Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Improving the Cyber and Physical Security Posture of the Electric Sector (Final Report)

Cooperative electric utilities represent an integral part of the larger electric grid and are part of the nation’s critical infrastructure. The National Rural Electric Cooperative Association (NRECA) has a unique relationship with approximately 900 cooperatively owned and operated electric utilities and engaged in a program with the Department of Energy (DOE) to promote a culture of cybersecurity and resiliency within the electric cooperative community. The Rural Cooperative Cybersecurity Capabilities (RC3) Program, funded under a Cooperative Agreement with DOE (Project DE-OE-0000807), focused on improving the cybersecurity and resiliency capabilities of small and mid-sized electric distribution cooperatives. This segment of electric utilities faces many challenges, but also embraces a culture of cooperation that presents opportunities. A customized approach is needed to reach these utilities – one that emphasizes collaboration, more focused and personalized training, use of trusted and familiar experts that can be deployed as needed, software security services that require limited in-house cybersecurity expertise, and shared resource models that enable access to more expensive cybersecurity options.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Mississippi's Strategic Resilience: A multi-systems approach to secure, reliable, and adaptable electric grid infrastructure

Mississippi’s electric grid resilience challenges are linked to an intersection of complex socioeconomic, ecological, technological, historical, and political challenges, exacerbated by increasing severe weather like flooding and tornado events. The state’s legacy of underinvestment in critical energy infrastructure, particularly in rural areas and vulnerable floodplains, have stressed an aging grid, creating long-lasting disruptions in electric service during weather-related outages. Effective emergency management and preparedness is further hampered by a lack of coordination across local, county, and regional scales. Using the TASTI-GRID platform and partnership with Oak Ridge National Laboratory (ORNL), Mississippi is developing a comprehensive regional resilience strategy to overcome energy security and reliability challenges, mitigating the impacts of natural hazards, and positioning Mississippi as a resilient and premier destination for residents, businesses, and economic development.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Computing, Data Science, and Artificial Intelligence Research Opportunities for Energy-Focused Transportation Science

The Energy Efficient Mobility Systems (EEMS) technology landscape is complex and rapidly evolving, which provides both tremendous opportunities and formidable challenges. Significant alterations to the mobility landscape are underway due to the advent of vehicle and infrastructure connectivity, autonomous driving, and rapid passenger- and freight-vehicle electrification. Advanced computing will play an increasingly important role in enabling the EEMS program to understand and identify the most important levers to improve the energy productivity of future integrated mobility systems. It is also driving new approaches to mobility and the research to unlock an affordable, efficient, safe, and accessible transportation future. Driving much of this change is the collection, analysis, and strategic use of massive amounts of diverse, complex data from infrastructure and vehicles with on-board sensors and data storage and transmission capabilities. Diverse and representative data are key to implementing approaches to maximize mobility energy productivity. While high-fidelity modeling of integrated transportation networks has strengthened our understanding of dynamic movement and behavior patterns, existing tools must be expanded beyond their current focus. This work necessitates data infrastructure investments (e.g., secure-streaming data platforms driven by ubiquitous sensors and video analytics) as well as investments in critical capabilities for large-scale automated analysis and organization using modern machine learning, statistics, and artificial intelligence. Other chief needs include agile, large-scale storage that can be quickly searched and queried for relevant data to support validation and model development, data-sharing agreements, and formatting standards for key data types. The future of public transit must be explored in greater detail, research must inform design, and opportunities must be identified for improving the mobility productivity of public transit in both urban and rural America.

33 ADVANCED PROPULSION SYSTEMS↗

Lessons Learned for Responsible Use of Cloud in the Cirrus Project, Following the CrowdStrike Outage Event

A disruption in CrowdStrike’s Falcon cybersecurity platform on July 19th, 2024, caused worldwide chaos. This event highlights the imperative need for cloud security measures for networks that are critically reliant on cloud technology. This incident negatively impacted air travel, government networks, and critical infrastructure sectors such as hospitals and financial institutions. While no electric utilities had a physical impact, and few had an IT impact, there were issues created by loss of cloud services, and other interrelated industries. For utilities and energy distribution organizations, understanding and mitigating these risks is essential. The Cirrus tool offers a strategic solution engineered to weave cloud integration seamlessly into the fabric of operational management, thereby enhancing resilience and streamlining efficiency in the face of digital challenges.

