Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

MiniMOD

SAND2025-03854O MiniMod is a user-friendly software tool designed to assess the performance of high-performance computing (HPC) systems. Researchers can use the program to test communication methods and computational tasks to understand how different setups can affect application efficiency. This software is particularly useful for optimizing network performance in scientific research, simulations, and data analysis. MiniMod‘s flexible design allows users to make informed decisions about their computing environments, which can enhance productivity and results in real-world applications. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Dosanjh, Matthew [Sandia National Lab. (SNL-CA), L↗

Neural Network Approaches for Mobile Spectroscopic Gamma-Ray Source Detection

Artificial neural networks (ANNs) for performing spectroscopic gamma-ray source identification have been previously introduced, primarily for applications in controlled laboratory settings. To understand the utility of these methods in scenarios and environments more relevant to nuclear safety and security, this work examines the use of ANNs for mobile detection, which involves highly variable gamma-ray background, low signal-to-noise ratio measurements, and low false alarm rates. Simulated data from a 2” × 4” × 16” NaI(Tl) detector are used in this work for demonstrating these concepts, and the minimum detectable activity (MDA) is used as a performance metric in assessing model performance.In addition to examining simultaneous detection and identification, binary spectral anomaly detection using autoencoders is introduced in this work, and benchmarked using detection methods based on Non-negative Matrix Factorization (NMF) and Principal Component Analysis (PCA). On average, the autoencoder provides a 12% and 23% improvement over NMF- and PCA-based detection methods, respectively. Additionally, source identification using ANNs is extended to leverage temporal dynamics by means of recurrent neural networks, and these time-dependent models outperform their time-independent counterparts by 17% for the analysis examined here. The paper concludes with a discussion on tradeoffs between the ANN-based approaches and the benchmark methods examined here.

Bilton, Kyle J. (ORCID:0000000184553689)↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Tight Practical Bounds for Subgraph Densities in Ego-centric Networks

SAND2025-11782O Tight Practical Bounds for Subgraph Densities in Ego-centric Networks is a software tool for calculating the “subgraph spread ratio” for social network analysis. This value is useful in network analysis for determining the amount of exogenous and endogenous pressure on a graph. It can distinguish between networks coming from different sources, e.g. distinguishing a graph of Facebook data versus a graph of Wikipedia data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Mattes, Connor↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

scANN

SAND2025-00656O scANN, also known as sampling by coinflips artificial neural networks, is a software tool that estimates uncertainty in artificial intelligence by performing Monte Carlo analysis on the weight matrices of feedforward neural networks. This computationally intensive process aims to explore the potential value added by future probabilistic hardware. The program’s output helps researchers gain insights into how probabilistic neural networks work. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

SciDAC↗

The Lithuania 100% Renewable Energy Study - Interim Results: Electricity System Scenarios for 2030 [Slides]

Lithuania's Energy Vision aims to achieve self-sufficiency in electricity generation by 2035 and transition to 100% renewable energy as soon as possible while maintaining affordability, reliability, and energy security. The Lithuania Energy Agency (LEA) is partnering with the National Renewable Energy Laboratory (NREL) to conduct the Lithuania 100% Renewable Energy Study (Lithuania 100) to provide evidence-based analysis for development of Lithuania's National Energy Independence Strategy. The Lithuania 100 Study leverages unique tools and capabilities of NREL to provide rigorous technical analysis of clean energy policies to achieve 100% renewable energy, and assess impacts on electricity grid operations, hydrogen system development, electricity distribution networks, air quality, and human health outcomes. The study is supported by a stakeholder committee chaired by the Ministry of Energy of Lithuania and implemented by four technical working groups. This report provides highlights of key interim results from modeling of Lithuania's near-term electricity grid through the year 2030. Results show that Lithuania has sufficient renewable energy potential, flexible generation capacity, and interconnection with neighboring European Union countries to reliably meet projected 2030 electricity demand with 100% renewable energy. A range of scenarios were modeled, each of which achieves at least 100% renewable energy in electricity, on average over the year, by 2030. Potential demands for hydrogen across industrial and transportation sectors were also evaluated, as well as the cost of hydrogen produced in Lithuania by 2030.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Seamless Wireless Communication Platform for Internet of Things Applications

