Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Securing Inverter Communication: Proactive Intrusion Detection and Mitigation System to Tap, Analyze, and Act

The electric grid has undergone rapid, revolutionary changes in recent years; from the addition of advanced smart technologies to the growing penetration of distributed energy resources (DERs) to increased interconnectivity and communications. However, these added communications, access interfaces, and third-party software to enable autonomous control schemes and interconnectivity also expand the attack surface of the grid. To address the gap of DER cybersecurity and secure the grid-edge to motivate a holistic, defense-in-depth approach, a proactive intrusion detection and mitigation system (PIDMS) device was developed to secure PV smart inverter communications. The PIDMS was developed as a distributed, flexible bump-in-the-wire (BITW) solution for protecting PV smart inverter communications. Both cyber (network traffic) and physical (power system measurements) are processed using network intrusion monitoring tools and custom machinelearning algorithms for deep packet analysis and cyber-physical event correlation. The PIDMS not only detects abnormal events but also deploys mitigations to limit or eliminate system impact; the PIDMS communicates with peer PIDMSs at different locations using the MQTT protocol for increased situational awareness and alerting. The details of the PIDMS methodology and prototype development are detailed in this report as well as the evaluation results within a cyber-physical emulation environment and subsequent industry feedback.

14 SOLAR ENERGY↗

Cybersecurity Assessment in DER-rich Distribution Operations: Criticality Levels and Impact Analysis

The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.

Maharjan, Manisha↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

Development of a Cloud-based Application to Enable a Scalable Risk-informed Predictive Maintenance Strategy at Nuclear Power Plants

Light-water reactor operations and maintenance (O&M) costs are prohibitively high, thus contributing to the premature decommissioning of nuclear power plants (NPPs). This is partly due to how the equipment is monitored. In recent years, cloud computing has emerged as a dominant technology by virtue of its low costs, computing and storage adaptability, and ability to host applications over numerous types of virtual infrastructures. Cloud computing can be a cost-effective alternative to onsite storage and diagnostics. This paper conducts a techno-economic assessment of a provisional cloud deployment architecture for a NPP predictive monitoring (PdM) system. The cloud-based monitoring system would enable maintenance and diagnostics (M&D) analysts and other authorized plant users to remotely monitor equipment functionality so as to enable PdM practices and early detection of faults. The Microsoft Azure cloud platform is included in the proposed cloud architecture to provide data processing and storage, sensor device networking, and database management; however, this analysis could be extended to other cloud computing service providers as well. For the techno-economic assessment, technical feasibility is measured in terms of network performance metrics such as response time, latency, and throughput, whereas economic feasibility is measured in terms of operational costs and capital expenditures. Finally, this report covers certain regulatory and security aspects that may concern licensees looking to implement cloud computing. The report focuses on the integration of sensor database storage, the application of cloud resources to PdM, and the identification of technological and economic hurdles associated with moving to a cloud-computing-based architecture.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

Mapping Critical Vulnerabilities in Natural Gas Pipeline Systems through Network Centrality and GIS Analytics

Natural gas plays a central role in the US energy landscape, providing 43% of electricity generation in 2023. Its exclusive recovery ability on pipelines for transmission underscores the importance of understanding the disruption recovery ability of this infrastructure. This study employs a network-based analytical framework integrating geographic information systems (GIS) with multiple centrality measures—betweenness, closeness, degree, and eigenvector—to pinpoint key segments and evaluate the structural robustness of the national pipeline network. Pipelines are grouped by System ID and Operator ID to capture variations across organizational and physical structures. The analysis reveals uneven patterns of network influence, where certain pipelines function as critical connectors or dominant hubs. Spatial mapping highlights geographic dependencies and potential chokepoints, offering a clear view of where targeted risk prevention measures would be most effective. The findings provide practical guidance for prioritizing maintenance, enhancing system robustness, and mitigating risks to ensure a stable and secure energy supply. Future research will expand the framework to incorporate dynamic operational data and real-time network behavior.

Peterson, Steven [ORNL] (ORCID:0000000287672998)↗

Securing Solar for the Grid: Spring 2024 IAB Meeting

The Spring 2024 IAB meeting will focus on updates from the research team and collective feedback and inputs for an updated Roadmap for Solar Cybersecurity. Researchers from the four DOE National Laboratories will present with industry counterparts for the major research tasks within the S2G program, including: Solar Cybersecurity Standards and Certifications, Solar Risk Assessments & Mitigation, Solar Supply Chain Assessment, Network Monitoring Tools and Analysis, and Training and Workforce Development. Sandia National Laboratories developed an original Roadmap for PV Cybersecurity in 2017. This year, we are updating that roadmap to reflect the current state of research and industry and identify gaps and priorities still to be addressed. We look forward to the IAB’s input on key topics for the roadmap.

