Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

Facility Cybersecurity Framework Best Practices

Federal facilities are increasingly adopting automation and connecting to the Internet creating an energy-internet-of-things environment that converges operational technology (OT) and information technology (IT). Today's buildings increasingly weave together networked sensors and cyber and physical systems that enable data to be collected, aggregated, exchanged, stored and monetized in new ways. Building technological advances have created new energy technology, services, markets and value creation opportunities (e.g. transactive energy, two-way grid communications, machine learning, and increased use of renewable and distributed energy resources). But as larger data sets are being exchanged at faster speeds between an increasing number of OT systems, it becomes more difficult to protect the security of the data lifecycle and the physical equipment it interacts with. These challenges are especially difficult to overcome because the economic and environmental gain (interoperability, big data, social networks and ubiquitous information sharing) are driving these prominent trends in the digital age. Often cybersecurity is an afterthought. The U.S. Department of Energy’s (DOE) Federal Energy Management Program (FEMP) funded the Pacific Northwest National Laboratory (PNNL) to develop various cybersecurity tools, trainings, and reports to aid federal facility managers – and other building owners and operators – in better applying frameworks and lessons learned from the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), risk management framework (RMF), DOE’s cybersecurity capability maturity model (C2M2), and a wide variety of industry best practices and guidance documents (i.e., NIST 800 series, Department of Defense United Facilities Criteria). This set of tools, collectively known as the FEMP Facility-Related Control System Cyber Toolkit (FRCS Cyber Toolkit)2, is focused on cybersecurity concerns from facility-related control systems and other operational technology (OT), such as industrial control systems (ICS). The FRCS Cyber Toolkit can be applied across six of the sixteen critical infrastructure sectors designated by the Department of Homeland Security, including government facilities, healthcare and public health, commercial facilities (e.g., public assembly, offices, lodging), financial services (e.g., banking and insurance), emergency services (e.g., fire and police stations), and information technology. With increasingly converged IT and OT systems, it is crucial to address OT cybersecurity considerations and assess how the seam of these two systems could impact the overall cybersecurity posture of a facility. The objective of this report is to provide an overview of the best possible method to use FRCS Cyber Toolkit (section 2.0) and distilled cybersecurity best practices for the federal facilities to address growing non-linear cyber threats (section 3.0). Recommendations in this document are aggregated from several NIST and other documents (see Appendix A for additional details).

97 MATHEMATICS AND COMPUTING↗

Autonomous Tools for Attack Surface Reduction (Final Report)

The electric power grid is a complex critical infrastructure that forms the lifeline of modern society, and its secure and reliable operation is of paramount importance to national security and economic wellbeing. However, recent findings documented in authoritative sources indicate the threat of cyber-based attacks growing in numbers and sophistication. However, securing the grid against stealthy cyberattacks is a challenging task due to legacy nature of the infrastructure coupled with dynamic nature of threat landscape and ever-growing sophistication of the adversaries. Additionally, the grid’s attack surface continues to grow with the increased dependence on digital communications and control that now extends to each consumer through smart meters and distributed energy resources. Unfortunately, this expansive surface increases the grid’s vulnerability and further exposes critical control systems in both substations and control centers. To respond to this emerging need, we had successfully assembled an interdisciplinary team with academic- industry partnership to successfully conduct research, development, evaluation, demonstration, and commercialization of attack surface reduction tools, whose goal was to significantly reduce the cyber attack surface in the North American power grid. Our proposed project was a synergistic collaborative effort leveraging the synergistic expertise of the team members across power systems, cyber security and CPS security, testbeds, field deployments and demonstration, and successful commercialization. The following are the specific tasks that have been successfully completed two phases (2016-2020). Phase I: Task 1: Developed and implemented a robust Project Management and Data Management Plan, coupled with a well thought out Risk Mitigation Plan. Task 2.1: Developed a comprehensive framework that continually assesses and autonomously reduces the attack surface for the power grid control environment spanning across substations, control center and the SCADA network to significantly reduce the risks of cyber attacks. Task 2.2: Developed attack surface analysis techniques, metrics, and tools that assess the attack surface at multiple levels including the control center, substations, and the SCADA network. Task 2.3: Developed attack surface reduction techniques and tools that dynamically reduce attack surface and hence increase attacker’s cost without interfering in the critical functions of the system. Task 2.4: Prototyped, implemented, and quantitatively evaluated/validated the techniques and tools on a realistic industrial CPS security testbed environment by leveraging the unique resources of the team. Task 3: Developed Commercialization plan to transition the developed tools into power system industry stakeholders for a broader adoption by leveraging the expertise of our industrial members. Phase II: Task 4: Successfully completed field demonstration, verification, and evaluation of the effectiveness of the attack surface analysis and reduction techniques on a realistic utility testbed environment. This also involved the development of realistic scenarios, sound metrics, data sets, evaluation criteria, and documentation. Technology integration & Field demonstration: The project had significantly advanced the state-of-the-art research and practice in improving the cybersecurity of our nation’s power grid infrastructure against cyber threats. In particular, the proposed, designed, and deployed attack surface analysis and reduction algorithms and tools have contributed to significantly reducing the exposure and risk of the devices, substations, and the integrated SCADA/EMS/ DMS grid environment to cyber threat. Strong demonstration and evaluation techniques have verified the feasibility of the developed techniques on realistic cyber-physical testbeds and utility partner's real grid environment, and collaborative research and evaluation of attack surface reduction techniques (for wide-are monitoring and control) within a vendor (GE) EMS platform. The Attack Host Analyzer (AHA) tool that was developed through this project was made available through GitHub.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Efficient Clustering of Software Vulnerabilities using Self Organizing Map (SOM)

