Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber Research”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

Considerations for an Integrated UAS CNS Architecture

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) is investigating revolutionary and advanced universal, reliable, always available, cyber secure and affordable Communication, Navigation, Surveillance (CNS) options for all altitudes of UAS operations. In Spring 2015, NASA issued a Call for Proposals under NASA Research Announcements (NRA) NNH15ZEA001N, Amendment 7 Subtopic 2.4. Boeing was selected to conduct a study with the objective to determine the most promising candidate technologies for Unmanned Air Systems (UAS) air-to-air and air-to-ground data exchange and analyze their suitability in a post-NextGen NAS environment. The overall objectives are to develop UAS CNS requirements and then develop architectures that satisfy the requirements for UAS in both controlled and uncontrolled air space. This contract is funded under NASAs Aeronautics Research Mission Directorates (ARMD) Aviation Operations and Safety Program (AOSP) Safe Autonomous Systems Operations (SASO) project and proposes technologies for the Unmanned Air Systems Traffic Management (UTM) service.There is a need for accommodating large-scale populations of Unmanned Air Systems (UAS) in the national air space. Scale obviously impacts capacity planning for Communication, Navitation, and Surveillance (CNS) technologies. For example, can wireless communications data links provide the necessary capacity for accommodating millions of small UASs (sUAS) nationwide? Does the communications network provide sufficient Internet Protocol (IP) address space to allow air traffic control to securely address both UAS teams as a whole as well as individual UAS within each team? Can navigation and surveillance approaches assure safe route planning and safe separation of vehicles even in crowded skies?Our objective is to identify revolutionary and advanced CNS alternatives supporting UASs operating at all altitudes and in all airspace while accurately navigating in the absence of navigational aids. These CNS alternatives must be reliable, redundant, always available, cyber-secure, and affordable for all types of vehicles including small UAS to large transport category aircraft. The approach will identify CNS technology candidates that can meet the needs of the range of UAS missions to specific air traffic management applications where they will be most beneficial and cost effective.

Templin, Fred L.↗

Considerations for an Integrated UAS CNS Architecture

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) is investigating revolutionary and advanced universal, reliable, always available, cyber secure and affordable Communication, Navigation, Surveillance (CNS) options for all altitudes of UAS operations. In Spring 2015, NASA issued a Call for Proposals under NASA Research Announcements (NRA) NNH15ZEA001N, Amendment 7 Subtopic 2.4. Boeing was selected to conduct a study with the objective to determine the most promising candidate technologies for Unmanned Air Systems (UAS) air-to-air and air-to-ground data exchange and analyze their suitability in a post-NextGen NAS environment. The overall objectives are to develop UAS CNS requirements and then develop architectures that satisfy the requirements for UAS in both controlled and uncontrolled air space. This contract is funded under NASAs Aeronautics Research Mission Directorates (ARMD) Aviation Operations and Safety Program (AOSP) Safe Autonomous Systems Operations (SASO) project and proposes technologies for the Unmanned Air Systems Traffic Management (UTM) service.There is a need for accommodating large-scale populations of Unmanned Air Systems (UAS) in the national air space. Scale obviously impacts capacity planning for Communication, Navigation, and Surveillance (CNS) technologies. For example, can wireless communications data links provide the necessary capacity for accommodating millions of small UASs (sUAS) nationwide? Does the communications network provide sufficient Internet Protocol (IP) address space to allow air traffic control to securely address both UAS teams as a whole as well as individual UAS within each team? Can navigation and surveillance approaches assure safe route planning and safe separation of vehicles even in crowded skies?Our objective is to identify revolutionary and advanced CNS alternatives supporting UASs operating at all altitudes and in all airspace while accurately navigating in the absence of navigational aids. These CNS alternatives must be reliable, redundant, always available, cyber-secure, and affordable for all types of vehicles including small UAS to large transport category aircraft. The approach will identify CNS technology candidates that can meet the needs of the range of UAS missions to specific air traffic management applications where they will be most beneficial and cost effective.

Templin, Fred L.↗

Requirements for an Integrated UAS CNS Architecture

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) is investigating revolutionary and advanced universal, reliable, always available, cyber secure and affordable Communication, Navigation, Surveillance (CNS) options for all altitudes of UAS operations. In Spring 2015, NASA issued a Call for Proposals under NASA Research Announcements (NRA) NNH15ZEA001N, Amendment 7 Subtopic 2.4. Boeing was selected to conduct a study with the objective to determine the most promising candidate technologies for Unmanned Air Systems (UAS) air-to-air and air-to-ground data exchange and analyze their suitability in a post-NextGen NAS environment. The overall objectives are to develop UAS CNS requirements and then develop architectures that satisfy the requirements for UAS in both controlled and uncontrolled air space. This contract is funded under NASAs Aeronautics Research Mission Directorates (ARMD) Aviation Operations and Safety Program (AOSP) Safe Autonomous Systems Operations (SASO) project and proposes technologies for the Unmanned Air Systems Traffic Management (UTM) service. Communications, Navigation and Surveillance (CNS) requirements must be developed in order to establish a CNS architecture supporting Unmanned Air Systems integration in the National Air Space (UAS in the NAS). These requirements must address cybersecurity, future communications, satellite-based navigation APNT, and scalable surveillance and situational awareness. CNS integration, consolidation and miniaturization requirements are also important to support the explosive growth in small UAS deployment. Air Traffic Management (ATM) must also be accommodated to support critical Command and Control (C2) for Air Traffic Controllers (ATC). This document therefore presents UAS CNS requirements that will guide the architecture.

