Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Fission Battery Initiative: Research and Development Plan

The Fission Battery Initiative has been established by the Idaho National Laboratory’s (INL’s) Nuclear Science and Technology Directorate [6] to define, focus, and coordinate research and development (R&D) of technologies that can fully achieve battery-like functionality for nuclear energy systems. The notion of a “fission battery” conveys a vision focused on realizing very simple “plug-and-play” nuclear systems that can be integrated into a variety of applications requiring affordable, reliable energy in the form of electricity and/or heat and function without operations and maintenance staff. In order to formalize the desired functionality, the initiative has adopted the following key attributes to be achieved: economic, standardized, installed, unattended and reliable

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

2021 Annual Report Laboratory Directed Research & Development

The Department of Energy’s (DOE) Laboratory Directed Research and Development (LDRD) program is an essential pathway for innovation, capability growth, and research staff development at Idaho National Laboratory (INL). This program enables timely and agile response to national security, energy, and environmental challenges that motivate INL’s mission to discover and demonstrate innovative nuclear energy solutions and other clean energy options as well as securing our critical infrastructure. This report highlights INL’s LDRD projects concluding in fiscal year (FY) 2021 which included innovative research and development (R&D) across INL’s five science and technology initiatives: nuclear reactor sustainment and expanded deployment, integrated fuel cycle solutions, integrated energy systems, advanced design and manufacturing for extreme environments, and secure and resilient cyber-physical systems.

99 GENERAL AND MISCELLANEOUS↗

Integrating Cybersecurity with System Operations and Restoration

This presentation covers the interaction of the discipline of system operations with the discipline of cybersecurity. First, a common mental model for risk - both cybersecurity and all-hazards - is presented, followed by a discussion of high-level management strategies for different kinds of cyber harm facing system operators, based on the consequences and frequencies of the harm. The next section covers the importance of cybersecurity for a system operator organization and explains some general concepts to understand the relationships. Finally the role of system operators in the security of the grid as a larger system of systems is discussed over the framework of a resilience event.

24 POWER TRANSMISSION AND DISTRIBUTION↗

INL FY 2021 Laboratory Overview

The INL FY 2021 Laboratory Overview is an opportunity for INL to share its achievements and plans for the future with the entire Laboratory, stakeholders, and the public. This document outlines how INL will advance its clean energy and national security objectives in the future and highlights FY 2020 accomplishments across the Laboratory in science and technology, community outreach, and operations.

07 ISOTOPE AND RADIATION SOURCES↗

Cyber-Resilient Design Methodology for Microgrids

Recent advancement in tools has helped with microgrid design, development, planning and operation. Microgrids offer a unique application based on users with different requirements for tools. The process of designing, constructing, commissioning, and assessing a microgrid is not always straightforward due to these distinct requirements. Additionally, metrics are needed for performance evaluation. This panel will offer an overview and description of tools that helps with microgrid design, construction, planning, operation, cyber security, and metrics-driven performance assessment driven by multiple diverse applications and use cases.

CCE↗

Advancing Nuclear Energy to Support a Net-Zero Future

Seminar for the KEPCO International Nuclear Graduate School (KINGS) in South Korea. The presentation will cover a brief introduction to INL, opportunities for advanced nuclear, and integrated energy systems.

08 HYDROGEN↗

Cyber-Informed Engineering

Briefings provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.

42 ENGINEERING↗

Applying Cyber-Informed Engineering to Power System Operations

This presentation covers the interaction of the discipline of system operations with the growing body of knowledge around Cyber-Informed Engineering (CIE). First is discussion of a number of fundamental concepts for system operators - organizational division of responsibilities, human and machine cooperation, goals, and priorities. The next section covers the reasons why CIE was developed, what it is, and the key design and operational, and organizational principles of CIE. Finally, some thoughts on how CIE can be applied to power system operations are offered, along with some examples of how an organization can approach applying CIE principles in their particular circumstances.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Mental Models for Managing Grid Cybersecurity Risk - ARC Industry Forum, Cybersecurity and Energy Transition

A proper mental model of the concepts of cyber risk and its components of threat and exploitability and consequence is necessary to allocate limited resources to different security activities, especially when considered alongside reliability and regulatory and economic risks. Understanding the consequence and frequency different risks are realized also helps align the right mitigations to the right risks. Cyber-informed engineering (CIE) is an emerging method to “engineer out” cyber risk across product and system lifecycles, and INL has a portfolio of programs operationalizing CIE’s principles for the energy sector.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CCE and Resilience Strategies

Consequence-driven Cyber-informed Engineering (CCE) is a methodology focused on securing the nation’s critical infrastructure systems. Developed at Idaho National Laboratory, CCE starts with the assumption that if a critical infrastructure system is targeted by a skilled and determined adversary, the targeted network can and will be penetrated. This think like the adversary approach provides critical infrastructure owners, operators, vendors and manufacturers with a disciplined methodology to: evaluate complex systems; determine what must be fully safeguarded; and apply proven engineering strategies to isolate and protect an industry’s most critical assets.