14 SOLAR ENERGY↗

Integrated Research Infrastructure Architecture Blueprint Activity (Final Report 2023)

The complexity of scientific pursuits is increasing rapidly with aspects that require dynamic integration of experiment, observation, theory, modeling, simulation, visualization, machine learning (ML), artificial intelligence (AI), and analysis. Research projects across the Department of Energy (DOE) are increasingly data and compute intensive. Innovative research teams are accelerating the pace of discovery by using high-performance computational and data tools in their research workflows and leveraging multiple research infrastructures. Additionally, several recent high-level U.S. government reports underscore the necessity of a new advanced computing ecosystem for international competitiveness and national security. International competitors are moving forward with major research infrastructure integration efforts that seek to capture a competitive advantage in the global innovation race. Owing to its unparalleled constellation of world-class experimental and observational facilities and high-performance and extreme-scale computational, data, and networking infrastructure, DOE is positioned to be a global leader in this new era of integrated science. However, this new integration paradigm will demand continuing evolution to ensure the U.S. remains a global leader in research and innovation. The DOE Office of Science (SC) has seized on the strategic importance of integration and has adopted a vision for Integrated Research Infrastructure (IRI): To empower researchers to meld DOE’s world-class research tools, infrastructure, and user facilities seamlessly and securely in novel ways to radically accelerate discovery and innovation. To respond to the evolving computational requirements of research and the competitive international innovation landscape, experimental facilities could be connected with high performance computing resources for near real-time analysis, and resources should be provided for merging enormous and diverse data for AI/ML techniques and analysis.

97 MATHEMATICS AND COMPUTING↗

A hardware-in-the-loop (HIL) testbed for cyber-physical energy systems in smart commercial buildings

In recent years, there has been a growing trend toward the development of smart buildings that rely on cyber-physical systems (CPS) to optimize occupant comfort, safety, and energy efficiency. To ensure the reliable and efficient operation of CPS with designed control strategies, it is important to evaluate their performance under various scenarios before deploying them in the real world. This is where a Hardware-in-the-loop (HIL) testbed designed for studying sensor and control-related studies in smart buildings can be highly valuable. With the growing threat of cyber-attacks and physical faults targeting smart buildings, it is essential to ensure the security of building operations. A HIL testbed can emulate cyber-attack and physical fault scenarios, allowing researchers to develop and test threat detection and mitigation algorithms. This enables researchers to identify potential issues and optimize the algorithms in a safe and controlled environment before they are deployed in real-world settings, reducing the risk of failures that can negatively impact occupant comfort, safety, and energy efficiency. Therefore, this paper developed a HIL testbed designed for cyber-physical energy systems (e.g. buildings automation system (BAS)) in smart commercial buildings. The HIL testbed is comprised of a real-time building and Heating, Ventilation, and Air-Conditioning (HVAC) emulator using Modelica-based dynamic models, a set of BAS controllers, and a BAS computer server. The data generation capability of the HIL testbed is demonstrated by tracking normal and faulty operating data in the BAS, as well as monitoring detailed network traffic in the local BAS network. Here, this study further demonstrates the HIL testbed’s capability by conducting case studies on real-time physical fault and cyber-attack experiments using a Department of Energy (DOE) prototype commercial building. It is anticipated that the fully functional HIL testbed will be utilized for a variety of sensor and control-related studies, including but not limited to testing, developing, validating of different HVAC control strategies, fault detection & diagnosis, energy monitoring and analysis, cyber security study, etc.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

CFD Data Sets on the WWW for Education and Testing

The Numerical Aerodynamic Simulation (NAS) Systems Division at NASA Ames Research Center has begun the development of a Computational Fluid Dynamics (CFD) data set archive on the World Wide Web (WWW) at URL http://www.nas.nasa.gov/NAS/DataSets/. Data sets are integrated with related information such as research papers, metadata, visualizations, etc. In this paper, four classes of users are identified and discussed: students, visualization developers, CFD practitioners, and management. Bandwidth and security issues are briefly reviewed and the status of the archive as of May 1995 is examined. Routine network distribution of data sets is likely to have profound implications for the conduct of science. The exact nature of these changes is subject to speculation, but the ability for anyone to examine the data, in addition to the investigator's analysis, may well play an important role in the future.

Globus, Al↗

Real-Time Xenon Sensor Analysis Report

Radiotracer release experiments were performed at the Nevada National Security Site in October 2022. The overall experiment was called the RElease ACTivity (REACT) experiment. Twenty-two real-time xenon sensors were deployed for each of four releases. Initial, quick-look analysis results were reported in December 2022. This report reviews the more comprehensive offline analysis effort that was conducted during the remainder of fiscal year 2023 by the Dynamic Networks venture. Improved energy stabilization routines were implemented along with an improved background subtraction routine compared to the original quicklook calculations. The relative detection efficiencies of all real-time sensors were examined. Finally, simulated detector response functions were coupled to two different meteorological models using the measured conditions for the final release (REACT-04) to compare simulated detections with measurements. While there is some agreement between the models and measured data on the detection locations and timing, there is less agreement on the magnitude of those detections. Future sensor and meteorological modeling work will be needed to improve the agreement and to examine the additional releases (REACT-01 through REACT-03).

