Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “intrusion detection systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Commercialization of the Transportation-Security, Tracking, and Reporting System (T-STAR)

The Transportation-Security, Tracking, and Reporting System (T-STAR) was developed by the National Nuclear Security Administration, NA-21, Office of Radiological Security (ORS) to provide a transportation security system for detection and tracking during transport of Category 1 and Category 2 radiological material. Few off-the-shelf systems for conveyance tracking offer detection of a cargo compartment breach or a removal of the cargo. Systems that do offer this capability often require permanent installation through modifying of the conveyance itself. This is not sustainable in many countries where ORS is building use, storage, and transport security capacity. The development of T-STAR has moved from fielding robust prototypes deployed in countries ranging from North America, Latin America and Central Asia to a commercially produced product that can now be deployed to provide enhanced security during transit. Each prototype deployment resulted in important lessons learned, which informed the requirements for the final commercial product. T-STAR uses both cellular and Iridium satellite modems to provide redundant communications to provide the configuration, status, and alerts to a server monitoring the shipment, which is accessible using a multilanguage browser-based user interface. A wireless security system employing using Z-wave sensors for intrusion detection located in the conveyance provide low cost but effective solution for a wide range of conveyance types. Additional capabilities include the ability to monitor a vehicles’ CANBUS (Controller Area Network) system, an ethernet port for high throughput sensor information such as video cameras, and the ability to power and use advanced external sensor payloads. These features make the T-STAR a capable and expandable security gateway that can be deployed on a variety of conveyances from box trucks to open trailers. The ability to provide tracking, monitoring, and detection provide a key component in overall best practices designed to protect shipments of radioactive material.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

Clonal Selection Based Artificial Immune System for Generalized Pattern Recognition

The last two decades has seen a rapid increase in the application of AIS (Artificial Immune Systems) modeled after the human immune system to a wide range of areas including network intrusion detection, job shop scheduling, classification, pattern recognition, and robot control. JPL (Jet Propulsion Laboratory) has developed an integrated pattern recognition/classification system called AISLE (Artificial Immune System for Learning and Exploration) based on biologically inspired models of B-cell dynamics in the immune system. When used for unsupervised or supervised classification, the method scales linearly with the number of dimensions, has performance that is relatively independent of the total size of the dataset, and has been shown to perform as well as traditional clustering methods. When used for pattern recognition, the method efficiently isolates the appropriate matches in the data set. The paper presents the underlying structure of AISLE and the results from a number of experimental studies.

pattern recognition↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Security in Full-Force

When fully developed for NASA, Vanguard Enforcer(TM) software-which emulates the activities of highly technical security system programmers, auditors, and administrators-was among the first intrusion detection programs to restrict human errors from affecting security, and to ensure the integrity of a computer's operating systems, as well as the protection of mission critical resources. Vanguard Enforcer was delivered in 1991 to Johnson Space Center and has been protecting systems and critical data there ever since. In August of 1999, NASA granted Vanguard exclusive rights to commercialize the Enforcer system for the private sector. In return, Vanguard continues to supply NASA with ongoing research, development, and support of Enforcer. The Vanguard Enforcer 4.2 is one of several surveillance technologies that make up the Vanguard Security Solutions line of products. Using a mainframe environment, Enforcer 4.2 achieves previously unattainable levels of automated security management.

Source record↗

Integrating 5G Technology for Improved Process Monitoring and Network Slicing in ICS

Industrial Control Systems (ICS) are crucial for monitoring physical processes that support essential cyber-enabled services like power generation. The use of proprietary communication and lack of effective intrusion detection mechanisms pose constraints for efficient operation. Therefore, there is a need to modernize these systems with decentralized technologies like Edge Computing and 5G. However, integrating 5G and Edge Computing into large-scale ICS networks presents implementation and performance challenges. To address these challenges, this paper proposes an integrated ICS architecture that combines 5G and Edge Computing technologies with traditional ICS protocols. The objective is to minimize implementation and operational difficulties while improving the monitoring of physical processes and enabling robust intrusion detection. The proposed architecture outlines the necessary components, services, and communication protocols required for the integration of 5G and Edge Computing.

Aguayo, Jared M.↗

Data-based and secure switched cyber–physical systems

In this work, we develop a completely model-free moving target defense framework for the detection and mitigation of sensor and/or actuator attacks in cyber–physical systems with dynamics that evolve in discrete-time. We incorporate an intrusion detection mechanism based on an approximate dynamic programming technique that learns the policies for optimal regulation and optimal tracking while simultaneously defending against actuator and sensor attacks in a model-free fashion. Switching rules are leveraged to force proactive and reactive defense mechanisms as well as, guarantee the stability of the equilibrium point. Finally, as a case study, we apply the proposed moving target defense framework to a DC–DC converter that is used in electric vehicles.

42 ENGINEERING↗

Deliberate Motion Analytics Fused Radar and Video Test Results Deployed Beyond the Perimeter Fence in a High Noise Environment

Security systems that protect the nation’s critical facilities must be capable of detecting physical intrusions in all weather conditions. Intrusion detection sensors in a perimeter with a high nuisance alarm rate (NAR) significantly undermine detection performance and degrade security system effectiveness. This research demonstrated a fused sensor system that can differentiate foliage and weather-induced nuisance alarms from those caused by intruders, providing reliable detection within a two-fence perimeter or beyond the fence. A key element of this work is the creation and application of a “deliberate motion algorithm” that fuses alarm data from radar and video analytics to create video motion detection fused radar system. The two-layer architecture of the algorithm uses machine learning, multi-hypothesis tracking, and Dynamic Bayes Nets to differentiate intruder alarms from weather induced alarms.

