Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Integration of Wireless Sensor Networks and Battery-free RFID for Advanced Reactors

To address an important need for Nuclear Power Plants (NPPs) to significantly reduce the amount of the required cables for sensor data communications, this Phase I SBIR effort successfully developed and demonstrated a novel low-cost proof-of-concept prototype of a secure wireless sensor network backbone communications system. This system combines commercially available low power, low cost XBEE wireless communications network and passive (battery-free) Radio Frequency Identification (RFID) systems to report individual sensor data and their location through the containment wall for rapid response to anomalies in nuclear facilities. This WIreless Sensing and Locating (WISLO) system network architecture allows non-intrusive wireless collection of sensor data with the sensor’s accurate location information from inside of the instrumentation or containment area with minimal need for power sources. The multi-node sensor data in the containment area is wirelessly transmitted to outside through the metal reinforced concrete walls without the need for any batteries. The WISLO system could be readily used in current reactor fleet and future advanced reactors, as well as in small modular reactors (SMR). The WISLO system is the first dual frequency battery-free trough the wall communications backbone system developed specifically for use in nuclear power plants. It not only can modernize the sensor monitoring practices in the existing reactor fleet, but also offers a secure, low-cost solution to advanced reactors and SMRs by removing cables and issues related to them such as cable integrity, reporting delays, and installation and maintenance costs. The intent is to improve process safety, reliability, efficiency, and cost effectiveness to the monitoring and maintenance process in current and future plants. As we address the next productization and manufacturing capabilities in the next phase, this system will serve the needs of many commercial and government applications in remote monitoring of sensor data that demand battery-free transmission of sensor data such as Internet-of-Things (IOT).

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Enhancing Network Anomaly Detection Using Graph Neural Networks

In the world of Internet of Things (IoT) networks, where devices are constantly communicating, keeping them secure from cyber threats is critical. This paper introduces a novel approach to detecting unusual and potentially harmful activities in these networks using graph neural networks (GNNs). We combine two specific types of GNNs-GraphSAGE and graph attention networks (GAT)-to create a model that understands and represents the behaviors and interactions in a network. GraphSAGE creates an embedding of network activities by examining local data interactions, while GAT directs the model's focus to the most critical interactions. By integrating these two methods in a single model that considers different types of interactions (both host and flow nodes), we aim to create a system that accurately represents the current state of a network and can also spot anomalies effectively while reducing false positives and negatives. Our innovative approach has demonstrated promising results, achieving an accuracy of 98% on the UNSW-NB15 dataset, significantly outperforming standalone GraphSAGE and GAT models. This underscores its potential as a robust framework for securing IoT networks against cyber threats and anomalies.

Marfo, William↗

FEST: Facility Energy Saving and Securing Technology Using Multi-Source Data: (Milestone 2 Report)

This project aims to demonstrate three technologies developed in-house at LLNL and University of Michigan-Dearborn (UMD), at a military site, including i) Grid Data Crossing (called GriD-Xing) for increasing smart meter data usability, ii) Facility Energy Optimization (called Facility E-GO) for improving facility energy efficiency in both operation and planning perspectives, and iii) Co-simulation tool (called Co-Sim) for enhancing smart meter and energy facility networks resilience and security. In this report, Millstone 2 - Integration A: Integrate GriD-Xing and facility optimization tools is documented.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Opdefender Network Monitoring And Control System

OpDefender is a new system designed to enhance the cyber security of control system networks. It accomplishes this by inspecting each network packet using a novel, patent-pending method that extends software defined networking into the application/ICS protocol layer. OpDefender consists of two key components: 1. Smart, “ICS-aware” network switches that analyze and filter network traffic in real time. 2. A network management human machine interface (HMI) that allows an operator to monitor and control network traffic in real time. The “ICS-aware” switches can serve as a drop-in replacement for typical network switches, or they can be used in conjunction with existing network switches. OpDefender is configured and controlled in real time via a custom-built, web-based HMI designed with the operator in mind.