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Compact Microscope Imaging System With Intelligent Controls Improved

The Compact Microscope Imaging System (CMIS) with intelligent controls is a diagnostic microscope analysis tool with intelligent controls for use in space, industrial, medical, and security applications. This compact miniature microscope, which can perform tasks usually reserved for conventional microscopes, has unique advantages in the fields of microscopy, biomedical research, inline process inspection, and space science. Its unique approach integrates a machine vision technique with an instrumentation and control technique that provides intelligence via the use of adaptive neural networks. The CMIS system was developed at the NASA Glenn Research Center specifically for interface detection used for colloid hard spheres experiments; biological cell detection for patch clamping, cell movement, and tracking; and detection of anode and cathode defects for laboratory samples using microscope technology.

McDowell, Mark↗

Management of the Space Physics Analysis Network (SPAN)

Here, the purpose is to define the operational management structure and to delineate the responsibilities of key Space Physics Analysis Network (SPAN) individuals. The management structure must take into account the large NASA and ESA science research community by giving them a major voice in the operation of the system. Appropriate NASA and ESA interfaces must be provided so that there will be adequate communications facilities available when needed. Responsibilities are delineated for the Advisory Committee, the Steering Committee, the Project Scientist, the Project Manager, the SPAN Security Manager, the Internetwork Manager, the Network Operations Manager, the Remote Site Manager, and others.

Green, James L.↗

Hybrid Network Architectures for the Next Generation NAS

To meet the needs of the 21st Century NAS, an integrated, network-centric infrastructure is essential that is characterized by secure, high bandwidth, digital communication systems that support precision navigation capable of reducing position errors for all aircraft to within a few meters. This system will also require precision surveillance systems capable of accurately locating all aircraft, and automatically detecting any deviations from an approved path within seconds and be able to deliver high resolution weather forecasts - critical to create 4- dimensional (space and time) profiles for up to 6 hours for all atmospheric conditions affecting aviation, including wake vortices. The 21st Century NAS will be characterized by highly accurate digital data bases depicting terrain, obstacle, and airport information no matter what visibility conditions exist. This research task will be to perform a high-level requirements analysis of the applications, information and services required by the next generation National Airspace System. The investigation and analysis is expected to lead to the development and design of several national network-centric communications architectures that would be capable of supporting the Next Generation NAS.

Madubata, Christian↗

Subsurface microbial communities as a tool for characterizing regional-scale groundwater flow

Subsurface microbial community distribution patterns are influenced by biogeochemical and groundwater fluxes and may inform hydraulic connections along groundwater-flow paths. This study examined the regional-scale microbial community of the Death Valley Regional Flow System and evaluated whether subsurface communities can be used to identify groundwater-flow paths between recharge and discharge areas. Samples were collected from 36 sites in three groundwater basins: Pahute Mesa–Oasis Valley (PMOV), Ash Meadows (AM), and Alkali Flat–Furnace Creek Ranch (AFFCR). Microbial diversity within and between communities varied by location, and communities were separated into two overall groups that affiliated with the AM and PMOV/AFFCR basins. Network analysis revealed patterns between clusters of common microbes that represented groundwaters with similar geochemical conditions and largely corroborated hydraulic connections between recharge and discharge areas. Null model analyses identified deterministic and stochastic ecological processes contributing to microbial community assemblages. Most communities were more different than expected and governed by dispersal limitation, geochemical differences, or undominating processes. However, certain communities from sites located within or near the Nevada National Security Site were more similar than expected and dominated by homogeneous dispersal or selection. Overall, the (dis)similarities between the microbial communities of DVRFS recharge and discharge areas supported previously documented hydraulic connections between: (1) Spring Mountains and Ash Meadows; (2) Frenchman and Yucca Flat and Amargosa Desert; and (3) Amargosa Desert and Death Valley. However, only a portion of the flow path between Pahute Mesa and Oasis Valley could be supported by microbial community analyses, likely due to well-associated artifacts in samples from the two Oasis Valley sites. This study demonstrates the utility of combining microbial data with hydrologic, geologic, and water-chemistry information to comprehensively characterize groundwater systems, highlighting both strengths and limitations of this approach.

54 ENVIRONMENTAL SCIENCES↗

MiniMOD

SAND2025-03854O MiniMod is a user-friendly software tool designed to assess the performance of high-performance computing (HPC) systems. Researchers can use the program to test communication methods and computational tasks to understand how different setups can affect application efficiency. This software is particularly useful for optimizing network performance in scientific research, simulations, and data analysis. MiniMod‘s flexible design allows users to make informed decisions about their computing environments, which can enhance productivity and results in real-world applications. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Dosanjh, Matthew [Sandia National Lab. (SNL-CA), L↗