47 OTHER INSTRUMENTATION↗

Deliberate Motion Analytics Applied to CUAS Sensor Fusion

The Advanced Reactor Safeguards and Security (ARSS) program in the Department of Energy’s Office of Nuclear Energy (DOE-NE) seeks to identify new technology solutions for safeguards and security challenges associated with domestic deployment of advanced nuclear reactors. Research in the ARSS program is investigating alternative physical protection system (PPS) approaches that leverage new detection technologies. This report shows test results from a new form of artificial intelligence (AI) that is called deliberate motion analytics (DMA) when used to spatially and temporally fuse active radar and passive radio frequency (RF) detection that significantly improves detection of uncrewed aircraft systems (UASs). DMA is designed to filter out false positive alarms yet provide highly reliable intrusion detection at nuclear power plants (NPPs) and advanced small modular reactor (ASMR) perimeters. This form of AI is considered to be an enabling technology for security of the future and supports the ARSS investigation of alternative PPSs.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

Evaluation and Demonstration of Intrusion Detection for Spent Fuel Storage Facilities

The IAEA recommends dual containment and surveillance (C/S) systems for difficult to access or difficult to measure spent fuel storage areas. However, many storage areas have limitations that prevent traditional secondary C/S systems, such as radiation levels too high for inspectors to apply individual Tamper Indicating Devices (TID) or have physical impedances to the use of TIDs. Recent developments in C/S technology include Laser Curtain for Containment (LCCT) technology implemented at Atucha-1 power plant in Argentina. The LCCT is a new approach to perimeter-wide C/S and the IAEA has granted provisional approval for its use as one of two required C/S systems. This proposal focuses on investigating and testing new and evolving completely passive (or ultra-low power) tamper indicating systems that will provide backup C/S to the LCCT even during power outages. An investigation of Commercial Off The Shelf (COTS) technology will be conducted to identify readily available options. Optically Stimulated Luminescence (OSL) fibers will also be investigated. OSL fibers are a passive technology that can measure radiation dose by knocking an electron into a metastable state where it remains until the fiber is interrogated with light. The goal of this project would be to investigate COTS technologies that can be used in low or no power scenarios for radiation detection as well as test and evaluate OSL technology, which can operate passively in no power scenarios. Limitations for each technology will be determined and documented in an effort to determine the best technology for spent fuel storage monitoring.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Network visualization, intrusion detection, and network healing

The present disclosure is related to a cyber-security system that includes a Supervisory Control and Data Acquisition (SCADA) network monitor configured to receive a data set from a power system network, an event manager, and a mitigation system, where the SCADA network monitor includes an anomaly detector.

Rivera, Joshua Eli↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Distributed fiber optic sensing is a cutting-edge technology that has found extensive applications in the monitoring of Ensuring the safety, integrity, and operational efficiency of underground product pipelines is vital for maintaining the nation’s critical infrastructure. Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensors—were employed to measure key parameters like hoop strain, pressure, and acoustic vibrations. The underground product pipeline's outer diameter is 30 inches, the wall thickness is 1.28 inches, and the 3-foot depth. The fiber deployment strategies, and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety.

distributed fiber sensing↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensor systems were tested to measure the key parameters, such as hoop strain, pipe pressure, surrounding soil temperature, and acoustic vibrations. The underground product pipeline’s outer diameter is 30 inches, the wall thickness is 1.28 inches, and 3 feet deep from the surface. The fiber deployment strategies and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety. These findings from pilot-scale testing offer valuable insights into advancing pipeline monitoring technologies and improving the reliability of underground pipeline systems.

fiber optic sensors↗

Feature Engineering and Ensemble Methods for Imbalanced ICS Intrusion Detection: Pipeline Audit and Constrained Evaluation

Industries are becoming increasingly connected and are more vulnerable to cyberattacks due to the widened attack surface. Industrial Control Systems (ICS) are among the most critical sectors that malicious actors can target, as such attacks can cause significant operational disruption and physical damage. It is imperative to detect such attacks as early as possible. This paper evaluates constraint-conditioned optimistic performance estimates for traditional ML models in ICS intrusion detection (i.e., estimates obtained under contiguous, non-shuffled temporal evaluation without test-set alteration, but with pre-split feature engineering that may introduce temporal leakage, due to dataset constraints). Our findings are threefold. First, we quantify how iterative feature engineering affects tree-based ensemble performance and examine how pipeline decisions (split strategy, sampling scope, and cleaning policy) can inflate or reduce reported IDS results under constraint-bound evaluation. Second, we compare intrinsic class-imbalance handling across ensemble models. Third, under our current pipeline constraints (including pre-split feature engineering), CatBoost achieves the best performance on Water Storage Tank (accuracy: 0.9831, class-1 F1: 0.9682), while Light- GBM achieves the best performance on Gas Pipeline (accuracy: 0.9618, class-1 F1: 0.9086).

97 MATHEMATICS AND COMPUTING↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗

An Advanced Cyber-Physical System Security Testbed for Substation Automation

A Cyber-Physical System (CPS) testbed serves as a powerful platform for testing and validating cyber intrusion detection and mitigation strategies in substations. This study presents the design and development of a CPS testbed that can effectively assess the real-time dynamics of a substation. Cyber attacks exploiting IEC 61850-based SV and GOOSE protocols are demonstrated using the testbed, along with an analysis on attack detection. Realistic timing measurements are obtained, and the time frames for deploying detection and mitigation strategies are evaluated.

24 POWER TRANSMISSION AND DISTRIBUTION↗