25 ENERGY STORAGE↗

Synchrophasors-based Master State Awareness Estimator for Cybersecurity in Power Grid: Testbed Implementation & Field Demonstration

The integration of distributed energy resources(DERs) and expansion of complex network in the distribution grid requires an advanced distributed state estimator to monitor the grid health at micro-level. The distribution state estimator will improve the situational awareness and resiliency of distributed power system. This paper proposes a synchrophasors-based master state awareness (MSA) estimator to enhance the cybersecurity in distribution grid by providing a real-time estimation of system operating states to control center operators. In this paper, the proposed MSA estimator utilizes only phasor measurements, bus magnitudes and angles, from phasor measurement units (PMUs),deployed in local substations, to estimate the system states and also detects data integrity attacks, such as load tripping attack that disconnects the load. To validate the proof of concept, we implement the proposed methodology in cyber-physical testbed environment at the Idaho National Laboratory (INL) Electric Grid Security Testbed. Further, to address the “valley of death” and support technology commercialization, field demonstration is also performed at the Critical Infrastructure Test Range Complex(CITRC) at the INL. Our experimental results reveal a promising performance in detecting load tripping attack and providing an accurate situational awareness through an alert visualization dashboard in real-time

42 ENGINEERING↗

Protecting and Defending against Autonomous Control Systems and Digital Twin Cyber Attacks: Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Models in Nuclear Power Plants (Final)

Navigating through the complex tapestry of technological advancements, "Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Model in Nuclear Power Plants" stands at the intersection of cybersecurity and nuclear power plant operations, embarking on a journey through the intricacies of securing digital twins against malicious cyber activities. As nuclear power plants progressively integrate digital twin technology and machine learning models to optimize operations and ensure system reliability, they inadvertently expose themselves to a new spectrum of vulnerabilities, notably in the realm of hyperparameter attacks. Hyperparameters, integral in machine learning model tuning and optimal performance of digital twins, have emerged as a target for adversaries aiming to destabilize the predictive capabilities and therefore, the operational accuracy of these digital entities within critical infrastructures like nuclear plants. This paper, therefore, meticulously threads the needle through the development of a robust response strategy, poised to shield these digital reflections against calculated hyperparameter manipulations, ensuring that the digital twin can effectively and securely function as a reliable proxy for its physical counterpart. The ensuing sections delve into the orchestrated maelstrom of multi-rate time-changing intelligent coordinated hyperparameter attacks and the implementation of event-triggered predictive control, laying down a structured, predictive, and responsive framework that safeguards the nexus where the digital and physical realms of nuclear power plants coalesce. The operational integrity of digital twins in nuclear power plants depends critically on the security of machine learning hyperparameters. This study makes two different contributions. First, a decision-based idea known as a multi-rate time changing intelligent coordinated hyperparameter attack is put forth. In this attack, many hyperparameters are repeatedly changed using both random and intelligent optimal techniques by the attacker. These assaults introduce varied rates at different attack steps, compromise various amounts of hyperparameters, and improve stealth and flexibility. Second, a technique is developed for event triggered predictive control to rapidly respond to potential hyperparameter attacks. This control integrates a sliding window framework, retaining a history of previous data points and employing linear regression to predict the next data point from the current dataset. The control gain K is determined using the Lyapunov-Krasovskii method, and subsequently, an action is developed. Finally, the outcome of the simulation demonstrates the viability of the proposed method for defending nuclear power plant digital twins from hyperparameter attacks.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Physical Power Systems Protection: The Byzantine Cybersecurity Framework

Cybersecurity of smart grids have been topic of much interest in recent years. As this critical infrastructure operation increases dependency on automated processes and controls, exposure to cyber-physical threats become inevitable. Considering cyber-physical security of the grid, much focus of attention has been made towards smart grids real-time monitoring solutions, including the state estimation process. Analyzing the relevant literature, one can note though that seldom research has been done on cyber-physical security of smart grids protection systems. Protection systems have intangible value towards grid reliability. This paper presents a cybersecurity framework for smart grids protection systems. A physics-based inspired machine learning solution is at the core process of the framework. Processed relay inputs and outputs are used by a deep predictive coding network. Formal models, a quasi-static state estimator, provides an oracle when low confidence decision is reached. Evolving knowledge is derived through reinforcement learning. Implementation aspects considering the Pacific Northwest National Laboratory Electricity Infrastructure Operations Center are presented. Built as an extra control layer to protection systems, without hard-to-derive parameters, highlights potential aspects towards real-life applications.