The common vulnerabilities and exposures (CVE) database was created with a mission to ``identify, define, and catalog publicly disclosed cybersecurity vulnerabilities''. This rich body of information can be used to enable rapid and efficient response to secure and defend cyber operations and protect critical cyber infrastructure. The main goal of this paper is to develop a visual analytics tool to enable deep analysis of CVEs using unsupervised clustering techniques. We enhance our analysis by first mapping CVEs to hierarchical-classes in Common Weakness Enumeration (CWE) using information in the National Vulnerability Database (NVD). Both the mapping and the numerical representation of CVEs are enabled by V2W-BERT, which uses natural language processing of the extensive information in NVD to generate a large tabular database of 137,226 CVE entries from 1999 to 2020, where each CVE is represented by a vector of 768 numerical features. The vectorized data is processed by Self-Organizing Maps (SOM), which is an unsupervised machine learning technique for dimensionality reduction, visual representation and clustering. Using a Torus map of 6417 units, we achieve ~10-fold data compression of ~140k CVEs using SOM. The trained map is further clustered using standard K-means clustering into 138 clusters of CVEs. We conducted a brief investigation of the rich mapping of CVEs to best-matching-units to K-means clusters, as well as CVEs to CWEs. For example, this novel mapping provided insight into the role of CWE-59 and CWE-264 in several CVEs that is otherwise hard to explore in the original data. We conclude that our this novel approach will not only enable deep analysis of the complex relationships between CVEs and CWEs, but also a mechanism to quickly respond to and design mitigation actions for rapidly evolving vulnerabilities that have not been mapped to existing CWEs.

Panchal, Khyati↗

Convergence of Emerging Technologies - OWL Test Results

The OWL GroundAware GA1360 2D radar system with advertised capability of advanced digital beam-forming radar technology, classification intelligence, reconfigurability, and easy integration with other security systems to bring 360° of real-time, all-weather situational awareness for the physical security of perimeters and other sensitive areas for critical infrastructure.

47 OTHER INSTRUMENTATION↗

Environmental Extremes: Building a New Research Partnership between the University of Nevada Reno and the Pacific Northwest National Laboratory (Final Report)

This project focused on strengthening research partnership and collaboration between the University of Nevada, Reno (UNR) and the Pacific Northwest National laboratory (PNNL) in two focused areas: wildfires and hydrology in the context of environmental extremes. The goal was to overcome barriers and bring UNR university researchers, students, and postdocs up to speed and entrained into DOE/SC/BER /Earth and Environmental System Science Division’s (EESSD) environmental research enterprise. UNR continues to work with the Earth and Biological Sciences Directorate (EBSD) at PNNL to create a broad new collaborative research program connecting scientists and research faculty at the two institutions. This research partnership has been designed to increase the capabilities and velocities of both institutions by developing long-term relationships between researchers from each institution, exposing university researchers to the deep capabilities in the DOE National Laboratories and user facilities, and establishing a pipeline of skilled and experienced graduate students and postdoctoral researchers ready to work alongside DOE scientists to take on grand challenge science problems. These collaborations are intended to ultimately benefit the public by advancing scientific discovery, unleashing the scientific potentials through collaboration and connection, enriching the technical and scientific competitiveness of our nation, and enabling the development of a skilled workforce to tackle the critical scientific challenges that face our nation’s security, infrastructure, and prosperity.