The rapid growth of the Internet of Things (IoT) devices resulted in the proliferation of wireless technologies to cater to their increasing data rate requirements and support multiple applications. However, such ever-increasing wireless technologies present numerous challenges such as incompatible wireless standards, increased energy consumption, and insecure communication. The traditional gateways proposed in the literature suffers from limitations such as computational complexity, resource requirements, increased cost, and device size. We vision an era of seamless wireless communication to alleviate the aforementioned challenges in IoT applications. through three inter-dependent functionalities namely detection and identification of wireless technologies, energy-efficient transmit power control, and secure end-to-end communication. To prove the concept, a new gateway is proposed to achieve these three functionalities with only physical layer measurements so that the different communication protocols in the higher layers can be avoided. Novel schemes are conceptualized for resource-limited seamless IoT applications. Moreover, the conceptual seamless IoT platform is validated through software-based computer simulation and software-defined radio-based testbed implementation. Finally, the preliminary analysis demonstrates that the proposed platform has great potential in advancing seamless IoT applications.

97 MATHEMATICS AND COMPUTING↗

Distributed Software-Defined Network Architecture for Smart Grid Resilience to Denial-of-Service Attacks

An important challenge for smart grid security is designing a secure and robust smart grid communications architecture to protect against cyber-threats, such as Denial-of-Service (DoS) attacks, that can adversely impact the operation of the power grid. Researchers have proposed using Software Defined Network frameworks to enhance cybersecurity of the smart grid, but there is a lack of benchmarking and comparative analyses among the many techniques. In this work, a distributed three-controller software-defined networking (D3-SDN) architecture, benchmarking, and comparative analysis with other techniques is presented. The selected distributed flat SDN architecture divides the network horizontally into multiple areas or clusters, where each cluster is handled by a single Open Network Operating System (ONOS) controller. A case study using the IEEE 118-bus system is provided to compare the performance of the presented ONOS-managed D3-SDN, against the POX controller. In addition, the proposed architecture outperforms a single SDN controller framework by a tenfold increase in throughput; a reduction in latency of > 20%; and an increase in throughput of approximately 11% during the DoS attack scenarios.

Agnew Jr., Dennis↗

WEC as a multiport

SAND2025-00555O WEC as a multiport is a software tool that simplifies the modeling and design of ocean wave energy converters (WECs) using a multi-port network framework in the frequency domain. Users can simulate the dynamic interactions between WECs and ocean waves, optimizing energy extraction and system performance. This tool supports the analysis of complex wave energy systems, aiding in the development of efficient and effective WEC designs. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Coe, Ryan↗

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy↗

Conin

SAND2025-07645O Conin is a Python library that supports constrained analysis of probabilistic graphical models (PGMs). It enables constrained inference and learning for hidden Markov models, Bayesian networks, dynamic Bayesian networks, and Markov networks. Conin interfaces with the pgmpy library to specify general probabilistic graphical models with a variety of optimization solvers to support learning and inference. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Hart, William [Sandia National Lab. (SNL-CA), Live↗

GSAS Tools

SAND2023-06684O GSAS Tools is a web application that manages user access to modeling and simulation tools and promotional material. This software, which is a spiking neural network (SNN) simulator, represents an SNN as a graph of stochastic differential equations and simulates the time-evolution of these equations. It has the capability of reading inputs from file and writing outputs to file, and generally supports experimentation, analysis, and algorithm development using SNNs. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Noel, Todd↗

