Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack surface”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

A supercritical airfoil experiment

The purpose of this investigation is to provide a comprehensive data base for the validation of numerical simulations. The initial results of the study (single angle of attack) were presented in ref. 1, where the effects of various parameters and the adequacies of selected turbulence models were discussed. The objective of the present paper is to provide a tabulation of the experimental data. The data were obtained in the two-dimensional, transonic flowfield surrounding a supercritical airfoil. A variety of flows were studied in which the boundary layer at the trailing edge of the model was either attached or separated. Unsteady flows were avoided by controlling the Mach number and angle of attack. Surface pressures were measured on both the model and wind tunnel walls, and the flowfield surrounding the model was documented using a laser Doppler velocimeter (LDV). Although wall interference could not be completely eliminated, its effect was minimized by employing the following techniques. Sidewall boundary layers were reduced by aspiration, and upper and lower walls were contoured to accommodate the flow around the model and the boundary-layer growth on the tunnel walls. A data base with minimal interference from a tunnel with solid walls provides an ideal basis for evaluating the development of codes for the transonic speed range because the codes can include the wall boundary conditions more precisely than interference corrections can be made to the data sets.

Mateer, George G.↗

A supercritical airfoil experiment

The purpose of this investigation is to provide a comprehensive data base for the validation of numerical simulations. The objective of the present paper is to provide a tabulation of the experimental data. The data were obtained in the two-dimensional, transonic flowfield surrounding a supercritical airfoil. A variety of flows were studied in which the boundary layer at the trailing edge of the model was either attached or separated. Unsteady flows were avoided by controlling the Mach number and angle of attack. Surface pressures were measured on both the model and wind tunnel walls, and the flowfield surrounding the model was documented using a laser Doppler velocimeter (LDV). Although wall interference could not be completely eliminated, its effect was minimized by employing the following techniques. Sidewall boundary layers were reduced by aspiration, and upper and lower walls were contoured to accommodate the flow around the model and the boundary-layer growth on the tunnel walls. A data base with minimal interference from a tunnel with solid walls provides an ideal basis for evaluating the development of codes for the transonic speed range because the codes can include the wall boundary conditions more precisely than interference connections can be made to the data sets.

Mateer, G. G.↗

Rhenium/Oxygen Interactions at Elevated Temperatures

The oxidation of pure rhenium is examined from 600-1400 C in oxygen/argon mixtures. Linear weight loss kinetics are observed. Gas pressures, flow rates, and temperatures are methodically varied to determine the rate controlling steps. The reaction at 600 and 800 C appears to be controlled by a chemical reaction step at the surface; whereas the higher temperature reactions appear to be controlled by gas phase diffusion of oxygen to the rhenium surface. Attack of the rhenium appears to be along grain boundaries and crystallographic planes.

Jacobson, Nathan↗

Addressing Software Security

Historically security within organizations was thought of as an IT function (web sites/servers, email, workstation patching, etc.) Threat landscape has evolved (Script Kiddies, Hackers, Advanced Persistent Threat (APT), Nation States, etc.) Attack surface has expanded -Networks interconnected!! Some security posture factors Network Layer (Routers, Firewalls, etc.) Computer Network Defense (IPS/IDS, Sensors, Continuous Monitoring, etc.) Industrial Control Systems (ICS) Software Security (COTS, FOSS, Custom, etc.)

software↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

IS BLOCKCHAIN A SUITABLE TECHNOLOGY FOR ENSURING THE INTEGRITY OF DATA SHARED BY LIGHTING AND OTHER BUILDING SYSTEMS?

Increasing amounts of data are available from lighting and other building systems. In commercial buildings, these data can be used to improve system and energy performance, detect and diagnose faults, and facilitate maintenance. Building data are not only of interest to owners and operators of the building systems, however. Owners and operators of similar buildings, manufacturers of building systems, utilities, and city agencies also have interesting use cases. Energy data can, for example, be used to verify the performance of energy-conservation measures, issue renewableenergy certificates, and financially settle grid services. Increased data sharing, however, significantly expands the cyber-attack surface, creating new challenges. In this work, blockchain is explored as an option for ensuring the integrity of data that are shared by lighting and other building systems. Blockchain fundamentals and variants are briefly reviewed, and value propositions relevant to building systems are discussed. A recently developed blockchain applicability framework (BAF) that builds upon and addresses the limitations of previous applicability models is also briefly reviewed. The BAF is used to assess the suitability of blockchain over other technologies or approaches for building-data applications, using emerging connected lighting systems as an example use case.

blockchain, connected lighting system, data integr↗

Cyber Threat Assessment Methodology for Autonomous and Remote Operations for Advanced Reactors (Conference Presentation)

The next generation of Advanced Reactors include planned capabilities for both Autonomous (operating without human interaction for a set period-of-time) and Remote (operating with human interaction from a separate physical location) Operations. Existing Nuclear Reactor architectures include a set of safety and security constraints tightly coupled with personnel policies and procedures. As Advanced Reactors are fielded with these new Autonomous and Remote operational capabilities, the architectures and associated infrastructure services and components will perceivably expand the overall attack surface and risk calculations with regards to safe and secure operations. This paper is part of an FY21 work program focused on ensuring Advanced Reactor designs are informed with threat-based guidance on design and operation of Secure Architectures with a specific focus on the deployment of Autonomous Systems in support of Advanced Reactor Operations. The next phase of this research program is to complement produce a methodology for assessment of the cyber threat against these architectures as well as a catalogue of Use Cases to support the Advanced Reactor community in their implementation of Autonomous and Remote Operations.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