Templin, Fred↗

Condition monitoring and anomaly detection in cyber-physical systems

The modern industrial environment is equipping myriads of smart manufacturing machines where the state of each device can be monitored continuously. Such monitoring can help identify possible future failures and develop a cost-effective maintenance plan. However, it is a daunting task to perform early detection with low false positives and negatives from the huge volume of collected data. This requires developing a holistic machine learning framework to address the issues in condition monitoring of high priority components and develop efficient techniques to detect anomalies that can detect and possibly localize the faulty components. This paper presents a comparative analysis of recent machine learning approaches for robust, cost-effective anomaly detection in cyber-physical systems. While detection has been extensively studied, very few researchers have analyzed the localization of the anomalies. We show that supervised learning outperforms unsupervised algorithms. For supervised cases, we achieve near-perfect accuracy of 98% (specifically for tree-based algorithms). In contrast, the best-case accuracy in the unsupervised cases was 63%—the area under the receiver operating characteristic curve (AUC) exhibits similar outcomes as an additional metric.

Marfo, William↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyote Research Tool Library

The software is a library of individual proof-of-concept tools to be further developed in research efforts with partner utilities to detect indicators of Cyber Attacks within the Operational Technology Environments.

Wellman, LawrenceR.↗

What Clinical Trials Can Teach Us About the Development of More Resilient AI for Cybersecurity

Policy-mandated, rigorously administered scientific testing is needed to provide transparency into the efficacy of artificial intelligence-–based (AI-based) cyber defense tools for consumers and to prioritize future research and development. In this work, we propose a model that is informed by our experience, urged forward by massive-scale cyberattacks, and inspired by parallel developments in the biomedical field and the unprecedentedly fast development of new vaccines to combat global pathogens.

97 MATHEMATICS AND COMPUTING↗

Assessment of ROI for Workforce Development Efforts National & Homeland Security

The IDEAL Professional Engagement project at Idaho National Laboratory (INL) aims to enhance the laboratory's workforce diversity and inclusivity efforts, focusing on the U.S. National and Homeland Security mission areas. This project involves researching and evaluating opportunities for INL to engage in various professional events, particularly cyber conferences, to support recruitment and professional development. The project involved several key tasks: compiling comprehensive information on national laboratories and their mission statements, developing a deep understanding of INL’s role and efforts in national and homeland security, and identifying and engaging key stakeholders. Interviews were conducted with a set of targeted questions, and the findings were analyzed to identify common themes, insights, and actionable recommendations. Additionally, relevant upcoming cyber conferences were identified, various sponsorship levels and their associated benefits were evaluated, and the recruitment potential of these conferences was assessed. A detailed cost analysis was performed, including registration fees and travel expenses, and a cost-benefit analysis was conducted to evaluate the financial viability and potential return on investment (ROI) of conference participation and sponsorship. Based on the research and analysis, actionable recommendations for conference participation and sponsorship were formulated, ensuring alignment with INL’s mission and diversity goals. Preliminary results include a comprehensive list of relevant cyber conferences, a detailed cost analysis, and a set of actionable recommendations for future conference participation and sponsorship. The analysis highlights the financial requirements and geographical distribution of these conferences, providing valuable insights for INL's engagement strategies. This project underscores the importance of strategic engagement in professional events to attract and develop a diverse and skilled workforce, ultimately supporting INL’s mission areas in U.S. National and Homeland Security.

99 GENERAL AND MISCELLANEOUS↗

Cybersecurity for Digital Energy Infrastructure : Trends, Threats, and Cyber-Informed Engineering

This presentation discusses the rise in digital energy infrastructure and associated threats. It covers an in-depth risk assessment of digital energy equipment and provides real world examples of threats, vulnerabilities, and known incidents. Research conducted by INL assessing and addressing these risks follows, concluding with a dive into Cyber-Informed Engineering (CIE) and it's application to digital energy infrastructure, using battery energy storage systems (BESS) as an example.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

INS–Support for Formal Cyber Security Education in Brazil–After Action Report

The adoption of digital technology into Instrumentation and Control (I&C) systems in nuclear facilities fundamentally changes the nature of these systems. Greater interconnectivity of reprogrammable, and functionally interdependent control systems has given rise to the need for computer security consideration in digital I&C Systems. The cyber security of I&C systems presents a growing risk to nuclear facilities and requires the development of educational and research tools to ensure the safety of these facilities. Currently there is a major gap in formal educational offerings on cyber security for these Operational Technology (OT) systems. To provide formal cyber security education resources, DOE’s office of International Nuclear Security (INS) partnered with the University of São Paulo (USP) to develop a training course on the cyber security of nuclear facility I&C systems using the hypothetical Nuclear Power Plant, Asherah.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Personal Resiliency Index