54 ENVIRONMENTAL SCIENCES↗

FY 2021 Idaho National Laboratory Site Sustainability Plan

The mission of the Department of Energy (DOE) is to ensure America’s security and prosperity by addressing its energy, environmental, and nuclear challenges through transformative science and technology solutions. This FY 2021 Idaho National Laboratory Site Sustainability Plan (SSP) was developed to enable and sustain Idaho National Laboratory’s (INL’s) mission to discover, demonstrate, and secure innovative nuclear solutions, clean energy options, and critical infrastructure. The SSP was developed according to the narrative requirements from the “FY 2021 DOE Site Sustainability Plan Guidance” document issued in August 2020. The SSP contains strategies and activities that will lead to continual energy, water, and waste reductions that move INL toward meeting DOE sustainability goals and requirements. The SSP summarizes energy and available fuel use reporting requirements and references criteria for instituting sustainable design. SSP requirements are integrated into each INL contractor’s Integrated Safety Management System and Environmental Management System (EMS). Finally, the Sustainability Program directives, based on this SSP, are integrated into the INL Annual Laboratory Plan Fiscal Year 2020 (INL/LTD-20-59747), and operations and acquisition systems.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

FY 2022 Idaho National Laboratory Site Sustainability Plan

The mission of the Department of Energy (DOE) is to ensure America’s security and prosperity by addressing its energy, environmental and nuclear challenges through transformative science and technology solutions. This FY 2022 Idaho National Laboratory Site Sustainability Plan (SSP) was developed to enable and sustain Idaho National Laboratory’s (INL’s) mission to discover, demonstrate, and secure innovative nuclear solutions, clean energy options, and critical infrastructure. DOE Order 436.1, “Departmental Sustainability,” provides requirements and assigns responsibilities for managing sustainability within DOE to ensure that DOE missions are carried out in a sustainable manner, to institute wholesale cultural change to factor sustainability into all DOE decisions, and to ensure DOE achieves sustainability goals. DOE Order 436.1 also requires DOE sites to commit appropriate personnel resources, establish a financing plan that prioritizes the use of life-cycle cost effective private-sector financing, optimize the application of appropriations and budgeted funds, and establish specific performance measures and deliverables designed to achieve the listed requirements. The SSP was developed according to the narrative requirements from the “FY 2022 DOE Site Sustainability Plan Guidance” document issued in September 2021. The SSP contains strategies and activities that will lead to continual energy, water, and waste reductions that move the INL site toward meeting DOE sustainability goals and requirements. The SSP summarizes energy and available fuel use reporting requirements and references criteria for instituting sustainable design. SSP requirements are integrated into each INL site contractor’s Integrated Safety Management System and Environmental Management System (EMS). Finally, the Sustainability Program directives, based on this SSP, are integrated into INL/LTD-21-62463, Annual Laboratory Plan 2021, and operations and acquisition systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

