices for defense purposes. Such practices may lead to the development of robust external and non-intrusive anomaly detection systems. Nevertheless, the majority of current work in the area neglects to consider the implications of real-life environments, particularly environmental noise. In this work, we explore the limits of EM-based anomaly detection towards identifying injection attacks in control logic software in noisy environments. Our study conducted upon both synthetically generated and real signals identified that indeed environmental noise might significantly degrade the accuracy of the anomaly detection process. Experiments done upon synthetic data indicated that assuming that signals are captured with high sampling rates, even minor code injections can be detected with above-90% accuracy in noisy environments where SNR is up to -2dB. This is true even if naive detection methods are considered. Moreover, experiments done using a real-life testbed attest that even single-instruction injections can be detected with near-perfect accuracy in relatively clean environments. Finally, noise-elimination techniques can drastically improve the reliability of the detection mechanism even in noisy environments.

97 MATHEMATICS AND COMPUTING↗

Artificial Intelligence for Energy Systems Cybersecurity

Artificial intelligence and machine learning systems have the potential to influence the future design and implementation of cybersecurity systems for the power grid. These systems may enhance the overall operation of the power system by leveraging and making sense of massive amounts of data. However, we must also understand how AI/ML will need to be protected from cyber threat actors. We discuss the existing insights the NREL team has developed using AI/ML systems and then present resources including ESIF and the Cyber Energy Emulation Platform that can be used to generate training data and insights. We end by offering suggestions on priority research paths for AI in cybersecurity.

artificial intelligence↗

General-Purpose Unsupervised Cyber Anomaly Detection via Non-Negative Tensor Factorization

Distinguishing malicious anomalous activities from unusual but benign activities is a fundamental challenge for cyber defenders. Prior studies have shown that statistical user behavior analysis yields accurate detections by learning behavior profiles from observed user activity. These unsupervised models are able to generalize to unseen types of attacks by detecting deviations from normal behavior, without knowledge of specific attack signatures. However, approaches proposed to date based on probabilistic matrix factorization are limited by the information conveyed in a two-dimensional space. Non-negative tensor factorization, on the other hand, is a powerful unsupervised machine learning method that naturally models multi-dimensional data, capturing complex and multi-faceted details of behavior profiles. Herein, our new unsupervised statistical anomaly detection methodology matches or surpasses state-of-the-art supervised learning baselines across several challenging and diverse cyber application areas, including detection of compromised user credentials, botnets, spam e-mails, and fraudulent credit card transactions.

97 MATHEMATICS AND COMPUTING↗

DER Translate

SAND2024-13723O This software translates and maps any .xlsx-based distributed energy resource (DER) device from the SunSpec certification registry (https://sunspec.org/certified-registry/) to a JSON-based DER models map. It is then read by DER monitoring tools for applications such as network intrusion detection and system health monitoring. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Fragkos, Georgios↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

Cyber Energy Emulation Platform (CEEP) [SWR-20-102]

NREL's Cyber-Energy Emulation Platform (CEEP) provides the capability to realize cyber-energy security and resilience through automation and orchestration of virtualized systems and software defined networks for the electric grid. CEEP enables testing and validation of grid-security and -control methodologies as the grid evolves to include smart technologies/systems, such as virtualization and containerization of grid components, software defined networking, simulation and co-simulation frameworks, and hardware in the loop. CEEP is a modular system that can be distributed and deployed across different hardware infrastructure sizes and network architectures. For example, CEEP can visualize, emulate, and/or coordinate the Smart-Grid Network Visualization, Intrusion Detection, and Network Healing system. Using CEEP, intrusion-detection and network-self-healing solutions can be deployed at grid control centers, within secure private clouds, and in cyber-energy appliances.

Rivera, Joshua↗

Speaking Volumes About 3-D

In 1999, Genex submitted a proposal to Stennis Space Center for a volumetric 3-D display technique that would provide multiple users with a 360-degree perspective to simultaneously view and analyze 3-D data. The futuristic capabilities of the VolumeViewer(R) have offered tremendous benefits to commercial users in the fields of medicine and surgery, air traffic control, pilot training and education, computer-aided design/computer-aided manufacturing, and military/battlefield management. The technology has also helped NASA to better analyze and assess the various data collected by its satellite and spacecraft sensors. Genex capitalized on its success with Stennis by introducing two separate products to the commercial market that incorporate key elements of the 3-D display technology designed under an SBIR contract. The company Rainbow 3D(R) imaging camera is a novel, three-dimensional surface profile measurement system that can obtain a full-frame 3-D image in less than 1 second. The third product is the 360-degree OmniEye(R) video system. Ideal for intrusion detection, surveillance, and situation management, this unique camera system offers a continuous, panoramic view of a scene in real time.

