Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management

Marine renewable energy (MRE) is an emerging source of power for marine applications, marine devices, and coastal communities. This energy source relies on industrial control systems and IT to support operations and maintenance activities, which create a pathway for an adversary to gain unauthorized access to systems and data and disrupt operations. Incorporating cybersecurity risk prevention measures and mitigation capabilities from inception, development, operation, to decommissioning of the MRE system and components is paramount to the protection of energy generation and the security of network architecture and infrastructure. To improve the resilience of MRE systems as a predictable, affordable, and reliable source of energy, cybersecurity guidance was developed to enable operators to assess cybersecurity risks and implement security measures commensurate with the risk. This publication is the second of a two-part series, with Part 1 addressing a framework to determine cybersecurity risk by assessing the vulnerability of an MRE system to potential cyber threats and the consequences a cyberattack would have on the end user. This Part 2 publication describes an approach to select appropriate cybersecurity best practices commensurate with the MRE system's cybersecurity risk. The guidance includes 86 cybersecurity best practices, which are associated with 36 cybersecurity domains and grouped into nine categories. The best practices follow the core functions of the National Institute of Science and Technology Cybersecurity Framework (e.g., identify, detect, protect, respond, and and recover) and insights from both maritime and energy industry guidance documents to identify security measures effective in protecting information and operational technology assets prevalent in MRE systems.

97 MATHEMATICS AND COMPUTING↗

A Trilevel Model for Segmentation of the Power Transmission Grid Cyber Network

Network segmentation of a power grid's communication system can make the grid more resilient to cyberattacks. Here we develop a novel trilevel programming model to optimally segment a grid communication system, taking into account the actions of an information technology (IT) administrator, attacker, and grid operator. The IT administrator is allowed to segment existing networks, and the attacker is given a budget to inflict damage on the grid by attacking the segmented communication system. Finally, the grid operator can redispatch the grid after the attack to minimize damage. The resulting problem is a trilevel interdiction problem that we solve using a branch and bound algorithm for bilevel problems. We demonstrate the benefits of optimal network segmentation through case studies on the 9-bus Western System Coordinating Council (WSCC) system and the 30-bus IEEE system. These examples illustrate that network segmentation can significantly reduce the threat posed by a cyberattacker.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Revisiting Current Paradigms: Subject Matter Expert Views on High Consequence Facility Security Assessments

Security assessments support decision-makers' ability to evaluate current capabilities of high consequence facilities (HCF) to respond to possible attacks. However, increasing complexity of today's operational environment requires a critical review of traditional approaches to ensure that implemented assessments are providing relevant and timely insights into security of HCFs. Using interviews and focus groups with diverse subject matter experts (SMEs), this study evaluated the current state of security assessments and identified opportunities to achieve a more "ideal" state. The SME-based data underscored the value of a systems approach for understanding the impacts of changing operational designs and contexts (as well as cultural influences) on security to address methodological shortcomings of traditional assessment processes. These findings can be used to inform the development of new approaches to HCF security assessments that are able to more accurately reflect changing operational environments and effectively mitigate concerns arising from new adversary capabilities.

36 MATERIALS SCIENCE↗

Harnessing the Power of AI: Status and Expansion of Current Domestic Transport Security Through Flexible Embedded Hardware

As applications of Artificial Intelligence (AI) continue to expand, there are increasing opportunities to leverage applied AI methodologies with mobile transportation focused embedded systems. Current applications of AI in transportation focus on a variety of areas, including fuel efficiency, safety, security, and other broad fields of optimization or detection. To leverage these AI workflows and methodologies in the field, teams must utilize complex embedded systems capable of implementing these AI-enabled algorithms in real-time. In this paper, we will investigate how these algorithms can be integrated into existing technologies leveraging vehicle data - such as the Controller Area Network Transport Security Tracking and Reporting Unit (C-STAR). The C-STAR technology is an embedded platform with onboard computation capable of running next generation algorithms in vehicle systems AI, such as preventative maintenance, driver authentication, and transport security. As deployed in the field, the C-STAR has a limited AI functionality –this paper will directly discuss how a device like C-STAR can be utilized and the advantages of integrating these new technologies. We will open with relevant background information and transportation projects that leverage AI, focusing specifically on those around transport security such as vehicle identification, anomaly detection, and deterrence. We will then extend this into potential opportunities and scaling for AI methodologies using platforms like the C-STAR. Finally, we will speak directly to the challenges of deploying AI-powered workflows, such as computing power needs, bandwidth, hallucinations, and other regulatory considerations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

