Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

LDRD23-0184: Resilience and Hazard Risk Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI)

Recent examples provide a significant concern for the resilience of the U.S. electric grid and represent a need for enhanced decision-making to address an increasingly wide range of complex system interactions and potential consequences. In response, this LDRD project produced a proof-of-concept evaluation called the Resilience and Hazard Assessment to Prioritize Security Operations for Decisions and Impacts (RHAPSODI) methodology as an agile and flexible analytic framework capable of addressing multiple, diverse threats to desired electric grid performance. After empirically grounding needs for the future of U.S. electric grid resilience, this project employed the systems-theoretic process analysis (STPA) to develop a systems engineering risk model. The results of a completed feasibility study of a notional high voltage transmission system demonstrate an improved ability to incorporate both spatial (e.g., geographically distributed) and temporal (e.g., dynamic and time-dependent) elements of security risk to the gird. The success of this LDRD project provides the foundation for further evolution of the systems engineering risk model for the grid; derivation of quantitative approaches to evaluate risk and resilience performance; facilitation of agile experimenting and grid sensitivity to a range of vulnerabilities; and development of tools to assist decision-makers in enhancing U.S. electrical grid resilience.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP (Presentation)

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. Idaho National Laboratory has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal hydraulics modeling to enhance security planning while reducing costs. A reduced order model for thermal hydraulic simulations performed by the Modular Accident Analysis Program (MAAP) was developed to evaluate reactor core behavior during attack scenarios. MAAP simulations are computationally intensive and must be run in a secure environment, complicating analysis and validation. By pre-computed scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. To address this, Idaho National Laboratory [JL2.1]has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal-hydraulics modeling [JL3.1]to enhance security planning while reducing costs. We developed a tool that produces reduced order models using thermal hydraulic simulations from the Modular Accident Analysis Program (MAAP) [1]. These models can quickly evaluate reactor core behavior during attack simulations, and in so doing, address two barriers of traditional methods: (1) MAAP simulations are computationally intensive, and (2) attack scenarios must be run in a secure environment, which complicates analysis and validation. By precomputing scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Security Self-Assessment Toolkit for Nuclear Materials Facilities: Focus on Insider Threat Mitigation

Theft or sabotage of weapons-usable nuclear materials is a global concern. To minimize this threat, establishing and maintaining an effective nuclear security regime is required to protect against criminal or other negligent acts. Use of a formalized insider threat mitigation program is one such security measure. Individuals who have or held authorized access to an organization's critical assets, such as nuclear materials, are considered "insiders." Insider threats, or insider adversaries, are motivated individuals who possess access, authority, and knowledge to conduct a malicious act or facilitate that of an external party. To thwart insider threats (both intentional and unintentional), organizations can formalize an enterprise-wide approach to identify and mitigate the unique risks presented by insiders. This report provides an approach to evaluate an insider threat mitigation program at facilities with nuclear materials. Formal program evaluations serve many purposes and can be designed using several different methods and techniques. This report presents a self-assessment approach to program evaluation whereby an organization can assess its strengths, identify key gaps, and set priorities for ongoing improvement efforts to mitigate insider threats. Results of the self-assessment can provide critical information to contribute to the continuous improvement of an organization’s insider threat mitigation program within eight specific domain areas.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Dayflow-PR: High-Resolution Streamflow Reanalysis for Puerto Rico, Version 1.0

This dataset presents a high-resolution historical streamflow reanalysis for NHDPlusV2 stream reaches across Puerto Rico (PR) spanning 1950 - 2019. The reanalysis is generated using the calibrated VIC-RAPID hydrologic modeling framework at the Hydrologic Unit Code Sub-basin (HUC08) scale, forced with sub-daily and daily meteorological forcings from Daymet. Runoff is simulated on 1- and 6-km grids, and the resulting total runoff is routed through the NHDPlusV2 river network using the RAPID routing model to produce Naturalized Streamflow Reanalysis. Where complete observational records are available over 1980 - 2019, streamflows are assimilated (substituted) and subsequently routed downstream through the river network to produce Assimilated Streamflow Reanalysis. The dataset includes streamflow outputs from eight distinct hydrologic modeling configurations along with key performanc evaluation metrics at daily and monthly scales, supporting a wide range of water resource applications. This dataset is derived to support the Non-Powered Dam Assessment, as well as 9505 Secure Water Assessment projects for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). For further details, refer to Ghimire et al. (2023), Kao et al. (2024), and Ghimire et al. (2025).

13 HYDRO ENERGY↗

Method for Assessment of Security-Relevant Settings in Anomaly-Based Intrusion Detection for Industrial Control Systems

Ensuring the integrity of Ethernet-based networks is a challenging and constantly evolving domain. This problem is exacerbated for those operational technology (OT) networks supporting industrial control systems (ICS) since much of that equipment was originally designed to be on a network that was isolated and generally considered free of malefactors. Increasing pressure to bridge these systems with traditional information technology (IT) networks has introduced a bevy of new threats. In response, both academia and industry have responded with security solutions tailored to ICS environments. Deploying these protection systems often involves several configuration choices. While some of these choices are clear (e.g., block/enable protocol X) others are far more subjective (e.g. alert threshold == 3.43). Further complicating the situation, while often similar to IT networks, OT networks have unique challenges and characteristics that make the task of protecting them simultaneously more difficult and straight forward.Extant solutions for quantifying the relative security of intrusion detection systems fail to effectively support the operators of said systems with understanding the impact of various configuration changes. Further, they assume that the attacks are static and not subject to manipulation or alteration in the face of defenses. In this paper, we present a threat-based method for quantifying the relative impact of various security settings for intrusion detection systems (IDSs) within ICS environments. This method provides operational staff with a clear understanding of the relative impact of their settings and assumes that the attacks levied against them are dynamic. The model is described in detail, we apply the model to a synthetic data set, and discuss the inferences that can be made and what types of decisions they could be used to support.

