Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Cyber Energy Emulation Platform (CEEP) [SWR-20-102]

NREL's Cyber-Energy Emulation Platform (CEEP) provides the capability to realize cyber-energy security and resilience through automation and orchestration of virtualized systems and software defined networks for the electric grid. CEEP enables testing and validation of grid-security and -control methodologies as the grid evolves to include smart technologies/systems, such as virtualization and containerization of grid components, software defined networking, simulation and co-simulation frameworks, and hardware in the loop. CEEP is a modular system that can be distributed and deployed across different hardware infrastructure sizes and network architectures. For example, CEEP can visualize, emulate, and/or coordinate the Smart-Grid Network Visualization, Intrusion Detection, and Network Healing system. Using CEEP, intrusion-detection and network-self-healing solutions can be deployed at grid control centers, within secure private clouds, and in cyber-energy appliances.

Rivera, Joshua↗

Toward Common Weakness Enumerations in Industrial Control Systems

Here, the storyline of MITRE’s common weakness enumeration framework illustrates how the security and privacy technical community can collaborate/cooperate with policy makers to advance policy, giving it specifics and filling gaps of technical knowledge to improve security and resilience of critical infrastructure.

42 ENGINEERING↗

Engineering Controls Database

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

Source record↗

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

Grid-Forming Frequency Shaping Control for Low-Inertia Power Systems

As power systems transit to a state of high renewable penetration, little or no presence of synchronous generators makes the prerequisite of well-regulated frequency for grid-following inverters unrealistic. As such, there is a trend to resort to grid-forming inverters which set frequency directly. We propose a novel grid-forming frequency shaping control that is able to shape the aggregate system frequency dynamics into a first-order one with the desired steady-state frequency deviation and Rate of Change of Frequency (RoCoF) after a sudden power imbalance. The no overshoot property resulting from the first-order dynamics allows the system frequency to monotonically move towards its new steady-state without experiencing frequency Nadir, which largely improves frequency security. We prove that our grid-forming frequency-shaping control renders the system internally stable under mild assumptions. The performance of the proposed control is verified via numerical simulations on a modified Icelandic Power Network test case.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Grid-Forming Frequency Shaping Control for Low-Inertia Power Systems

As power systems transit to a state of high renewable penetration, little or no presence of synchronous generators makes the prerequisite of well-regulated frequency for grid-following inverters unrealistic. Thus, there is a trend to resort to grid-forming inverters which set frequency directly. We propose a novel grid-forming frequency shaping control that is able to shape the aggregate system frequency dynamics into a first-order one with the desired steady-state frequency deviation and Rate of Change of Frequency (RoCoF) after a sudden power imbalance. The no overshoot property resulting from the first-order dynamics allows the system frequency to monotonically move towards its new steady-state without experiencing frequency Nadir, which largely improves frequency security. We prove that our grid-forming frequency-shaping control renders the system internally stable under mild assumptions. The performance of the proposed control is verified via numerical simulations on a modified Icelandic Power Network test case.

control systems↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Industrial Control Systems Network Protocol Parsers

Industrial Control Systems protocol parsers plugins for the Zeek network security monitoring framework. Currently we have four fully developed protocol parsers but we plan on adding more in the future. The protocol parsers we currently have developed are for BACnet, DNP3, Ethernet/IP, and Modbus.

Rasmussen, BrettD↗

Fusing Edge Computing with Transport Security by Leveraging the Controller Area Network Transport Security Tracking and Reporting (C-STAR) Unit

Rapid advances in embedded system complexity and capability provides exciting opportunities for transportation security deployment. Manufacturers and developers of these embedded systems continue to provide lower cost and more powerful solutions that can be leveraged by researchers and engineers. Furthermore, deploying these devices at the “edge” of the Internet-of-Things (IoT) infrastructure provides opportunities for highly capable applications in transport security. In an edge computation architecture, the device is co-located at the source of the data in the larger IoT structure – this provides computational capability at the location directly where the data is collected. For shipment transport security, this provides a direct compute node for digestion of data and mitigation actions in real-time. In our application, the vehicle provides a significant amount of this data that can be processed in real-time via the Controller Area Network Transport Security Tracking and Reporting (C-STAR) edge device. Utilization of a computational node located on the vehicle, such as the C-STAR, capitalizes on previously discussed opportunities of edge architectures. In this paper, we will discuss this security solution’s usability, current deployments, and scalability to further applications in transport security. First, we will cover the supported vehicle platforms that can leverage the C-STAR technology. This will be particularly relevant to medium- and heavy-duty vehicles transporting high-risk shipments. Second, we will speak to current deployments of the C-STAR that are ongoing. Finally, we will discuss additional areas for expansion such as maturing the onboard algorithms through continuing collaborations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Cyber-Informed Engineering Principles: What’s in it for me?