A plethora of information exists in literature focusing on different aspects of personal resilience. There are a number of questionnaires available to measure resilience in different aspects of an individual’s life, such as mental health. However, there is a lack of comprehensive information on the subject of personal resilience to natural and man-made disasters. A Personal Resiliency Index identifying four key areas of resilience related to natural and man-made disasters will help fill this gap by providing individuals an idea of where the stand comparatively to their peers on this topics. As an increasing amount of man-made disasters, natural disasters and pandemics occur, we realize that preparation is key.?“Crisis can be experienced at individual, group and mass levels and at local, regional, national or supra-national levels.” 1? Dr. Ron Fisher, the principal investigator has over 20 years’ critical infrastructure protection including developing vulnerability assessment methodology, risk and resiliency analyses and infrastructure interdependencies. Dr. Fisher and his team will research and develop a voluntary survey which evaluates the user’s personal resilience level to natural and man-made disasters. The research team is focusing on 4 main categories:? financial resilience, cyber security, physical and mental health, and emergency preparedness.?The web based application will?provide a resilience score for each of the categories and also a comprehensive personal resiliency score based on the voluntary survey. The application will also provide feedback to the user on actions to take to become more resilient to natural and man-made disasters. Through this effort, we will also be able to identify the areas where participants are excelling as well as opportunities for improvement in terms of resilience. This information will provide insight into areas of further investigation and identify potential areas of support needed for the general public to adopt strategies to become more resilient. 1 Lynott, William. “Surviving a Natural (or Man-Made) Disaster: How to Prepare for and Bounce Back? from a Crisis in Your Business | 2018-02-01 | NOLN.” Home Page, NOLN, 1 Feb. 2018, https://www.noln.net/articles/2683-surviving-a-natural-or-man-made-disaster-how-to-prepare-for-and-bounce-back-from-a-crisis-in-your-business.

99 GENERAL AND MISCELLANEOUS↗

IBR Digital Supply Chain Gap Analysis and Recommendations

The adoption of clean energy technologies, including solar photovoltaics, continues to introduce non-traditional stakeholders to the operations and planning of the electric system. Stakeholders such as manufacturers, vendors, owners, aggregators, and others are enabling the adoption, integration, and optimum operations of solar technologies at accelerated rates. Inverters form the foundation of many digitally controlled energy sources for clean energy technologies, including Solar, Battery Energy Storage Systems, Hybrid Systems, and Hydrogen Fuel Cells. Their supply chain is complex, a series of microchips, electronic switches and other components making up its primary functions. The complexity of this space and the growing digitization associated with these components can create supply chain cyber risks. One measure to mitigate cybersecurity attacks is proper digital supply chain security. The U.S. Department of Energy (DOE) Solar Energy Technologies Office (SETO), in partnership with the Cybersecurity, Energy, Security, and Emergency Response (CESER) office, is hosting a workshop to bring together solar vendors and services providers to discuss digital supply chain security for solar systems and challenges and opportunities in the transitioning to a fully domestic supply chain for solar energy in the U.S. This workshop will support the Securing Solar for the Grid (S2G) and Energy Cyber Sense program activities. During the workshop, industry experts and researchers from DOE National Laboratories will discuss the current solar supply chain landscape and the transition to domestic manufacturing of solar components in the U.S. Tools and techniques to better manage and secure the digital supply chain of solar devices and systems will be discussed.

cybersecurity↗

Artificial Intelligence for Energy Systems Cybersecurity

Artificial intelligence and machine learning systems have the potential to influence the future design and implementation of cybersecurity systems for the power grid. These systems may enhance the overall operation of the power system by leveraging and making sense of massive amounts of data. However, we must also understand how AI/ML will need to be protected from cyber threat actors. We discuss the existing insights the NREL team has developed using AI/ML systems and then present resources including ESIF and the Cyber Energy Emulation Platform that can be used to generate training data and insights. We end by offering suggestions on priority research paths for AI in cybersecurity.

artificial intelligence↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Transformer Health Monitoring via Synchrophasors

Traditional transformer protection schemes such as differential protection operate once the transformer is in a critical state. Proactive means of transformer health evaluation such as Sweep Frequency Response Analysis, can only be performed periodically with the transformer out-of-service. This work presents a framework where the health and structural integrity of transformers is monitored via synchrophasors in real-time. Synchrophasors and subspace estimation techniques are used to build reduced-order models which are then analyzed across multiple domains. A diagnostics algorithm is developed and tested via Matlab simulations. Test results are promising, opening up new prospects in transformer protection research.

cyber-physical security↗