Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS↗

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a framework for consequence-driven applied risk analysis, enabling utilities to prioritize and mitigate potential threats effectively, and responsibly deploy cloud applications. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Resilient U.S. Land Ports of Entry

The continued operation of Land Ports of Entry (LPOE), managed by the Customs and Border Protection (CBP) and General Services Administration% is vital to the U.S. economy and security. Border faculties are included in the Department of Homeland Security (DHS) Government Facilities Sector2, one of the 16 critical infrastructures "whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.'" Specifically, disruptions to the flow of border crossing traffic, in the form of closures or increased border crossing wait times, impact the economy and security of all countries involved. This paper describes a process for analyzing and improving the resilience of U.S. Land Ports of Entry. For LPOE, the team believes that energy resilience is the primary objective due to the complete reliance on the e-manifest system and the increasing use of Multi-Energy Portals (MEPs). Emanifests are part of CPB's Automated Commercial Environment (ACE). They document several key pieces of information about cargo vehicles wishing to cross the border into the United States and are submitted before arriving at the port. Vehicles can be flagged for more invasive inspection based on the content of the e-manifest. MEPs are a non-intrusive inspection (NII) technology used to scan the contents of the cargo. Together MEPs and ACE serve an important role in aiding CBP with their mission to protect "the public from dangerous people and materials", and "enabling legitimate trade and travel.'" To analyze resilience of a port, the team would need to understand the port's current energy usage, which systems depend on energy and what backup systems exist, and any emergency operation plans that dictate how systems are operated in the event of a power outage. The team would also need to determine the design basis threats (DBTs) for the LPOE which could include natural disasters, manmade events, and accidents. The magnitudes of the DBTs are calculated and are then translated to expected impacts on the infrastructure and systems at the port. With this information gathered, existing LPOE models developed here at Sandia National Laboratories could be extended to support decisions about resilience. Current models are implemented in FlexSim, a 3rd party discrete event simulator. FlexSim provides 3-D visuals of physical layout that can reveal valuable insights, allows input to be variable (e.g. time it takes to interact with the CBP officer at primary inspection can vary) so that a whole range of possibilities can be captured in the results, and can be used to collect user-defined output metrics. Current LPOE models focus on cargo vehicle traffic, and process changes caused by the installation of new drive-through MEPs. Extending them to address resilience questions would require the addition of key pieces of information learned during the resilience analysis including critical systems, failure rates, and process changes for when failures occur. The primary output metric for current models is border crossing wait time. Additional metrics would also be added to the model to gain a more complete understanding of impacts related to resilience, for example, MEP scan rate. Once complete, the model could be used to analyze the effectiveness of mitigation strategies representing some future state.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Water Security: Trends, Capabilities, and Research Directions to Secure Water Infrastructure

Water and wastewater sector is target rich and resource poor ~153k water utilities, serve 80% of US population ~16k publicly-owned wastewater systems in the US serve 75% of the population Need scalable solutions to fit small and medium to large systems Federal attention to critical infrastructure continues to grow – particularly in the water sector Increase in water sector incidents and threats for large scale disruption – particularly by nation-state actors and their proxies EPA is the SRMA DHS CISA focuses on critical infrastructure protection across sectors They must work together to secure WWW systems Research capabilities to enable secure water systems Current and future threats Resilience – natural disasters, accidents, cyber-physical attacks

99 - GENERAL AND MISCELLANEOUS↗

Clean Energy Cybersecurity Accelerator Cohort 1: Authentication and Authorization

In the 2023 National Cybersecurity Strategy, the Biden-Harris Administration defines the need for a "defensible, resilient digital ecosystem where it is costlier to attack systems than defend them." The strategy cites the Clean Energy Cybersecurity Accelerator (CECA) as an exemplary effort to bolster the security and resilience of clean energy generation. These efforts help "secure the clean energy grid of the future and [generate] security best practices that extend to other critical infrastructure sectors" and promise broad and far-reaching impacts to bridge the capabilities of private industry and the needs of energy production. Cohort 1 of CECA launched in the fall of 2022 with a focus on solutions that provide strong authentication and authorization for industrial control systems to mitigate attacks on the energy grid. Authentication and authorization verify that the identity (authentication) and permissions (authorization) of a user or device are aligned with their assigned roles. Weaknesses in either can have serious repercussions. To assess the strength of Cohort 1's solutions, CECA devised threat scenarios grounded in historical precedents: the CECA team reviewed exploits from real-world case studies of state-sponsored actors to match the assessment's attack paths and targets. Cohort 1 results provided the energy industry, product vendors, and related agencies valuable insights into the efficacy and applicability of solutions in common system configurations under realistic threat scenarios. The results of the assessment highlight points for interrogation and improvement in subsequent technology iterations. CECA's evaluations are part of an ongoing conversation and collaboration to bolster U.S. cyber resilience against adversaries today and in the future.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cross-Layered Cyber-Physical Power System State Estimation towards a Secure Grid Operation