Johnson, Jay Tillay↗

Empowering Critical Infrastructure Communication with Secure 5G Private Networks

With the transformational New Radio- Unlicensed (NR-U), 5G network can be operated with unlicensed and shared spectrum. Private 5G networks without any licensed bands, which are both highly expensive and usually available to only large commercial wireless providers, can now be used for a whole range of new applications including smart factories, warehouses, connected cars and drones. 5G’s support of a) massive machine type communication (mMTC) for a large number of connected devices with b) ultra-reliable low latency communication (URLLC) capability when needed, and c) up to 20 times higher data rate with enhanced mobile broadband (eMBB) than previously available, enables new and powerful capabilities in a wireless network. While these capabilities are transformational, necessary security and reliability requirements have to be satisfied when used in critical infrastructure such as factories, power plants, water systems, ports, and other industrial facilities. 5G standards have introduced significant security improvement over 4G/LTE as well as mitigations for new attack surfaces created by changes in the 5G network. This talk will discuss these security improvements and whether they meet the security properties required for mission critical communication over wireless.

5G↗

Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The future of the grid will be powered by AI—or undermined by it. Artificial intelligence is rapidly reshaping grid operations, improving fault detection, forecasting accuracy, and real-time optimization. As AI systems move closer to operational decision loops, however, they introduce new consequence pathways: expanded attack surfaces, model integrity risks, regulatory exposure, and human-automation challenges. This talk presents a consequence-driven framework for deploying AI responsibly in the electric grid. Attendees will gain practical strategies to strengthen resilience, boost reliability, and deploy AI securely — ensuring the grid of the future is not only smarter but safer.

25 - ENERGY STORAGE↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Normal- and oblique-shock flow parameters in equilibrium air including attached-shock solutions for surfaces at angles of attack, sweep, and dihedral

Normal- and oblique-shock flow parameters for air in thermochemical equilibrium are tabulated as a function of shock angle for altitudes ranging from 15.24 km to 91.44 km in increments of 7.62 km at selected hypersonic speeds. Post-shock parameters tabulated include flow-deflection angle, velocity, Mach number, compressibility factor, isentropic exponent, viscosity, Reynolds number, entropy difference, and static pressure, temperature, density, and enthalpy ratios across the shock. A procedure is presented for obtaining oblique-shock flow properties in equilibrium air on surfaces at various angles of attack, sweep, and dihedral by use of the two-dimensional tabulations. Plots of the flow parameters against flow-deflection angle are presented at altitudes of 30.48, 60.96, and 91.44 km for various stream velocities.

Hunt, J. L.↗

Wind-tunnel research comparing lateral control devices, particularly at high angles of attack XII : upper-surface ailerons on wings with split flaps

This report covers the twelfth of a series of tests conducted to compare different lateral control devices with particular reference to their effectiveness at high angles of attack. The present wind tunnel tests were made with two sizes of upper-surface ailerons on rectangular Clark Y wing models equipped with full span split flaps. The tests showed the effect of the upper-surface ailerons and of the split flaps on the general performance characteristics of the wings, and on the lateral controllability and stability characteristics. The results are compared with those for plain wings with ordinary ailerons of similar sizes.

Weick, Fred E↗

A method for estimating static aerodynamic characteristics for slender bodies of circular and noncircular cross section alone and with lifting surfaces at angles of attack from 0 deg to 90 deg

An engineering-type method is presented for estimating normal-force, axial-force, and pitching-moment coefficients for slender bodies of circular and noncircular cross section alone and with lifting surfaces. Static aerodynamic characteristics computed by the method are shown to agree closely with experimental results for slender bodies of circular and elliptic cross section and for winged-circular and winged-elliptic cones. However, the present experimental results used for comparison with the method are limited to angles of attack only up to about 20 deg and Mach numbers from 2 to 4.

Jorgensen, L. H.↗

Calculation of potential flow past non-lifting bodies at angle of attack using axial and surface singularity methods

Two different singularity methods have been utilized to calculate the potential flow past a three dimensional non-lifting body. Two separate FORTRAN computer programs have been developed to implement these theoretical models, which will in the future allow inclusion of the fuselage effect in a pair of existing subcritical wing design computer programs. The first method uses higher order axial singularity distributions to model axisymmetric bodies of revolution in an either axial or inclined uniform potential flow. Use of inset of the singularity line away from the body for blunt noses, and cosine-type element distributions have been applied to obtain the optimal results. Excellent agreement to five significant figures with the exact solution pressure coefficient value has been found for a series of ellipsoids at different angles of attack. Solutions obtained for other axisymmetric bodies compare well with available experimental data. The second method utilizes distributions of singularities on the body surface, in the form of a discrete vortex lattice. This program is capable of modeling arbitrary three dimensional non-lifting bodies. Much effort has been devoted to finding the optimal method of calculating the tangential velocity on the body surface, extending techniques previously developed by other workers.

Shu, J. Y.↗