The Synchronic Web

The Synchronic Web is a distributed network for securing data provenance on the World Wide Web. By enabling clients around the world to freely commit digital information into a single shared view of history, it provides a foundational basis of truth on which to build decentralized and scalable trust across the Internet. Its core cryptographical capability allows mutually distrusting parties to create and verify statements of the following form: “I commit to this information—and only this information—at this moment in time.” The backbone of the Synchronic Web infrastructure is a simple, small, and semantic-free blockchain that is accessible to any Internet-enabled entity. The infrastructure is maintained by a permissioned network of well-known servers, called notaries, and accessed by a permissionless group of clients, called journals. Through an evolving stack of flexible and composable semantic specifications, the parties cooperate to generate synchronic commitments over arbitrary data. When integrated with existing infrastructures, adapted to diverse domains, and scaled across the breadth of cyberspace, the Synchronic Web provides a ubiquitous mechanism to lock the world’s data into unique points in discrete time and digital space. This document provides a technical description of the core Synchronic Web system. The distinguishing innovation in our design—and the enabling mechanism behind the model—is the novel use of verifiable maps to place authenticated content into canonically defined locations off-chain. While concrete specifications and software implementations of the Synchronic Web continue to evolve, the information covered in the body of this document should remain stable. We aim to present this information clearly and concisely for technical non-experts to understand the essential functionality and value proposition of the network. In the interest of promoting discourse, we take some liberty in projecting the potential implications of the new model.

97 MATHEMATICS AND COMPUTING↗

Security-Constrained Unit Commitment for Electricity Market: Modeling, Solution Methods, and Future Challenges

This paper summarizes the technical activities of the IEEE Task Force on Solving Large Scale Optimization Problems in Electricity Market and Power System Applications. This Task Force was established by the IEEE Technology and Innovation Subcommittee to first review the state-of-the-art of the security-constrained unit commitment (SCUC) business model, its mathematical formulation, and solution techniques in solving electricity market clearing problems. The Task Force then investigated the emerging challenges of future market clearing problems and presented efforts in building benchmark mathematical and business models.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Distributed Trust Model Simulator for Energy Grid of Things Distributed Energy Resource Management System

The evolution of networks into more distributed, self-reliant nodes has mitigated single-point failures that plagued traditional centralized networks. Applied to power grids, distributed systems can increase the integrity and availability of grid services while also offering a power management solution. However, while distributed networks provide scalability, security, and sustainability compared to centralized networks, their distributed nature makes them harder for anomaly detection and prevention. Incorporating a Distributed Trust Model (DTM) System into an Energy Grid of Things Distributed Energy Resource Management System (EGOT DERMS) allows grid participants to be characterized and their communication to be analyzed for possible attacks. A Trust Model simulator is needed to evaluate and improve the DTM System.Trustworthiness is calculated using a Trust Model. While many trust models exist, most only consider 2-3 matrices to evaluate trust. The TM proposed in this thesis uses a Metric Vector of Trust (MVoT) monitoring 17 parameters when assessing trust. Moreover, unlike standard trust models, the proposed trust model establishes a method to test the trust between various actors within the network and probe the trust model itself. Using a Trust Model Simulator, MVoT calaculations, initial values, and parameters are fine-tuned to achieve high-confidence message classifications and minimize false positives. The DTM System and Trust Mode Simulation Suite allow for distributed trust evaluation with a real-time classification of EGOT DERMS actors, providing additional security for distributed systems.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Resilient Design of Continuous-time Distributed Optimization Algorithm in the Presence of Cyber-attacks