In the Smart Grid paradigm, this critical infrastructure operation is increasingly exposed to cyber-threats due to the increased dependency on communication networks. An adversary can launch an attack on a power grid operation through False Data Injection into system measurements and/or through attacks on the communication network, such as flooding the communication channels with unnecessary data or intercepting messages. A cross-layered strategy that combines power grid data, communication grid monitoring and Machine Learning based processing is a promising solution for detecting cyberthreats. In this paper, an implementation of an integrated solution of a cross-layer framework is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection of anomalies in the operation of power grid. IEEE 118-bus system is built in Simulink to provide a power grid testing environment and communication network data is emulated using SimComponents. The performance of the framework is investigated under various FDI and communication attacks.

cyber security, network security, cyber-physical s↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗

Long-Range Biometric Identification in Real World Scenarios: A Comprehensive Evaluation Framework Based on Missions

The considerable body of data available for evaluating biometric recognition systems in Research and Development (R&D) environments has contributed to the increasingly common problem of target performance mismatch. Biometric algorithms are frequently tested against data that may not reflect the real world applications they target. From a Testing and Evaluation (T&E) standpoint, this domain mismatch causes difficulty assessing when improvements in State-of-the-Art (SOTA) research actually translate to improved applied outcomes. This problem can be addressed with thoughtful preparation of data and experimental methods to reflect specific use-cases and scenarios.To that end, this paper evaluates research solutions for identifying individuals at ranges and altitudes, which could support various application areas such as counterterrorism, protection of critical infrastructure facilities, military force protection, and border security. We address challenges including image quality issues and reliance on face recognition as the sole biometric modality. By fusing face and body features, we propose developing robust biometric systems for effective long-range identification from both the ground and steep pitch angles. Preliminary results show promising progress in whole-body recognition. This paper presents these early findings and discusses potential future directions for advancing long-range biometric identification systems based on mission-driven metrics.

Aykac, Deniz↗

EVs@Scale Deep Dive - SCM/VGI (Day 1: SCM/VGI Analysis)

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This Deep Dive Discussion from year 1 of the project encompasses the progress and future plans for the analysis components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS↗

EVs@Scale Deep Dive - SCM/VGI (Day 2: SCM/VGI Demonstration)

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This Deep Dive Discussion from year 1 of the project encompasses the progress and future plans for the demonstration components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS,POWER TRANSMISSION AND↗

Electric Vehicles at Scale (EVs@Scale) Laboratory Consortium Deep-Dive Technical Meeting: May 18, 2023

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This Deep Dive Discussion from year 2 of the project encompasses the progress and future plans for the analysis components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS,ENERGY PLANNING, POLIC↗

Smart Charge Management and Vehicle Grid Integration Deep Dive

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This deep dive discussion of the project encompasses the progress and future plans for the analysis components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS↗

GLIMPSE of Future Power Grid Models

Power grid is one of the critical national infrastructures with social, economics, and national security impacts. Particularly, power distribution systems represent part of the infrastructure between power distribution substations and customers such as residential, commercial, and industrial. To address various grid modernization challenges, state-of-the-art algorithms and methodologies have been developed to deploy, operate, and expand a secure and resilient power grid. At the same time, there is a need to develop capabilities to assist power grid stakeholders to quickly get insight into the design and structure of the grid. Data visualization is a key approach to comprehend and understand complex systems such as the power grid. We present GLIMPSE Grid Layout Interface for Model Preview and System Exploration), a graph-based semantic-aware application to visualize and update distribution power grid models. The GLIMPSE can be used with standard IEEE models to search and highlight power grid objects such as generators, loads, overhead lines, etc. Additionally, it supports updating attributes and model export to integrate with GridLAB-D simulations.

