Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “intrusion detection systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Draft Summary Report on Irradiated Fuel Handling and Management for LOTUS

The National Reactor Innovation Center (NRIC) has conceptualized the design of the Laboratory for Operation and Testing in the United States (LOTUS) test bed to provide the United States Department of Energy (DOE) with the infrastructure necessary to make advanced reactor designs available for commercial developers. LOTUS will provide a test bed to developers with the capabilities of supporting a wide range of experiment design possibilities. Upon completion of the developers’ operations and experiments within the test bed, the irradiated fuel, reactor components, and other experiment materials must be removed. Idaho National Laboratory (INL) possesses significant capabilities for radioactive material handling such as casks, carts, and forklifts. However, given the unique environment presented by the NRIC-LOTUS test bed, located inside the Zero Power Physics Reactor (ZPPR) Perimeter Intrusion Detection and Assessment System (PIDAS) area at the Materials and Fuels Complex (MFC) and the complexity of novel removal activities of recently operated reactor experiments through the new proposed access tunnel. The efficacy was not apparent for existing equipment to provide all the needed capability. To bridge the potential gaps in cask designs, storage, and transportation, NRIC requested the development of trade studies for the transfer, handling, and storage requirements of irradiated fuel salts and other radioactive materials. NRIC directed Boston Government Services, LLC (BGS) to perform the trade studies and develop a report analyzing alternatives. In addition to the BGS reports, the Idaho National Lab’s (INL), provided by the first potential user’s Advanced Reactor Development (ARD) team, prepared a feasibility study for the storage of specific irradiated fuel within the existing ZPPR vault.This summary report is intended to present the trade studies, options, and alternatives that were investigated. The maturity level of LOTUS, the reactor, fuel salt containers, gloveboxes, and reactor testing campaign and concept of operations were not at a level sufficient to base critical decisions on. This report is not intended to present a final recommendation. The final recommendations for fuel storage location, transport, handling equipment, and operations will be made in FY 2024 and will be based on known materials, test campaign requirements, funding, and final analysis of the fuel and equipment to be used.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Scanning seismic intrusion detection method and apparatus

An intrusion monitoring system includes an array of seismic sensors, such as geophones, arranged along a perimeter to be monitored for unauthorized intrusion as by surface movement or tunneling. Two wires lead from each sensor to a central monitoring station. The central monitoring station has three modes of operation. In a first mode of operation, the output of all of the seismic sensors is summed into a receiver for amplification and detection. When the amplitude of the summed signals exceeds a certain predetermined threshold value an alarm is sounded. In a second mode of operation, the individual output signals from the sensors are multiplexed into the receiver for sequentially interrogating each of the sensors.

Lee, R. D.↗

Programmable intrusion detection for distributed energy resources in cyber–physical networked microgrids

We present a programmable intrusion detection method is presented to identify the malicious attacks to distributed energy resources (DERs) in the cyber-physical networked microgrids. The proposed method injects small programmable signals into the system and uses the response to identify abnormal conditions. Because of the low or even zero inertia induced by integrations of DER power-electronic-interfaces, microgrids have very limited resilience capability; and thus, being sensitive to attacks. One microgrid's malfunction caused by attacks can easily propagate to its neighboring systems when several microgrids are connected, leading to catastrophic electricity supply failures. Through the presented method, malicious intrusions can be effectively detected, located, and defended for securing microgrids. Theoretical derivations are provided to define the programmable detection rules. The detection rule is easy and flexible to update, making it difficult for attack actors to gain the knowledge of the detection rules, in order to avoid being detected. Numerical results on a cyber-physical networked microgrids system show that the proposed method is effective and efficient in precisely locating intrusion attacks to the microgrids system.

42 ENGINEERING↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗

Time Sequence Machine Learning-Based Data Intrusion Detection for Smart Voltage Source Converter-Enabled Power Grid

Smart inverters of distributed energy resources can enable cloud computing, condition monitoring, result visualization, remote control, and peer-to-peer energy trading in advanced power systems. However, the advent of data injection attacks in the communication architecture can alter measurement characteristics of power grids and have devastating consequences. In this article, we propose a time sequence machine learning-based anomaly detection methodology for detecting cyber intrusion into control signal setpoints and dc voltage signal measurement bias of the voltage source converter (VSC) in wind generators. We first investigated the effects of four types of denial of service, tampering signal, and stealthy-type data intrusion attacks on smart VSCs and overall wind farms. We then proposed a novel time sequence machine learning-based intrusion detection framework that can be implemented to detect different cyberattacks in the VSCs. The performance of the proposed framework has been compared with that of autoencoder and clustering-based intrusion detection framework. The proposed framework was validated by using the IEEE 39 bus power system in the presence of four wind farms in different locations. Using several metrics for intrusion detection performance, we validated the effectiveness of the proposed framework.