Johnson, BriamE.↗

UAS IMPLEMENTATION CONSIDERATIONS FOR NUCLEAR SECURITY

Uncrewed aerial systems (UAS) have been an area of focus for the Office of International Nuclear Security within the US Department of Energy’s National Nuclear Security Administration and other foreign and domestic organizations for several years. This emerging technology provides significant capabilities to the nuclear security realm, but there are many things to consider when implementing them into an established security design or network. The goal of this paper is to discuss some of the benefits, challenges, and lessons learned with using UAS at nuclear facilities and during transport of material. Generic examples of UAS implementation will be used to facilitate a publicly releasable paper and presentation. The paper will start with a summary of the types and capabilities of UAS to provide a better understanding for people unfamiliar with current and new capabilities of these systems. Since there are many different types and sizes of UAS, this paper will focus on drones 55 lb and smaller. Then some of the use cases of UAS for security and challenges of employing them will be covered. Finally, lessons learned and some best practices that Oak Ridge National Laboratory has discovered from research, development, testing, and evaluation will be summarized.

Stockwell, Brandon↗

Virtualizing Industrial Control Networks for Cyber Resilience Experiments

Industrial control systems (ICS) networks are undergoing constant shifts to accommodate new security measures. It is challenging to test varying network configurations and security tools with physical systems as they typically include large, expensive equipment. Not only this, but researchers often do not have access to this type of equipment for development of new security tools and techniques. As a solution to these issues, this work presents a set of tools for utilizing GNS3 and Docker as a virtual ICS network. Additionally, the virtual network can be attached to physical devices including network switches, hardware simulations, and intelligent electronic devices (IEDs). Two case studies showcase a relatively complex automatically generated network and an attack on a simple ICS network with an example mitigation.

42 ENGINEERING↗

A Review of Cyber-Physical Security for Photovoltaic Systems

In this paper, the challenges and a future vision of the cyber-physical security of photovoltaic (PV) systems are discussed from a firmware, network, PV converter controls, and grid security perspective. The vulnerabilities of PV systems are investigated under a variety of cyber-attacks, ranging from data integrity attacks to software-based attacks. A success rate metric is designed to evaluate the impact and facilitate decision making. Model-based and data-driven methods for threat detection and mitigation are summarized. In addition, the blockchain technology that addresses cyber-attacks in software and cyber networks is described. Simulation and experimental results that show the impact of cyber-attacks at the converter (device) and grid (system) levels are presented. Finally, potential research opportunities are discussed for next-generation, cyber-secure power electronics systems. These opportunities include multi-scale controllability, self-/event-triggering control, artificial intelligence/machine learning, hot patching, and online security. As of today, this study will be one of the few comprehensive studies in this emerging and fast-growing area.

14 SOLAR ENERGY↗

Topological Analysis of Temporal Hypergraphs

In this work we study the topological properties of temporal hypergraphs. Hypergraphs provide a higher dimensional generalization of a graph that is capable of capturing multi-way connections. As such, they have become an integral part of network science. A common use of hypergraphs is to model events as hyperedges in which the event can involve many elements as nodes. This provides a more complete picture of the event in comparison to the standard dyadic connection limitation of a graph. However, a common attribution to events is temporal information as an interval for when the event occurred. Consequently, a temporal hypergraph is born which accurately captures both the temporal information of events as well as their multi-way connections. Common tools for studying these temporal hypergraphs typically use summary statistics of snapshots from a sliding window procedure to capture changes in the underlying dynamics. However, these do not provide insight into how the changing structure of the hypergraph evolves and which components of the temporal hypergraph persist and are influential to the underlying system. To alleviate this need we leverage zigzag persistence from the field of Topological Data Analysis (TDA) to study the change in topological structure of time-evolving hypergraphs. We apply our pipeline to both a cyber security and social network dataset and show how the topological structure of their temporal hypergraphs change and can be used to understand the underlying dynamics.

