Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

Mapping Critical Vulnerabilities in Natural Gas Pipeline Systems through Network Centrality and GIS Analytics

Natural gas plays a central role in the US energy landscape, providing 43% of electricity generation in 2023. Its exclusive recovery ability on pipelines for transmission underscores the importance of understanding the disruption recovery ability of this infrastructure. This study employs a network-based analytical framework integrating geographic information systems (GIS) with multiple centrality measures—betweenness, closeness, degree, and eigenvector—to pinpoint key segments and evaluate the structural robustness of the national pipeline network. Pipelines are grouped by System ID and Operator ID to capture variations across organizational and physical structures. The analysis reveals uneven patterns of network influence, where certain pipelines function as critical connectors or dominant hubs. Spatial mapping highlights geographic dependencies and potential chokepoints, offering a clear view of where targeted risk prevention measures would be most effective. The findings provide practical guidance for prioritizing maintenance, enhancing system robustness, and mitigating risks to ensure a stable and secure energy supply. Future research will expand the framework to incorporate dynamic operational data and real-time network behavior.

Peterson, Steven [ORNL] (ORCID:0000000287672998)↗

Securing Solar for the Grid: Spring 2024 IAB Meeting

The Spring 2024 IAB meeting will focus on updates from the research team and collective feedback and inputs for an updated Roadmap for Solar Cybersecurity. Researchers from the four DOE National Laboratories will present with industry counterparts for the major research tasks within the S2G program, including: Solar Cybersecurity Standards and Certifications, Solar Risk Assessments & Mitigation, Solar Supply Chain Assessment, Network Monitoring Tools and Analysis, and Training and Workforce Development. Sandia National Laboratories developed an original Roadmap for PV Cybersecurity in 2017. This year, we are updating that roadmap to reflect the current state of research and industry and identify gaps and priorities still to be addressed. We look forward to the IAB’s input on key topics for the roadmap.

14 SOLAR ENERGY↗

Integrated Research Infrastructure Architecture Blueprint Activity (Final Report 2023)

The complexity of scientific pursuits is increasing rapidly with aspects that require dynamic integration of experiment, observation, theory, modeling, simulation, visualization, machine learning (ML), artificial intelligence (AI), and analysis. Research projects across the Department of Energy (DOE) are increasingly data and compute intensive. Innovative research teams are accelerating the pace of discovery by using high-performance computational and data tools in their research workflows and leveraging multiple research infrastructures. Additionally, several recent high-level U.S. government reports underscore the necessity of a new advanced computing ecosystem for international competitiveness and national security. International competitors are moving forward with major research infrastructure integration efforts that seek to capture a competitive advantage in the global innovation race. Owing to its unparalleled constellation of world-class experimental and observational facilities and high-performance and extreme-scale computational, data, and networking infrastructure, DOE is positioned to be a global leader in this new era of integrated science. However, this new integration paradigm will demand continuing evolution to ensure the U.S. remains a global leader in research and innovation. The DOE Office of Science (SC) has seized on the strategic importance of integration and has adopted a vision for Integrated Research Infrastructure (IRI): To empower researchers to meld DOE’s world-class research tools, infrastructure, and user facilities seamlessly and securely in novel ways to radically accelerate discovery and innovation. To respond to the evolving computational requirements of research and the competitive international innovation landscape, experimental facilities could be connected with high performance computing resources for near real-time analysis, and resources should be provided for merging enormous and diverse data for AI/ML techniques and analysis.

97 MATHEMATICS AND COMPUTING↗

A hardware-in-the-loop (HIL) testbed for cyber-physical energy systems in smart commercial buildings

In recent years, there has been a growing trend toward the development of smart buildings that rely on cyber-physical systems (CPS) to optimize occupant comfort, safety, and energy efficiency. To ensure the reliable and efficient operation of CPS with designed control strategies, it is important to evaluate their performance under various scenarios before deploying them in the real world. This is where a Hardware-in-the-loop (HIL) testbed designed for studying sensor and control-related studies in smart buildings can be highly valuable. With the growing threat of cyber-attacks and physical faults targeting smart buildings, it is essential to ensure the security of building operations. A HIL testbed can emulate cyber-attack and physical fault scenarios, allowing researchers to develop and test threat detection and mitigation algorithms. This enables researchers to identify potential issues and optimize the algorithms in a safe and controlled environment before they are deployed in real-world settings, reducing the risk of failures that can negatively impact occupant comfort, safety, and energy efficiency. Therefore, this paper developed a HIL testbed designed for cyber-physical energy systems (e.g. buildings automation system (BAS)) in smart commercial buildings. The HIL testbed is comprised of a real-time building and Heating, Ventilation, and Air-Conditioning (HVAC) emulator using Modelica-based dynamic models, a set of BAS controllers, and a BAS computer server. The data generation capability of the HIL testbed is demonstrated by tracking normal and faulty operating data in the BAS, as well as monitoring detailed network traffic in the local BAS network. Here, this study further demonstrates the HIL testbed’s capability by conducting case studies on real-time physical fault and cyber-attack experiments using a Department of Energy (DOE) prototype commercial building. It is anticipated that the fully functional HIL testbed will be utilized for a variety of sensor and control-related studies, including but not limited to testing, developing, validating of different HVAC control strategies, fault detection & diagnosis, energy monitoring and analysis, cyber security study, etc.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Real-Time Xenon Sensor Analysis Report