Thermal Reservoir Networks for Modularly Expandable Thermal Microgrids

The Department of Defense (DoD) faces the substantial challenge of cost-effectively retrofitting one to two installations per month, each comprising approximately 1,000 buildings, to improve resilience, reduce energy consumption, and enhance energy supply security. Achieving these objectives requires optimal system selection and effective risk mitigation during system integration. To address this need, we introduce Platform-Based Design (PBD), a structured, hierarchical methodology adapted from other industrial sectors to the domain of energy system retrofits. We demonstrate the effectiveness of PBD through a techno-economic feasibility study comparing geothermal-coupled thermal energy networks (TENs) with conventional energy systems for heating, cooling, and powering 17 buildings at Joint Base Andrews (JBA) in Maryland. Our analysis illustrates that the PBD approach enables rigorous, data-driven, sequential decision making, resulting in a family of Pareto-optimal systems, among which the TEN emerged as the most promising solution. The selected TEN design integrates geothermal borefields, heat recovery heat pumps, photovoltaic (PV) arrays, and battery storage. Compared to the baseline system – gas heating combined with air-source chillers – the proposed TEN reduces annual imported energy by 74% and peak electricity demand by 45%, achieves a levelized cost of energy of $\$0.210$/kWh, and substantially enhances resilience. Life-cycle costs increase by approximately 6%, and initial investment costs are about 2.5 times higher than the baseline. However, if central plant infrastructure, district loops, and utility-scale PV and battery systems are privately funded and operated, the initial investment would fall below the baseline system cost. Critical to achieving these significant performance improvements were detailed nonlinear dynamic simulations coupling geothermal heat transfer, energy system operation, and realistic feedback control logic. These simulations identified essential design modifications and control strategy refinements that substantially reduced energy use, peak demand, and compressor shortcycling, thereby improving durability and reliability—issues that would have been significantly more expensive to resolve during operation. Additionally, the verification step highlighted sensitivities to key design parameters that could reduce initial investment by approximately $\$2$ million and reduce annual life-cycle costs more than $\$300,000$. We recommend adopting the PBD methodology for future feasibility studies and TEN pilot projects to gain valuable operational experience. Furthermore, we recommend that DoD invest in transferring and scaling the PBD methodology to other installations. This entails developing standardized computational frameworks and component libraries as well as training industry in conducting PBD. Such investments would enable rapid, robust, reliable, and cost-effective retrofits, supporting DoD’s ambitious energy system modernization goals.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Advanced Data Science Model for Detecting Intelligent Malware

This study focused on developing a robust artificial intelligence (AI) model capable of detecting and characterizing advanced malware in Internet of Things (IoT) devices using network data. By analyzing network traffic with various machine learning (ML) models, our AI model can identify and characterize malicious activities to significantly improve malware detection accuracy and reliability as compared to traditional methods. The developed AI/ML model was trained using network data from IoT devices, leveraging classifiers such as Random Forest, Gradient Boosting, AdaBoost, and others to optimize detection performance. This project demonstrates a scalable framework for real-time malware detection and characterization in IoT networks, capable of identifying infected devices and facilitating the necessary steps to remove or isolate them, thereby preventing further infections. Although digital twin (DT) integration is not yet implemented in the current model, it represents a promising future enhancement. By creating a virtual replica of physical IoT devices, DT technology would allow for real-time monitoring and analysis without directly accessing operational technology, thus reducing the risk of compromising or reducing the performance of actual devices. This integration would further enhance the security of IoT ecosystems, combining AI technology to better flag and detect indications of malware-infected devices within a nuclear system environment.

42 ENGINEERING↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

The Urban Deployment Model: A Toolset for the Simulation and Performance Characterization of Radiation Detector Deployments in Urban Environments

Static and mobile radiation detectors can be deployed in urban environments for a range of nuclear security applications, including radiological source search-and-tracking scenarios. Modeling detector performance for such applications is challenging, as it does not depend solely on the detector capabilities themselves. Many factors must be taken into consideration, including specific source and background signatures, the topology and constraints of the deployment environment, the presence of nuisance sources, and whether detectors are mobile or static. When considering the simultaneous deployment of multiple, heterogeneous detectors, assessment of the system-wide performance requires the simulation of the individual detectors, and a system-level analysis of the detection performance. In radiological source search-and-tracking scenarios, performance is mostly dominated by the probability of encounter, which depends on the specifics of a given deployment, e.g., static vs. mobile detectors or a combination of both modalities, the number of detectors deployed, the dynamic vs. static setting of false alarm rates, and individual vs. networked operation. The Urban Deployment Model (UDM) toolset was specifically developed to cover the gap in the available generic frameworks for the simulation of radiation detector deployments at city scales. UDM provides a unified and modular framework to support the simulation and performance characterization of heterogeneous detector deployments in urban environments. This paper presents the key components along the UDM workflow.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