FY 2023 Idaho National Laboratory Site Sustainability Plan

The mission of the Department of Energy (DOE) is to ensure America’s security and prosperity by addressing its energy, environmental and nuclear challenges through transformative science and technology solutions. This FY 2022 Idaho National Laboratory Site Sustainability Plan (SSP) was developed to enable and sustain Idaho National Laboratory’s (INL’s) mission to discover, demonstrate, and secure innovative nuclear solutions, clean energy options, and critical infrastructure. DOE Order 436.1, “Departmental Sustainability,” provides requirements and assigns responsibilities for managing sustainability within DOE to ensure that DOE missions are carried out in a sustainable manner, to institute wholesale cultural change to factor sustainability into all DOE decisions, and to ensure DOE achieves sustainability goals. DOE Order 436.1 also requires DOE sites to commit appropriate personnel resources, establish a financing plan that prioritizes the use of life-cycle cost effective private-sector financing, optimize the application of appropriations and budgeted funds, and establish specific performance measures and deliverables designed to achieve the listed requirements. The SSP was developed according to the narrative requirements from the “FY 2022 DOE Site Sustainability Plan Guidance” document issued in September 2021. The SSP contains strategies and activities that will lead to continual energy, water, and waste reductions that move the INL site toward meeting DOE sustainability goals and requirements. The SSP summarizes energy and available fuel use reporting requirements and references criteria for instituting sustainable design. SSP requirements are integrated into each INL site contractor’s Integrated Safety Management System and Environmental Management System (EMS). Finally, the Sustainability Program directives, based on this SSP, are integrated into INL/LTD-21-62463, Annual Laboratory Plan 2021, and operations and acquisition systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

NLR CSP Optical Facilities: Illuminating the Path Forward Through Innovation and Impact: Agreement 38490

This initiative is a multi-faceted project at the National Laboratory of the Rockies (NLR) aimed at strengthening its Concentrating Solar Power (CSP) Optical Facilities to advance the development of low-cost, high-performance materials for solar and other applications. The project's strategy is built on three pillars: strategic stakeholder engagement, diligent facility maintenance and utilization, and the development of new research capabilities. The overarching goal is to ensure the facilities remain state-of-the-art resources for industry and academia, thereby accelerating the conversion of concentrated sunlight into energy. A key driver of the project is an international Advisory Board, which provides critical guidance on research priorities and industry needs, leading to new collaborations and secured funding. This external engagement, combined with proactive outreach to industry partners, ensures the lab's work remains aligned with real-world challenges, including materials durability and performance certification. Significant efforts in facility maintenance have addressed challenges with aging infrastructure. Notable achievements include the complete refurbishment of the hail-damaged Ultra-Accelerated Weathering System (UAWS) and the successful replacement of a failing 15-year-old Lambda 1050 spectrophotometer with a new-generation model, substantially upgrading material characterization capabilities. These maintenance activities were complemented by achieving a prestigious ISO 9001:2015 certification for the Advanced Optical Materials Labs, formally recognizing the quality and reliability of NLR's measurement capabilities. Despite these successes, challenges remain, including high demand for the High Flux Solar Furnace (HFSF) and intermittent failures of other key instruments. The project has delivered major advancements in research techniques and capabilities. At the Flatirons campus, a new indoor laboratory, was established to house advanced deflectometry and photogrammetry systems for heliostat characterization. For on-sun testing, a novel, actively cooled turning mirror was developed for the HFSF, enabling more realistic testing of particle receivers and components. A collaboration with Virginia Tech successfully demonstrated the high-temperature durability of a new solar absorber coating through extensive cyclic testing. Concurrently, new modeling took place to better predict material degradation on rough, fractal surfaces. In summary, this project has systematically enhanced NLR's CSP Optical Facilities through strategic upgrades, rigorous maintenance, and stakeholder-guided research. By overcoming equipment failures, budgetary constraints, and logistical hurdles, the project has reinforced NLR's role as a central hub for CSP innovation and materials testing. Future work will focus on securing diverse funding, expanding collaborations, and continuing to provide the critical infrastructure needed to accelerate the development and deployment of next-generation technologies.

14 SOLAR ENERGY↗

Requirements and Recommendations for a Physical Attack Characterization Framework