Gillen, Rob↗

Design and Implementation of Full-Scale Industrial Control System Test Bed for Assessing Cyber-Security Defenses

In response to the increasing awareness of the Ethernet-based threat surface of industrial control systems (ICS), both the research and commercial communities are responding with ICS-specific security solutions. Unfortunately, many of the properties of ICS environments that contribute to the extent of this threat surface (e.g. age of devices, inability or unwillingness to patch, criticality of the system) similarly prevent the proper testing and evaluation of these security solutions. Production environments are often too fragile to introduce unvetted technology and most organizations lack test environments that are sufficiently consistent with production to yield actionable results. Cost and space requirements prevent the creation of mirrored physical environments leading many to look towards simulation or virtualization. Examples in literature provide various approaches to building ICS test beds, though most of these suffer from a lack of realism due to contrived scenarios, synthetic data and other compromises. In this paper, we provide a design methodology for building highly realistic ICS test beds for validating cybersecurity defenses. We then apply that methodology to the design and building of a specific test bed and describe the results and experimental use cases.

Gillen, Rob↗

Technical Guide for Implementing Cybersecurity Continuous Monitoring in the Nuclear Industry

A technical guide to assist the nuclear industry in implementing cybersecurity continuous monitoring program. The guide walks through the steps to develop a cybersecurity continuous monitoring program and provides details relative to the nuclear industry. It also includes a series of examples of optional metrics to be used, and technologies that can be useful when implementing a continuous monitoring program.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

CONUS-wide Projected Flood Frequency and Uncertainty Estimates, Version 1.0

This dataset presents a large-ensemble of CONUS-wide projected flood frequency and uncertainty estimates across ~2.7 million NHDPlusV2 river reaches over the CONUS. The framework producing this dataset leverages a multi-model, uncertainty-aware modeling framework that allows evaluating shifts in flood frequences at the stream reach level across the CONUS. CONUS-wide ensemble streamflow projections generated from hydrologic simulations driven by downscaled and bias-corrected Coupled Model Intercomparison Project Phase 6 (CMIP6) outputs are used to derive these flood frequency and uncertainty estimates over the period 1980 - 2099. A spatially consistent regional L-moment algorithm is applied across clusters defined by the US Hydrologic Unit Code Subregions (HUC4s and HUC8s) and NHDPlusV2 stream orders to estimate flood frequencies. The dataset also includes at-site based flood estimates that allow for the comparison between local and regional approach-based estimates, assess projected changes, and characterize their uncertainties. For more reliable estimation of rare flood frequencies such as 500 and 1000-year return periods, super-ensemble based estimates are also included in the dataset. This dataset is derived to support the "Impact-Informed Dam Safety Risk Assessment for Securing Hydropower Assests" project for the US Department of Energy (DOE) Hydropower and Hydrokinetic Office (H2O). For further details, refer to Kao et al. (2022), Ghimire et al. (2023), Ghimire et al. (2025), and Hosking and Wallis (1997).

Ghimire, Ganesh [ORNL] (ORCID:0000000242843941)↗

Security Risks: Management and Mitigation in the Software Life Cycle

A formal approach to managing and mitigating security risks in the software life cycle is requisite to developing software that has a higher degree of assurance that it is free of security defects which pose risk to the computing environment and the organization. Due to its criticality, security should be integrated as a formal approach in the software life cycle. Both a software security checklist and assessment tools should be incorporated into this life cycle process and integrated with a security risk assessment and mitigation tool. The current research at JPL addresses these areas through the development of a Sotfware Security Assessment Instrument (SSAI) and integrating it with a Defect Detection and Prevention (DDP) risk management tool.

securiy↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

A Review of Cyber-Physical Security for Photovoltaic Systems

In this paper, the challenges and a future vision of the cyber-physical security of photovoltaic (PV) systems are discussed from a firmware, network, PV converter controls, and grid security perspective. The vulnerabilities of PV systems are investigated under a variety of cyber-attacks, ranging from data integrity attacks to software-based attacks. A success rate metric is designed to evaluate the impact and facilitate decision making. Model-based and data-driven methods for threat detection and mitigation are summarized. In addition, the blockchain technology that addresses cyber-attacks in software and cyber networks is described. Simulation and experimental results that show the impact of cyber-attacks at the converter (device) and grid (system) levels are presented. Finally, potential research opportunities are discussed for next-generation, cyber-secure power electronics systems. These opportunities include multi-scale controllability, self-/event-triggering control, artificial intelligence/machine learning, hot patching, and online security. As of today, this study will be one of the few comprehensive studies in this emerging and fast-growing area.

14 SOLAR ENERGY↗

Towards Automated Assessment of Vulnerability Exposures in Security Operations

Current approaches for risk analysis of software vulnerabilities using manual assessment and numeric scoring do not complete fast enough to keep pace with the maintenance work rate to patch and mitigate the vulnerabilities. This paper proposes a new approach to modeling software vulnerability risk in the context of the network environment and firewall configuration. In the approach, vulnerability features are automatically matched up with networking, target asset, and adversary features to determine whether adversaries can exploit a vulnerability. The ability of adversaries to reach a vulnerability is modeled by automatically identifying the network services associated with vulnerabilities through a pipeline of machine learning and natural language processing and automatically analyzing network reachability. Our results show that the pipeline can identify network services accurately. We also find that only a small number of vulnerabilities pose real risks to a system. However, if left unmitigated, adversarial reach to vulnerabilities may extend to nullify the effect of firewall countermeasures.

Huff, Philip↗

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