Radiotracer release experiments were performed at the Nevada National Security Site in October 2022. The overall experiment was called the RElease ACTivity (REACT) experiment. Twenty-two real-time xenon sensors were deployed for each of four releases. Initial, quick-look analysis results were reported in December 2022. This report reviews the more comprehensive offline analysis effort that was conducted during the remainder of fiscal year 2023 by the Dynamic Networks venture. Improved energy stabilization routines were implemented along with an improved background subtraction routine compared to the original quicklook calculations. The relative detection efficiencies of all real-time sensors were examined. Finally, simulated detector response functions were coupled to two different meteorological models using the measured conditions for the final release (REACT-04) to compare simulated detections with measurements. While there is some agreement between the models and measured data on the detection locations and timing, there is less agreement on the magnitude of those detections. Future sensor and meteorological modeling work will be needed to improve the agreement and to examine the additional releases (REACT-01 through REACT-03).

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Subsurface microbial communities as a tool for characterizing regional-scale groundwater flow

Subsurface microbial community distribution patterns are influenced by biogeochemical and groundwater fluxes and may inform hydraulic connections along groundwater-flow paths. This study examined the regional-scale microbial community of the Death Valley Regional Flow System and evaluated whether subsurface communities can be used to identify groundwater-flow paths between recharge and discharge areas. Samples were collected from 36 sites in three groundwater basins: Pahute Mesa–Oasis Valley (PMOV), Ash Meadows (AM), and Alkali Flat–Furnace Creek Ranch (AFFCR). Microbial diversity within and between communities varied by location, and communities were separated into two overall groups that affiliated with the AM and PMOV/AFFCR basins. Network analysis revealed patterns between clusters of common microbes that represented groundwaters with similar geochemical conditions and largely corroborated hydraulic connections between recharge and discharge areas. Null model analyses identified deterministic and stochastic ecological processes contributing to microbial community assemblages. Most communities were more different than expected and governed by dispersal limitation, geochemical differences, or undominating processes. However, certain communities from sites located within or near the Nevada National Security Site were more similar than expected and dominated by homogeneous dispersal or selection. Overall, the (dis)similarities between the microbial communities of DVRFS recharge and discharge areas supported previously documented hydraulic connections between: (1) Spring Mountains and Ash Meadows; (2) Frenchman and Yucca Flat and Amargosa Desert; and (3) Amargosa Desert and Death Valley. However, only a portion of the flow path between Pahute Mesa and Oasis Valley could be supported by microbial community analyses, likely due to well-associated artifacts in samples from the two Oasis Valley sites. This study demonstrates the utility of combining microbial data with hydrologic, geologic, and water-chemistry information to comprehensively characterize groundwater systems, highlighting both strengths and limitations of this approach.

54 ENVIRONMENTAL SCIENCES↗

MiniMOD

SAND2025-03854O MiniMod is a user-friendly software tool designed to assess the performance of high-performance computing (HPC) systems. Researchers can use the program to test communication methods and computational tasks to understand how different setups can affect application efficiency. This software is particularly useful for optimizing network performance in scientific research, simulations, and data analysis. MiniMod‘s flexible design allows users to make informed decisions about their computing environments, which can enhance productivity and results in real-world applications. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Dosanjh, Matthew [Sandia National Lab. (SNL-CA), L↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Tight Practical Bounds for Subgraph Densities in Ego-centric Networks