This study seeks to identify existing frameworks or develop requirements and recommendations for a new framework that can consistently characterize physical attacks, analogous to MITRE ATT&CK®. MITRE ATT&CK is widely used across government, research organizations, and the cyber security community to characterize cyber attack tactics, techniques, and procedures (TTPs) in a consistent and commonly understood manner. While physical attack taxonomies, methodologies, and other tools for evaluating physical security do exist, many are sector and/or facility-type specific—and therefore not able to provide comparable scenarios across sectors—or are more focused on security assessment instead of the characterization of attacks themselves. A MITRE ATT&CK analog for physical attacks on critical infrastructure would provide a common language and structure for analysis of physical attacks. Existing attack characterization methodologies do not robustly address cyber-physical security risks. To fully understand a facility’s security needs, it is important to understand the entire vulnerability landscape from both a physical and a cyber perspective. To underscore this need, organizations such as the Cybersecurity and Infrastructure Security Agency (CISA) are calling for a coordinated approach to cyber and physical security, which they refer to as cyber and physical security convergence. A physical attack characterization framework that could be used jointly with MITRE ATT&CK would help support a more robust analysis in support of convergence, enabling the consistent characterization of attacks that utilize both cyber and physical tactics and techniques. This could provide analysts and stakeholders with a clearer understanding of how security mitigations deployed in the physical realm impact security risks in the cyber realm, and vice versa. In this study, the project team evaluates existing physical security taxonomies and methodologies to assess whether an existing method can be used to create a “physical half” of MITRE ATT&CK. This study then provides requirements and recommendations for a framework that can leverage aspects of existing methodologies. The goal of the final framework is for it to be widely adopted and referenced, regardless of critical infrastructure sector, facility type, or facility components. This study also identifies applicable use cases for when and how a framework could be applied across the various critical infrastructure sectors for a variety of attack types or motivations. Through a literature review of existing security-focused methodologies and taxonomies, engagement with relative stakeholders, evaluation of potential physical attack framework use cases, and subsequent identification of requirements, this study identified the following key findings and recommendations: There is a need for a new physical attack characterization framework; A physical attack framework should be interoperable with the MITRE ATT&CK framework; A physical attack framework should be broadly applicable, but with detailed tactics, techniques, and procedures that encompass the entire attack path; A physical attack framework should be based on observed or feasible events; A physical attack framework should adapt features from existing methodologies, frameworks, and taxonomies; A physical attack framework should be owned, overseen, and maintained by one organization.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Autonomous Tools for Attack Surface Reduction

The electric power grid is a complex critical infrastructure that forms the lifeline of modern society, and its secure and reliable operation is of paramount importance to national security and economic well being. However, recent findings documented in authoritative sources indicate the threat of cyber-based attacks growing in numbers and sophistication. However, securing the grid against stealthy cyber attacks is a challenging task due to legacy nature of the infrastructure coupled with dynamic nature of threat landscape and ever growing sophistication of the adversaries. Additionally, the grid’s attack surface continues to grow with the increased dependence on digital communications and control that now extends to each consumer through smart meters and distributed energy resources. Unfortunately, this expansive surface increases the grid’s vulnerability and further exposes critical control systems in both substations and control centers. To respond to this emerging need, we had successfully assembled an interdisciplinary team with academic- industry partnership to successfully conduct research, development, evaluation, demonstration, and commercialization of attack surface reduction tools, whose goal is to significantly reduce the cyber attack surface in the North American power grid. Our proposed project was a synergistic collaborative effort leveraging the synergistic expertise of the team members across power systems, cyber security and CPS security, testbeds, field deployments and demonstration, and successful commercialization. The team consisted of leading experts from two major universities – Iowa State University, Washington State University – complemented by reputed researchers from two DOE national laboratories – Pacific Northwest National Lab, and Argonne National Lab, one major utility vendor GE Global Research, and one utility partner – Cedar Falls Utilities (CFU). The team members have proven track record of successful academic-industry collaboration in interdisciplinary R&D projects, and bring onboard some of the best state-of-the-art testbed resources, industry-grade SCADA/EMS/DMS environment for experimentation and field demonstration.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Considerations for Emerging Energy Technologies

AI, cloud computing, post-quantum cryptography, zero-trust architectures, microgrids, and virtual power plants. What do these things have in common? They are all emerging technologies in the clean energy space that will be a critical part of grid modernization efforts. As we work towards clean energy and decarbonization targets, these technologies, developed to solve real-world problems, will help us reach goals and achieve new efficiencies as the paradigm of grid operation shifts. However, there are growing concerns about the cybersecurity risks associated with these trending topics as they are used in critical infrastructure applications. This talk will cover gaps, challenges, and opportunities for the secure implementation of grid modernization solutions and novel energy applications of state-of-the-art networking and communications. Proactive risk mitigation strategies, including the application of cyber-informed engineering, will be discussed. Practical applications of these techniques will help provide countermeasures to the impact of cyberattacks on critical infrastructure technologies in a new, digitized grid landscape.