42 ENGINEERING↗

Model-Based Detection of Coordinated Attacks (DCA) in Distribution Systems

The fast-paced growth in digitization of smart grid components enhances system observability and remote-control capabilities through efficient communication. However, enhanced connectivity results in heightened system vulnerability towards cybersecurity risks in the cyber-physical power system. Coordinated cyber-attacks (CCA), when undetected, lead to system-wide impact in terms of large disturbances or widespread outages. Detecting CCA in the cyber layer is critical to thwart cyber-attacks in real-time before the attack impacts the physical system. The challenge of locating CCA stems from the complex grid dynamics, making it difficult to distinguish between normal operational variations and cyber-attack impact. CCA often employs multiple attack vectors targeting geographically distributed components, further complicating CCA identification. Existing research in intrusion detection is primarily focused on the transmission network and limited to detecting individual attacks. In this paper, a novel proactive DCA strategy is proposed for early detection of CCA by establishing correlations among distinct attack events through model-based reinforcement learning that utilizes abductive reasoning to conclude the attacker goal. The solution includes understanding the system model, learning the system dynamics, and correlating individual cyber-attacks to extract the attacker’s objective. The developed learning algorithm identifies the most probable attack path to reach the attacker’s objective by predicting the next attack steps. A DNP3-based cyber-physical co-simulation testbed is developed to test the proposed algorithm using the IEEE 13-node test feeder.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Towards Reliable Evaluation of Anomaly-Based Intrusion Detection Performance

This report describes the results of research into the effects of environment-induced noise on the evaluation process for anomaly detectors in the cyber security domain. This research was conducted during a 10-week summer internship program from the 19th of August, 2012 to the 23rd of August, 2012 at the Jet Propulsion Laboratory in Pasadena, California. The research performed lies within the larger context of the Los Angeles Department of Water and Power (LADWP) Smart Grid cyber security project, a Department of Energy (DoE) funded effort involving the Jet Propulsion Laboratory, California Institute of Technology and the University of Southern California/ Information Sciences Institute. The results of the present effort constitute an important contribution towards building more rigorous evaluation paradigms for anomaly-based intrusion detectors in complex cyber physical systems such as the Smart Grid. Anomaly detection is a key strategy for cyber intrusion detection and operates by identifying deviations from profiles of nominal behavior and are thus conceptually appealing for detecting "novel" attacks. Evaluating the performance of such a detector requires assessing: (a) how well it captures the model of nominal behavior, and (b) how well it detects attacks (deviations from normality). Current evaluation methods produce results that give insufficient insight into the operation of a detector, inevitably resulting in a significantly poor characterization of a detectors performance. In this work, we first describe a preliminary taxonomy of key evaluation constructs that are necessary for establishing rigor in the evaluation regime of an anomaly detector. We then focus on clarifying the impact of the operational environment on the manifestation of attacks in monitored data. We show how dynamic and evolving environments can introduce high variability into the data stream perturbing detector performance. Prior research has focused on understanding the impact of this variability in training data for anomaly detectors, but has ignored variability in the attack signal that will necessarily affect the evaluation results for such detectors. We posit that current evaluation strategies implicitly assume that attacks always manifest in a stable manner; we show that this assumption is wrong. We describe a simple experiment to demonstrate the effects of environmental noise on the manifestation of attacks in data and introduce the notion of attack manifestation stability. Finally, we argue that conclusions about detector performance will be unreliable and incomplete if the stability of attack manifestation is not accounted for in the evaluation strategy.