42 ENGINEERING↗

Idaho National Laboratory Energy Cybersecurity Programs Update

This brief presentation provides a status update on three Idaho National Laboratory energy cybersecurity programs of particular interest to NERC Reliability and Security Technical Committee annual in-person Security Groups summit. Public information on the following three programs is included: Cybersecurity for Operational Technology Environments (CyOTE™) program Cyber-Informed Engineering (CIE) Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, and associated high-level information on the Energy Software Bill of Materials POC, Executive Order 14017, and the Energy Cyber Sense Act

24 POWER TRANSMISSION AND DISTRIBUTION↗

HOP and Cybersecurity: Leveraging safety and reliability experience to improve digital security culture

This presentation will introduce participants to key mental models on how to think about and understand safety and the organizational attributes that support it from three of the leading voices in the discipline – David Marx, Dr. Erik Hollnagel and Dr. Todd Conklin – and from there we ask the simple question of “how can we apply this to cybersecurity?” Opportunities, similarities, and differences from the history of accomplishment applying human and organizational performance principles to safety and reliability can be collectively leveraged to the meet the challenge of cybersecurity for OT/ICS/cyber-physical systems. This is the same intent as the "Cybersecurity Culture" principle of Cyber-Informed Engineering (CIE).

42 ENGINEERING↗

Using Cyber-Informed Engineering for Cyber Defense Workbook

This workbook was prepared for a detailed workshop in Cyber-Informed Engineering. It is designed to provide an audience of electrical cooperative engineering staff with an opportunity to practice leveraging the principles of Cyber-Informed Engineering for a hypothetical system upgrade. This workbook contains material describing the fictional project, information about Cyber-Informed Engineering, hands-on exercises, and a copy of the slides presented during the workshop. It can stand alone as a CIE resource.

42 ENGINEERING↗

Data-Driven Probabilistic Anomaly Detection for Electricity Market under Cyber Attacks

Information and communication technologies have been widely used in smart grid for efficient operation. However, these technologies are vulnerable to malicious cyber attacks, which may lead to severe reliability and economic issues. Recently, a variety of data-driven anomaly detection approaches have been explored to detect potential cyber attacks in smart grids. In this paper, we researched on the electricity market data aiming to identify anomalies from the locational marginal prices (LMPs) and provide a new indicator for potential cyber attacks in power grids. Specifically, a novel data-driven probabilistic anomaly detection framework is proposed for electricity market, which consists of three major components: long short-term memory (LSTM) based deterministic electricity price forecasting, probabilistic electricity price forecasting and anomaly detection. This framework is tested on a model-based electricity market simulator under two types of cyber attacks, i.e., load redistribution attack (LRA) and price responsive attack (PRA). Numerical results on the simulated LMPs show that the proposed framework is capable of detecting data anomalies over these attacks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Multiple social platforms reveal actionable signals for software vulnerability awareness: A study of GitHub, Twitter and Reddit

Software vulnerabilities are flaws in computer systems that leave users open to attack. In many cases, these vulnerabilities go unnoticed and remain unresolved in codebases. Thus, awareness of software vulnerabilities among the public is crucial to ensure effective cybersecurity practices, the development of high quality software, and ultimately national security. This awareness can be better understood by studying the spread and evolution of software vulnerability discussions in online communities. This work is the first to evaluate and contrast how discussions about software vulnerabilities spread on three social platforms -- Twitter, GitHub, and Reddit. To lay the groundwork, we showcase a novel fundamental framework for measuring information spread that identifies the spread mechanisms and observables across platforms, the units of information, and the groups of measurements that can be applied to focus on a specific phenomena e.g., information cascades. We then analyze and contrast social network topologies for three example social networks and measure the scale and speed of the spread of discussion of specific vulnerabilities to understand how far and how widely they spread, how many users participate in discussions, and the duration of their spread. To demonstrate the awareness of more impactful software vulnerabilities, a subset of our analysis focuses on vulnerabilities targeted during recent major cyber attacks as well as vulnerabilities exploited by advanced persistent threat groups. We discover that usually, vulnerability discussions start on GitHub, before occurring on Twitter and Reddit. While studying how some user-level and content-level characteristics influence vulnerability spread, we observe that Twitter discussions started by users predicted to be humans have larger size, breadth, depth, adoption rate, lifetime, and structural virality compared to those started by users predicted to be bots. On Reddit, we contrast the differences in thread structure that originate from posts with positive, negative and neutral polarity. We find that posts that are positive have larger, deeper and wider discussions compared to negative and neutral posts. We anticipate the results of our analysis to not only increase the understanding of software vulnerability awareness but also inform models for simulating information spread across multiple social environments online.

97 MATHEMATICS AND COMPUTING↗