SAND2025-11782O Tight Practical Bounds for Subgraph Densities in Ego-centric Networks is a software tool for calculating the “subgraph spread ratio” for social network analysis. This value is useful in network analysis for determining the amount of exogenous and endogenous pressure on a graph. It can distinguish between networks coming from different sources, e.g. distinguishing a graph of Facebook data versus a graph of Wikipedia data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Mattes, Connor↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗

scANN

SAND2025-00656O scANN, also known as sampling by coinflips artificial neural networks, is a software tool that estimates uncertainty in artificial intelligence by performing Monte Carlo analysis on the weight matrices of feedforward neural networks. This computationally intensive process aims to explore the potential value added by future probabilistic hardware. The program’s output helps researchers gain insights into how probabilistic neural networks work. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

SciDAC↗

The Lithuania 100% Renewable Energy Study - Interim Results: Electricity System Scenarios for 2030 [Slides]

Lithuania's Energy Vision aims to achieve self-sufficiency in electricity generation by 2035 and transition to 100% renewable energy as soon as possible while maintaining affordability, reliability, and energy security. The Lithuania Energy Agency (LEA) is partnering with the National Renewable Energy Laboratory (NREL) to conduct the Lithuania 100% Renewable Energy Study (Lithuania 100) to provide evidence-based analysis for development of Lithuania's National Energy Independence Strategy. The Lithuania 100 Study leverages unique tools and capabilities of NREL to provide rigorous technical analysis of clean energy policies to achieve 100% renewable energy, and assess impacts on electricity grid operations, hydrogen system development, electricity distribution networks, air quality, and human health outcomes. The study is supported by a stakeholder committee chaired by the Ministry of Energy of Lithuania and implemented by four technical working groups. This report provides highlights of key interim results from modeling of Lithuania's near-term electricity grid through the year 2030. Results show that Lithuania has sufficient renewable energy potential, flexible generation capacity, and interconnection with neighboring European Union countries to reliably meet projected 2030 electricity demand with 100% renewable energy. A range of scenarios were modeled, each of which achieves at least 100% renewable energy in electricity, on average over the year, by 2030. Potential demands for hydrogen across industrial and transportation sectors were also evaluated, as well as the cost of hydrogen produced in Lithuania by 2030.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Seamless Wireless Communication Platform for Internet of Things Applications

The rapid growth of the Internet of Things (IoT) devices resulted in the proliferation of wireless technologies to cater to their increasing data rate requirements and support multiple applications. However, such ever-increasing wireless technologies present numerous challenges such as incompatible wireless standards, increased energy consumption, and insecure communication. The traditional gateways proposed in the literature suffers from limitations such as computational complexity, resource requirements, increased cost, and device size. We vision an era of seamless wireless communication to alleviate the aforementioned challenges in IoT applications. through three inter-dependent functionalities namely detection and identification of wireless technologies, energy-efficient transmit power control, and secure end-to-end communication. To prove the concept, a new gateway is proposed to achieve these three functionalities with only physical layer measurements so that the different communication protocols in the higher layers can be avoided. Novel schemes are conceptualized for resource-limited seamless IoT applications. Moreover, the conceptual seamless IoT platform is validated through software-based computer simulation and software-defined radio-based testbed implementation. Finally, the preliminary analysis demonstrates that the proposed platform has great potential in advancing seamless IoT applications.

97 MATHEMATICS AND COMPUTING↗

Distributed Software-Defined Network Architecture for Smart Grid Resilience to Denial-of-Service Attacks

An important challenge for smart grid security is designing a secure and robust smart grid communications architecture to protect against cyber-threats, such as Denial-of-Service (DoS) attacks, that can adversely impact the operation of the power grid. Researchers have proposed using Software Defined Network frameworks to enhance cybersecurity of the smart grid, but there is a lack of benchmarking and comparative analyses among the many techniques. In this work, a distributed three-controller software-defined networking (D3-SDN) architecture, benchmarking, and comparative analysis with other techniques is presented. The selected distributed flat SDN architecture divides the network horizontally into multiple areas or clusters, where each cluster is handled by a single Open Network Operating System (ONOS) controller. A case study using the IEEE 118-bus system is provided to compare the performance of the presented ONOS-managed D3-SDN, against the POX controller. In addition, the proposed architecture outperforms a single SDN controller framework by a tenfold increase in throughput; a reduction in latency of > 20%; and an increase in throughput of approximately 11% during the DoS attack scenarios.

Agnew Jr., Dennis↗

WEC as a multiport

SAND2025-00555O WEC as a multiport is a software tool that simplifies the modeling and design of ocean wave energy converters (WECs) using a multi-port network framework in the frequency domain. Users can simulate the dynamic interactions between WECs and ocean waves, optimizing energy extraction and system performance. This tool supports the analysis of complex wave energy systems, aiding in the development of efficient and effective WEC designs. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Coe, Ryan↗

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy↗