CIE is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system that has digital connectivity, monitoring, or control. CIE complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Rather, it expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve, and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences. Engineers and technicians that design critical energy infrastructure installations can integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. These principles are aimed at system or design engineers, operators, and technicians, rather than software engineers or operational cybersecurity practitioners, because the engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. This approach creates new opportunities for engineering teams—and not just cybersecurity teams—to secure the system using the physics and mechanics of engineering controls—not just digital monitoring and controls.

99 GENERAL AND MISCELLANEOUS↗

Entropy of the Quantum–Classical Interface: A Potential Metric for Security

Hybrid quantum–classical systems are emerging as key platforms in quantum computing, sensing, and communication technologies, but the quantum–classical interface (QCI)—the boundary enabling these systems—introduces unique and largely unexplored security vulnerabilities. This position paper proposes using entropy-based metrics to monitor and enhance security, specifically at the QCI. We present a theoretical security outline that leverages well-established information-theoretic entropy measures, such as Shannon entropy, von Neumann entropy, and quantum relative entropy, to detect anomalous behaviors and potential breaches at the QCI. By linking entropy fluctuations to scenarios of practical relevance—including quantum key distribution, quantum sensing, and hybrid control systems—we promote the potential value and applicability of entropy-based security monitoring. While explicitly acknowledging practical limitations and theoretical assumptions, we argue that entropy-based metrics provide a complementary approach to existing security methods, inviting further empirical studies and theoretical refinements that can strengthen future quantum technologies.

97 MATHEMATICS AND COMPUTING↗

Capabilities for Water Sector Infrastructure Resilience - Prioritizing RD&D in a Target Rich, Resource Poor Sector

WSTB & Water Sector Security Program Expansion Objective: Incubate and shepherd a public-private consortium of joint seal US government sponsors and industry stakeholders to build out industrial control system (ICS) and operational technology (OT) architecture of the Idaho National Laboratory (INL) Water Security Test Bed (WSTB) asset to enable research, testing, and cyber workforce training related to evolving cyber-physical and physical vulnerabilities and threats in the water sector.

99 - GENERAL AND MISCELLANEOUS↗

Security Constrained Economic Optimization of Photovoltaic and Other Distributed Assets

The rapid growth of distributed energy resources (DERs), especially photovoltaic (PV) systems, has introduced new complexities in maintaining grid reliability, stability, and cost-effective operation. This project addresses these challenges by developing and demonstrating a scalable GridOS Distributed Energy Resource Management System (DERMS) that enables secure, real-time optimization and control of DERs at the distribution feeder level.

14 SOLAR ENERGY↗

Advancing Conduction-Cooled 650 MHz SRF Technology for Industrial Accelerators at Fermilab's IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator’s control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility—attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications

Ji, Y. [Fermilab] (ORCID:0000000233981752)↗

Advancing Conduction-Cooled 650 MHZ SRF Technology for Industrial Accelerators at Fermilab S IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator's control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications.

Ji, Yichen [Fermilab]↗

Industrial control system device classification using network traffic features and neural network embeddings

Characterization of modern cyber–physical Industrial Control System (ICS) devices is critical to the evaluation of their security posture and an understanding of the underlying industrial processes with which they interact. In this work, we address two related ICS device identification tasks: (1) separating ICS from non-ICS devices and (2) identifying specific ICS device types. We propose two distinct methods (one based on the existing IP2Vec method, and a novel traffic-features-based method) for achieving the first task. For transferability of the first task between two datasets, the traffic-features-based method performs significantly better (75% overall accuracy) compared to IP2Vec (22.5% overall accuracy). We further propose a novel method called DNP2Vec to address the second task. DNP2Vec is evaluated on two different datasets and achieves perfect multi-class classification accuracy (100%) for both datasets.

42 ENGINEERING↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