This paper presents a continuous-time resilient distributed optimization algorithm based on competitive interaction design method on connected graphs in the presence of adversaries. Here, the competitive interaction method allows us to design a network that protects the multi-agent systems from adversaries without requiring high network connectivity. In addition, the proposed algorithm does not require the global information about the number of adversaries. First, we show that the proposed distributed algorithm solves the resilient distributed optimization problem with no attack on the communication links. Second, we show that the proposed continuous-time distributed optimization algorithm on connected graphs converges to the small neighborhood of the optimal solution in the presence of cyber-attacks onto the communication channel. Simulations are presented to illustrate our theoretical results.

97 MATHEMATICS AND COMPUTING↗

Wildfires increasingly impact western US fluvial networks

Wildfires are increasing globally in frequency, severity, and extent, but their impact on fluvial networks, and the resources they provide, remains unclear. We combine remote sensing of burn perimeter and severity, in-situ water quality monitoring, and longitudinal modeling to create the first large-scale, long-term estimates of stream+river length impacted by wildfire for the western US. We find that wildfires directly impact ~6% of the total stream+river length between 1984 and 2014, increasing at a rate of 342 km/year. When longitudinal propagation of water quality impacts is included, we estimate that wildfires affect ~11% of the total stream+river length. Our results indicate that wildfire activity is one of the largest drivers of aquatic impairment, though it is not routinely reported by regulatory agencies, as wildfire impacts on fluvial networks remain unconstrained. We identify key actions to address this knowledge gap and better understand the growing threat to fluvial networks, water security, and public health risks.

54 ENVIRONMENTAL SCIENCES↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

Equipment Self-Assessment Guide Checklist

This Equipment Self-Assessment Checklist is designed for asset owners and operators (AOOs) responsible for the deployment, operation, maintenance, or cybersecurity oversight of grid systems and digital energy technologies. It provides a structured inspection checklist for evaluating the security, integrity, and operational trustworthiness of equipment across substations, generation sites, distributed energy resources (DERs), and control environments.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

TriC: Distributed-memory Triangle Counting by Exploiting the Graph Structure

Graph analytics has emerged as an important tool in the analysis of large scale data from diverse application domains such as social networks, cyber security and bioinformatics. Counting the number of triangles in a graph is a fundamental kernel with several applications such as detecting the community structure of a graph or in identifying important vertices in a graph. The ubiquity of massive datasets is driving the need to scale graph analytics on parallel systems. However, numerous challenges exist in efficiently parallelizing graph algorithms, especially on distributed-memory systems. Irregular memory accesses and communication patterns, low computation to communication ratios, and the need for frequent synchronization are some of the leading challenges. In this paper, we present TriC, our distributed-memory implementation of triangle counting in graphs using the Message Passing Interface (MPI), as a submission to the 2020 GraphChallenge competition. Using a set of synthetic and real-world inputs from the challenge, we demonstrate a speedup of up to 90x relative to previous work on 32 processor-cores of a NERSC Cori node. We also provide details from distributed runs with up to8192 processes along with strong scaling results. The observations presented in this work provide an understanding of the system-level bottlenecks at scale that specifically impact sparse-irregular workloads and will therefore benefit other efforts to parallelize graph algorithms.

Halappanavar, Mahantesh↗

Communication system and method for applying security for a time sensitive network

A method includes identifying power connections between plural components of a time sensitive network (TSN) that are interconnected via a predetermined connection plan. The method also includes determining a topology of the components of the TSN based on the power connections. Also, the method includes scheduling flows for the TSN based on the topology determined based on the power connections.

Bush, Stephen Francis↗