Cybersecurity, power grid, visualization↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Next-Generation Intensity-Duration-Frequency Curves for Climate-Resilient Infrastructure Design: Advances and Opportunities

National and international security communities (e.g., U.S. Department of Defense) have shown increasing attention for innovating critical infrastructure and installations due to recurring high-profile flooding events in recent years. The standard infrastructure design approach relies on local precipitation-based intensity-duration-frequency (PREC-IDF) curves that do not account for snow process and assume stationary climate, leading to high failure risk and increased maintenance costs. This paper reviews the recently developed next-generation IDF (NG-IDF) curves that explicitly account for the mechanisms of extreme water available for runoff including rainfall, snowmelt, and rain-on-snow under nonstationary climate. The NG-IDF curve is an enhancement to the PREC-IDF curve and provides a consistent design approach across rain- to snow-dominated regions, which can benefit engineers and planners responsible for designing climate-resilient facilities, federal emergency agencies responsible for the flood insurance program, and local jurisdictions responsible for developing design manuals and approving subsequent infrastructure designs. Further, we discuss the recent advances in climate and hydrologic science communities that have not been translated into actional information in the engineering community. To bridge the gap, we advocate that building climate-resilient infrastructure goes beyond the traditional local design scale where engineers rely on recipe-based methods only; the future hydrologic design is a multi-scale problem and requires closer collaboration between climate scientists, hydrologists, and civil engineers.

54 ENVIRONMENTAL SCIENCES↗

Architecting the Grid Edge: Ensuring Reliability and Resilience

Changes in technology, customer expectations, and business and regulatory environments are rapidly evolving causing fundamental changes in the nation’s electrical infrastructure. Nowhere is this more apparent that at the “grid edge”, where there is an increasing number of new devices and systems, as well as complex new interactions between them. This is leading to the traditional relationship between the end-use customers and their utilities being expanded by an increasing number of stakeholders, each with their own operational and financial objectives, governed by regulatory policy. While there are concerns about the rapidly increasing complexity negatively impacting reliable and resilience of the electrical infrastructure, these changes are also bringing new resources and opportunities that hold great potential if they can be properly coordinated. This white paper outlines the considerations for the coordination of multi-stakeholder objectives with electric utility requirements using the concept of grid services. Describing a framework that enables new stakeholders to achieve their local technical and economic objectives, while simultaneously delivering operational benefits to the electrical infrastructure. The concepts of grid architecture are presented as a tool to evaluate how stakeholders might participate in, and benefit from, services, and how utilities can make decision on the reliance on services to ensure reliability and resilience, translating abstract concepts into actionable information for utilities and grid edge stakeholders. The end result of proper coordination, informed by grid architecture, will be a range of new devices and systems, operated by new stakeholders, achieving their local objectives while also increasing the reliability, resilience, security, and affordability of the nation’s critical electrical infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Architecting the Grid Edge: Ensuring Reliability and Resilience

Changes in technology, customer expectations, and business and regulatory environments are rapidly evolving causing fundamental changes in the nation’s electrical infrastructure. Nowhere is this more apparent that at the “grid edge”, where there is an increasing number of new devices and systems, as well as complex new interactions between them. This is leading to the traditional relationship between the end-use customers and their utilities being expanded by an increasing number of stakeholders, each with their own operational and financial objectives, governed by regulatory policy. While there are concerns about the rapidly increasing complexity negatively impacting reliable and resilience of the electrical infrastructure, these changes are also bringing new resources and opportunities that hold great potential if they can be properly coordinated. This white paper outlines the considerations for the coordination of multi-stakeholder objectives with electric utility requirements using the concept of grid services. Describing a framework that enables new stakeholders to achieve their local technical and economic objectives, while simultaneously delivering operational benefits to the electrical infrastructure. The concepts of grid architecture are presented as a tool to evaluate how stakeholders might participate in, and benefit from, services, and how utilities can make decision on the reliance on services to ensure reliability and resilience, translating abstract concepts into actionable information for utilities and grid edge stakeholders. The end result of proper coordination, informed by grid architecture, will be a range of new devices and systems, operated by new stakeholders, achieving their local objectives while also increasing the reliability, resilience, security, and affordability of the nation’s critical electrical infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