cyber defense↗

Edge ML for CAN bus intrusion detection in AVs

Autonomous Vehicles (AVs) are revolutionizing transportation, but their reliance on interconnected cyber-physical systems exposes them to unprecedented cybersecurity risks. This study addresses the critical challenge of detecting real-time cyber intrusions in self-driving vehicles by leveraging a dataset from the Udacity self-driving car project. We simulate four high-impact attack vectors, Denial of Service (DoS), spoofing, replay, and fuzzy attacks, by injecting noise into spatial features (e.g., bounding box coordinates) to replicate adversarial scenarios. We develop and evaluate two lightweight neural network architectures (NN-1 and NN-2) alongside a logistic regression baseline (LG-1) for intrusion detection. The models achieve exceptional performance, with NN-2 attaining an AUC score of 93.15% and 93.15% accuracy, demonstrating their suitability for edge deployment in AV environments. Through explainable AI techniques, we uncover unique forensic fingerprints of each attack type, such as spatial corruption in fuzzy attacks and temporal anomalies in replay attacks, offering actionable insights for feature engineering and proactive defense. Visual analytics, including confusion matrices, ROC curves, and feature importance plots, validate the models' robustness and interpretability. This research sets a new benchmark for AV cybersecurity, delivering a scalable, field-ready toolkit for Original Equipment Manufacturers (OEMs) and policymakers. By aligning intrusion fingerprints with SAE J3061 automotive security standards, we provide a pathway for integrating machine learning into safety-critical AV systems. Our findings underscore the urgent need for security-by-design AI, ensuring that AVs not only drive autonomously but also defend autonomously. This work bridges the gap between theoretical cybersecurity and life-preserving engineering, offering a leap toward safer, more secure autonomous transportation.

97 MATHEMATICS AND COMPUTING↗

Towards Secure Autonomous Vehicles: An Integrated Edge and Multi-Modal Machine Learning Framework for Intrusion Detection

Autonomous vehicles (AVs) are vulnerable to cyberattacks targeting both internal communication networks and external perception sensors. While edge-based intrusion de- tection for Controller Area Network (CAN) buses offers real-time protection, it cannot detect cross-modal threats. Conversely, multi-modal fusion approaches improve coverage but often lack efficiency for in-vehicle deployment. This thesis integrates two complemen- tary solutions: (1) a lightweight, edge-deployable machine learning framework for CAN bus intrusion detection, and (2) a late-fusion system combining CAN FD and LiDAR data. Together, they form a hierarchical defense capable of handling single-modality and coordi- nated attacks. Simulations show that CAN-only models reach 93% accuracy on simulated DoS, spoofing, replay, and fuzzy attacks, while the fusion system achieves 0.87 AUC and 0.82 F1-score at 2 ms latency. This unified framework establishes a scalable, explainable, and field-ready strategy for AV cybersecurity.

97 MATHEMATICS AND COMPUTING↗

A Robust Method to Secure Multi-Inverter Grid Tied PV and Battery Energy Storage Systems Against Cyber Intrusions

This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.

Ibrahim, Hasan↗

Commercialization of the Transportation-Security, Tracking, and Reporting System (T-STAR)

The Transportation-Security, Tracking, and Reporting System (T-STAR) was developed by the National Nuclear Security Administration, NA-21, Office of Radiological Security (ORS) to provide a transportation security system for detection and tracking during transport of Category 1 and Category 2 radiological material. Few off-the-shelf systems for conveyance tracking offer detection of a cargo compartment breach or a removal of the cargo. Systems that do offer this capability often require permanent installation through modifying of the conveyance itself. This is not sustainable in many countries where ORS is building use, storage, and transport security capacity. The development of T-STAR has moved from fielding robust prototypes deployed in countries ranging from North America, Latin America and Central Asia to a commercially produced product that can now be deployed to provide enhanced security during transit. Each prototype deployment resulted in important lessons learned, which informed the requirements for the final commercial product. T-STAR uses both cellular and Iridium satellite modems to provide redundant communications to provide the configuration, status, and alerts to a server monitoring the shipment, which is accessible using a multilanguage browser-based user interface. A wireless security system employing using Z-wave sensors for intrusion detection located in the conveyance provide low cost but effective solution for a wide range of conveyance types. Additional capabilities include the ability to monitor a vehicles’ CANBUS (Controller Area Network) system, an ethernet port for high throughput sensor information such as video cameras, and the ability to power and use advanced external sensor payloads. These features make the T-STAR a capable and expandable security gateway that can be deployed on a variety of conveyances from box trucks to open trailers. The ability to provide tracking, monitoring, and detection provide a key component in overall best practices designed to protect shipments of radioactive material.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