hypergraphs, topological data analysis, zigzag per↗

Assessing the impact of Byzantine attacks on coupled phase oscillators

Abstract For many coupled dynamical systems, the interaction is the outcome of the measurement that each unit has of the others as e.g. in modern inverter-based power grids, autonomous vehicular platoons or swarms of drones, or it is the result of physical flows. Synchronization among all the components of these systems is of primal importance to avoid failures. The overall operational state of these systems therefore crucially depends on the correct and reliable functioning of the individual elements as well as the information they transmit through the network. Here, we investigate the effect of Byzantine attacks where one unit does not behave as expected, but is controlled by an external attacker. For such attacks, we assess the impact on the global collective behavior of nonlinearly coupled phase oscillators. We relate the synchronization error induced by the input signal to the properties of the attacked node. This allows to anticipate the potential of an attacker and identify which network components to secure.

Tyloo, Melvyn (ORCID:0000000317614095)↗

Lessons Learned for Responsible Use of Cloud in the Cirrus Project, Following the CrowdStrike Outage Event

A disruption in CrowdStrike’s Falcon cybersecurity platform on July 19th, 2024, caused worldwide chaos. This event highlights the imperative need for cloud security measures for networks that are critically reliant on cloud technology. This incident negatively impacted air travel, government networks, and critical infrastructure sectors such as hospitals and financial institutions. While no electric utilities had a physical impact, and few had an IT impact, there were issues created by loss of cloud services, and other interrelated industries. For utilities and energy distribution organizations, understanding and mitigating these risks is essential. The Cirrus tool offers a strategic solution engineered to weave cloud integration seamlessly into the fabric of operational management, thereby enhancing resilience and streamlining efficiency in the face of digital challenges.

25 ENERGY STORAGE↗

Trust Model System for the Energy Grid of Things Network Communications

Network communication is crucial in the Energy Grid of Things (EGoT). Without a network connection, the energy grid becomes just a power grid where the energy resources are available to the customer uni-directionally. A mechanism to analyze and optimize the energy usage of the grid can only happen through a medium, a communications network, that enables information exchange between the grid participants and the service provider. Security implementers of EGoT network communication take extraordinary measures to ensure the safety of the energy grid, a critical infrastructure, as well as the safety and privacy of the grid participants. With the dynamic nature of network communication of the EGoT, the information provided by the customer or the service provider can be falsified by a malicious attacker. Therefore, a trust model is necessary to monitor any abnormal activities. This paper describes a distributed trust model system that meets the need of the EGoT. This paper describes methods for evaluating and improving the distributed trust model using standard hypothesis testing metrics such as true positive, false positive, true negative, false negative, equal error rate, and F1 score. Example calculations are shown based on generated sample data.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

Cross-Layered Cyber-Physical Power System State Estimation towards a Secure Grid Operation

In the Smart Grid paradigm, this critical infrastructure operation is increasingly exposed to cyber-threats due to the increased dependency on communication networks. An adversary can launch an attack on a power grid operation through False Data Injection into system measurements and/or through attacks on the communication network, such as flooding the communication channels with unnecessary data or intercepting messages. A cross-layered strategy that combines power grid data, communication grid monitoring and Machine Learning based processing is a promising solution for detecting cyberthreats. In this paper, an implementation of an integrated solution of a cross-layer framework is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection of anomalies in the operation of power grid. IEEE 118-bus system is built in Simulink to provide a power grid testing environment and communication network data is emulated using SimComponents. The performance of the framework is investigated under various FDI and communication attacks.

cyber security, network security, cyber-physical s↗

Cybersecurity Platform and Certification Framework Development for Extreme Fast Charging (XFC)-Integrated Charging Ecosystem (Final Project Report)