Source record↗

Multilevel Cybersecurity for Photovoltaic Systems

The motivation behind this project is to protect critical infrastructure in electric power generation pertaining to solar photovoltaic (PV) systems. This growing renewable energy resource is becoming a more vital part of the nation’s energy portfolio, particularly since it has achieved grid-parity to existing generation methods in terms of cost. It is thus vital that steps be taken to ensure the cybersecurity of these assets. The project goal was to devise a multilevel cybersecurity solution to address PV security gaps at the inverter and system levels, and field test the solution under the supervision and review of a US-based solar inverter manufacturer and PV installer/operator. A two-level cyberattack defense approach was formulated whereby the first level, the solar inverter level, hardens individual devices and achieves a deeply cyber-secure inverter. The inverter level security involves a multi-layer defense-in-depth approach for securing the inverter while also providing data for the system level algorithms. The second level, the system level, addresses intrusion detection and restoration involving an ensemble of inverters and relevant systems.

14 SOLAR ENERGY↗

CANShield: Signal-based Intrusion Detection for Controller Area Networks

Modern vehicles rely on complex cyber-physical systems made up of hundreds of electronic control units (ECUs) connected through controller area network (CAN) buses. However, the CAN bus attack surface is increasing due to advanced features in automobiles, making it prone to injection attacks. The ordinary injection attacks disrupt the typical timing properties of the CAN data stream, and the rule-based intrusion detection systems (IDS) can easily detect them. However, advanced attackers can inject false data to the signal level, maintaining the regular pattern/frequency of the CAN messages. Such attacks can bypass the rule-based IDS or any anomaly-based IDS built on binary payload data. To make the vehicles robust against such intelligent attacks, we propose CANShield, a signal-based intrusion detection framework for the CAN bus that consists of three modules. A data preprocessing module handles the high-dimensional CAN data stream at the signal level and make them suitable for any machine learning model. A data analyzer module consists of multiple deep autoencoder networks, each analyzing the time series data from a different perspective. Finally, an attack detection module uses an ensemble method to make the final decision. Evaluation results on a standard signal-based dataset show the effectiveness of the CANShield in detecting five advanced attacks.

Shahriar, Md Hasan↗

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation

Advanced persistent threats and cyberattacks can impact wide-area monitoring, protection, and control (WAMPAC) system operation. Many cyber-physical system (CPS) testbeds have been developed for attack-defense experimentation and attack-resiliency tools evaluation for WAMPAC, but they are limited to a simulation-and-emulation based environment. This paper presents a quasi-realistic CPS attack-defense testbed-based framework for WAMPAC applications using the industrial substation and control center platforms such as eTerra integrated with the hardware-in-the-loop CPS smart grid testbed available at Iowa State University. The proposed framework includes various combinations of industry-grade substation and control center platforms, communication topologies, real-time digital simulators, and a novel cyber-physical distributed intrusion-and-anomaly detection system (D-IADS) for WAMPAC applications. The D-IADS includes a master at the control center and geographically distributed sensor devices at each substation. Each D-IADS sensor deployed at a substation or control center network monitors ingress and egress traffic, detect intrusions, and dispatch alerts to the D-IADS master. The D-IADS master centrally monitors and analyze the alerts and controls D-IADS sensors. We considered an EMP60 synthetic CPS grid as a case study to demonstrate the framework and proposed D-IADS for WAMPAC applications against cyberattack vectors such as Man-in-the-Middle DNP3 attack, denial-of-service, and data-integrity attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Networked Microgrid Cybersecurity Architecture Design Guide: A New Jersey TRANSITGRID Use Case

Microgrids require reliable communication systems for equipment control, power delivery optimization, and operational visibility. To maintain secure communications, Microgrid Operational Technology (OT) networks must be defensible and cyber-resilient. The communication network must be carefully architected with appropriate cyber-hardening technologies to provide security defenders the data, analytics, and response capabilities to quickly mitigate malicious and accidental cyberattacks. In this work, we outline several best practices and technologies that can support microgrid operations (e.g., intrusion detection and monitoring systems, response tools, etc.). Then we apply these recommendations to the New Jersey TRANSITGRID use case to demonstrate how they would be deployed in practice.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Statement of Work. Y-12 National Security Complex Security Infrastructure Revitalization Program Project - Combination Inspector

The Y-12 SIRP Quadrant 1, Quadrant 2, and Vehicle Barrier project involves the following summary elements. The perimeter intrusion detection and assessment system (PIDAS) is an existing system at the Y-12 National Security Complex, which is a government-owned facility located in Oak Ridge, Tennessee, and managed by Consolidated Nuclear Security, LLC (CNS) for the Department of Energy (DOE). National Technology and Engineering Solutions of Sandia, LLC (NTESS) is the engineering design agent and construction manager (CM) for the Y-12 SIRP effort. The Quadrants 1 and 2 portion of the project involves the replacement of the PIDAS, and the vehicle barrier portion of the project involves the installation of a continuous passive vehicle barrier alongside the inner PIDAS fence.

42 ENGINEERING↗