Clonal Selection Based Artificial Immune System for Generalized Pattern Recognition

The last two decades has seen a rapid increase in the application of AIS (Artificial Immune Systems) modeled after the human immune system to a wide range of areas including network intrusion detection, job shop scheduling, classification, pattern recognition, and robot control. JPL (Jet Propulsion Laboratory) has developed an integrated pattern recognition/classification system called AISLE (Artificial Immune System for Learning and Exploration) based on biologically inspired models of B-cell dynamics in the immune system. When used for unsupervised or supervised classification, the method scales linearly with the number of dimensions, has performance that is relatively independent of the total size of the dataset, and has been shown to perform as well as traditional clustering methods. When used for pattern recognition, the method efficiently isolates the appropriate matches in the data set. The paper presents the underlying structure of AISLE and the results from a number of experimental studies.

pattern recognition↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Security in Full-Force

When fully developed for NASA, Vanguard Enforcer(TM) software-which emulates the activities of highly technical security system programmers, auditors, and administrators-was among the first intrusion detection programs to restrict human errors from affecting security, and to ensure the integrity of a computer's operating systems, as well as the protection of mission critical resources. Vanguard Enforcer was delivered in 1991 to Johnson Space Center and has been protecting systems and critical data there ever since. In August of 1999, NASA granted Vanguard exclusive rights to commercialize the Enforcer system for the private sector. In return, Vanguard continues to supply NASA with ongoing research, development, and support of Enforcer. The Vanguard Enforcer 4.2 is one of several surveillance technologies that make up the Vanguard Security Solutions line of products. Using a mainframe environment, Enforcer 4.2 achieves previously unattainable levels of automated security management.

Source record↗

Integrating 5G Technology for Improved Process Monitoring and Network Slicing in ICS

Industrial Control Systems (ICS) are crucial for monitoring physical processes that support essential cyber-enabled services like power generation. The use of proprietary communication and lack of effective intrusion detection mechanisms pose constraints for efficient operation. Therefore, there is a need to modernize these systems with decentralized technologies like Edge Computing and 5G. However, integrating 5G and Edge Computing into large-scale ICS networks presents implementation and performance challenges. To address these challenges, this paper proposes an integrated ICS architecture that combines 5G and Edge Computing technologies with traditional ICS protocols. The objective is to minimize implementation and operational difficulties while improving the monitoring of physical processes and enabling robust intrusion detection. The proposed architecture outlines the necessary components, services, and communication protocols required for the integration of 5G and Edge Computing.

Aguayo, Jared M.↗

Deliberate Motion Analytics Fused Radar and Video Test Results Deployed Beyond the Perimeter Fence in a High Noise Environment

Security systems that protect the nation’s critical facilities must be capable of detecting physical intrusions in all weather conditions. Intrusion detection sensors in a perimeter with a high nuisance alarm rate (NAR) significantly undermine detection performance and degrade security system effectiveness. This research demonstrated a fused sensor system that can differentiate foliage and weather-induced nuisance alarms from those caused by intruders, providing reliable detection within a two-fence perimeter or beyond the fence. A key element of this work is the creation and application of a “deliberate motion algorithm” that fuses alarm data from radar and video analytics to create video motion detection fused radar system. The two-layer architecture of the algorithm uses machine learning, multi-hypothesis tracking, and Dynamic Bayes Nets to differentiate intruder alarms from weather induced alarms.

47 OTHER INSTRUMENTATION↗

Deliberate Motion Analytics Applied to CUAS Sensor Fusion

The Advanced Reactor Safeguards and Security (ARSS) program in the Department of Energy’s Office of Nuclear Energy (DOE-NE) seeks to identify new technology solutions for safeguards and security challenges associated with domestic deployment of advanced nuclear reactors. Research in the ARSS program is investigating alternative physical protection system (PPS) approaches that leverage new detection technologies. This report shows test results from a new form of artificial intelligence (AI) that is called deliberate motion analytics (DMA) when used to spatially and temporally fuse active radar and passive radio frequency (RF) detection that significantly improves detection of uncrewed aircraft systems (UASs). DMA is designed to filter out false positive alarms yet provide highly reliable intrusion detection at nuclear power plants (NPPs) and advanced small modular reactor (ASMR) perimeters. This form of AI is considered to be an enabling technology for security of the future and supports the ARSS investigation of alternative PPSs.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