This report summarizes a pioneering effort in Electric Vehicle charging infrastructure ecosystem cybersecurity requirements, assessment methodologies, functional verification, as well as embodiment of the key technologies in the form of hardware and software tools being made available to the public. EPRI led a team of experts, as well as a stakeholder coalition encompassing all key actors in the EV charging infrastructure ecosystem that includes eXtreme Fast Charging (XFC) equipment (defined as 200kW or above). EV charging infrastructure in the United States is a patchwork of networks that have continued to grow organically and have been designed to serve the charging needs of the EV owners, who are their customers. In doing so, each network provider, as well as their connected entities such as the cloud Electric Vehicle Service Providers or EVSPs, utility back office, utility AMI networks, payment networks, as well as Original Equipment Manufacturer (EV manufacturer) telematics networks, have designed systems that may work well individually, but no single entity is responsible for the entire ecosystem to be secure in terms of data exchange. Furthermore, there is no uniformity in how each actor has implemented the cybersecurity requirements since no system-wide cybersecurity requirements existed prior to this project. The final project report describes the technical approach guided by the EV charging infrastructure cybersecurity working group, convened specifically for this project. The technical approach included definition of requirements at the ecosystem level, treated as a ‘system of systems’, and then passed down to individual systems (EVSE, EV, cloud EVSP, utility, and the payment networks), followed by developing the cybersecurity risk and vulnerability assessment methods, that were later applied to real-world cyber-physical systems at EPRI, ANL, and NREL laboratories, to validate both the process and the results. Finally, in a spotlight over the most vulnerable equipment, which is the EV charge station (AC or DC), the team developed a multi-layer cybersecurity implementation in the embedded domain embodied by the open-source Secure Network Interface Card (SNIC) demonstrating the various ways in which the infrastructure can be secured protecting against the identified attack surfaces. Finally, the entire process of EV infrastructure cybersecurity assessment was encapsulated in the Electric Vehicle Charging Cybersecurity Management (EVC2M) online GUI-based tool, that is expected to be released to the public. The report presents the objectives, the technical approach, the key results, and recommendations for future work.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Adapting Secure MultiParty Computation to Support Machine Learning in Radio Frequency Sensor Networks

In this project we developed and validated algorithms for privacy-preserving linear regression using a new variant of Secure Multiparty Computation (MPC) we call "Hybrid MPC" (hMPC). Our variant is intended to support low-power, unreliable networks of sensors with low-communication, fault-tolerant algorithms. In hMPC we do not share training data, even via secret sharing. Thus, agents are responsible for protecting their own local data. Only the machine learning (ML) model is protected with information-theoretic security guarantees against honest-but-curious agents. There are three primary advantages to this approach: (1) after setup, hMPC supports a communication-efficient matrix multiplication primitive, (2) organizations prevented by policy or technology from sharing any of their data can participate as agents in hMPC, and (3) large numbers of low-power agents can participate in hMPC. We have also created an open-source software library named "Cicada" to support hMPC applications with fault-tolerance. The fault-tolerance is important in our applications because the agents are vulnerable to failure or capture. We have demonstrated this capability at Sandia's Autonomy New Mexico laboratory through a simple machine-learning exercise with Raspberry Pi devices capturing and classifying images while flying on four drones.

42 ENGINEERING↗

5G Zero Trust Architecture: A Testable and Phased Approach

With the emphasis being placed on Zero Trust Architecture in technology and by Executive Order (Executive Order on Improving the Nation’s Cybersecurity ), an investigation was performed as to the feasibility of implementing this approach into 5G. Reference documents include NIST Special Publication 800-207 and Department of Defense (DoD) Zero Trust Reference Architecture , and these provided guidance as to the overall approach. Progress is being made within 5G to address the lack of Zero Trust Architecture; a June 2021 DoD press release indicated that “The prototype 5G network is built on the next generation of Open Radio Network standards and designed to comply with DOD specifications for zero-trust architecture for native security and secure connectivity with other networks.”

5G↗