14 SOLAR ENERGY↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Arctic Critical Infrastructure: Assessing and Predicting the Risk to Critical Permafrost Infrastructure from Climate Change: A New Thermomechanical Approach

This study presents the development of a computational framework designed to predict the interaction between permafrost and infrastructure, addressing potential failure modes and mitigation strategies in the context of climate change. The framework, rooted in advanced modeling and simulation (mod/sim) techniques, integrates thermomechanical coupling to account for the complex interplay between heat flow, ice content, and mechanical behavior in permafrost. Existing models fail to fully capture these dynamics, particularly as they relate to the effects of ice saturation on structural integrity. Our innovative Arctic Coastal Erosion (ACE) framework fills this gap by coupling thermal and mechanical models to accurately simulate subsidence and deformation in permafrost environments. We applied the ACE framework to a representative runway, demonstrating its capability to predict settlement due to rising temperatures and subsequent permafrost thaw. This proof-of-concept showcases the potential of the framework to evaluate risks to Arctic infrastructure, which supports over four million people and 70% of existing permafrost-based structures. By simulating various infrastructure types and environmental conditions, our research offers insights into failure mechanisms and evaluates structural solutions to mitigate risk. The anticipated deliverables, including a prototype runway exemplar, position this project as a critical advancement in permafrost infrastructure modeling, with applications in national security and resilience planning.

54 ENVIRONMENTAL SCIENCES↗

Modeling and Detection of Future Cyber-Enabled DSM Data Attacks

Demand-Side Management (DSM) is an essential tool to ensure power system reliability and stability. In future smart grids, certain portions of a customer’s load usage could be under the automatic control of a cyber-enabled DSM program, which selectively schedules loads as a function of electricity prices to improve power balance and grid stability. In this scenario, the security of DSM cyberinfrastructure will be critical as advanced metering infrastructure and communication systems are susceptible to cyber-attacks. Such attacks, in the form of false data injections, can manipulate customer load profiles and cause metering chaos and energy losses in the grid. The feedback mechanism between load management on the consumer side and dynamic price schemes employed by independent system operators can further exacerbate attacks. To study how this feedback mechanism may worsen attacks in future cyber-enabled DSM programs, we propose a novel mathematical framework for (i) modeling the nonlinear relationship between load management and real-time pricing, (ii) simulating residential load data and prices, (iii) creating cyber-attacks, and (iv) detecting said attacks. In this framework, we first develop time-series forecasts to model load demand and use them as inputs to an elasticity model for the price-demand relationship in the DSM loop. This work then investigates the behavior of such a feedback loop under intentional cyber-attacks. We simulate and examine load-price data under different DSM-participation levels with three types of random additive attacks: ramp, sudden, and point attacks. We conduct two investigations for the detection of DSM attacks. The first studies a supervised learning approach, with various classification models, and the second studies the performance of parametric and nonparametric change point detectors. Results conclude that higher amounts of DSM participation can exacerbate ramp and sudden attacks leading to better detection of such attacks, especially with supervised learning classifiers. We also find that nonparametric detection outperforms parametric for smaller user pools, and random point attacks are the hardest to detect with any method.

97 MATHEMATICS AND COMPUTING↗

2022 Annual Report Laboratory Directed Research & Development

Idaho National Laboratory’s (INL’s) mission is “to discover, demonstrate and secure innovative nuclear energy solutions, other clean energy options and critical infrastructure.” INL executes this mission through research and development across the continuum from basic science to applied science to engineering demonstration and then deployment. The Department of Energy (DOE) Laboratory Directed Research and Development (LDRD) program enables INL to conduct high-risk, impactful research that enriches the laboratory capabilities in order to further its missions. INL’s LDRD portfolio specifically advances the core capabilities of the laboratory aligned with its five science and technology initiatives: 1) nuclear reactor sustainment and expanded deployment, 2) integrated fuel cycle solutions, 3) integrated energy systems, 4) advanced design and manufacturing for extreme environments, and 5) secure and resilient cyber-physical systems. The 45 projects that ended in fiscal year 2022 and highlighted in this report are just a small sample of the impressive breadth and depth of cutting-edge science, technology, and engineering ongoing at INL.

99 GENERAL AND MISCELLANEOUS↗