Bretas, Arturo Suman↗

Evaluating software defined networking solutions to reduce the digital attack surface of nuclear security systems

Most nuclear security systems used today were not designed for today’s threat environment. Systems that were intended to be stand alone are now interconnected. Devices that have a single purpose are built on multi-purpose platforms and communication protocols that, while effective, have no ability to authenticate authorized versus unauthorized commands. These attributes provide an attacker significant ability to affect the system, pivot throughout the interconnected networks, and remain undetected if he/she is able to compromise a single node. Software defined networking (SDN) has been used for years by information technology (IT) cloud service providers to quickly provision or remove servers or other systems to meet changing demand. The same concept has recently been applied to operational technology (OT) systems to enable very fast failover on critical systems that have stringent and deterministic (<5ms) transmit/receive times. By carefully engineering the communication flows through a network using preplanned routes and specific pathways it is possible to achieve deterministic and extremely reliable message delivery even when components fail. This engineering approach to network design has added security benefits including securing the networking control plane, eliminating network scanning and mapping, inhibiting ARP spoofing and host masquerading, eliminating unauthorized network pivoting and enabling greater situational awareness on the network. SDN in OT environments is new but early testing in electrical power and other critical infrastructure has shown it to be a very powerful tool for building reliable networks and reducing the digital attack surface of the network. The authors tested a software defined network switch on a simple physical protection system with components commonly found in nuclear security systems and found improved mitigations to denial of service attacks, lateral movement and network reconnaissance. The paper details the tests and their results.

Cyber security, Nuclear security, software defined↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Assessment of the High Flux Isotope Reactor Cybersecurity Initiative

Recent cyber-attacks on industrial control systems, and inadvertent exposure of nuclear plant systems to cyber-exploits underscore the need for plant operators to adopt and deploy cyber-security defense solutions made for industrial control systems. Of increasing concern is the fact that international cyber hackers are beginning to target critical infrastructure, and because these more modern controls systems depend on advanced use of digital systems, they are more vulnerable than ever before to cyber-attacks. Traditional cyber defense strategies and products that have been available for decades are tailored for use on IT or corporate networks but can cause interruptions and catastrophic damage when deployed on industrial control system networks. The Department of Energy (DOE) Office of Nuclear Energy established the Gateway for Accelerated Innovation in Nuclear (GAIN) program to provide private companies pursuing innovative nuclear energy technologies with access to the technical support necessary to move toward commercialization. One of these GAIN small business vouchers was awarded to Dragos, Inc. to enable collaboration with Oak Ridge National Laboratory (ORNL) to evaluate the Dragos Platform on a production nuclear reactor test bed, hence laying the path for future commercial adoption. The vision was to provide a guide for industrial operators on implementing an industrial monitoring solution and to show how these solutions can be deployed without causing safety and reliability issues. This report documents the results of the collaboration between ORNL and Dragos, Inc.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Occurrences of REE and CM in volcanic ash beds associated with coals in SW Wyoming & NW Colorado

Rare earth elements (REEs) and critical minerals (CMs) are vital components in the nation’s economy, national security, and the further strengthening of our renewable energy capabilities and infrastructure. Recent work has revealed more insight into previously unknown modes of occurrence for REEs, particularly in coal seams and adjacent noncoal sediments, but many data gaps persist. Temporal relationships between coal beds and adjacent tonstiens, ash beds, or other partings are widely recognized but not fully understood. Variations in REE concentration and their direct or indirect association with coal beds are not predictable. This study presents findings from examining lateral and potentially stratigraphic variation of REE and CM occurrences in coals of late Cretaceous and Paleocene age. In this study we collected and examined samples of differing ages both core and coal mine exposures for qualitative x-ray fluorescence (XRF), and multi-element geochemistry. Preliminary XRF data indicates variable levels of light REEs in a core from the Yampa coalfield of Moffat County in northwest Colorado. An absence of similar enrichments in slightly older coals in the Adaville Formation of the Fold and Thrust belt in southwest Wyoming is described from XRF and ICP-MS evaluation. Previous work has shown an association with the Yampa Bed and REE enrichment in coals of the Upper Cretaceous Williams Fork Formation. While not common and widespread, this association suggests that leaching or reworking of the ash bed could lead to elevated REEs in the adjacent coal. We investigate differences between the two data occurringas geologic compositions and post-depositional histories. In-depth petrography and precise geochemistry should reveal data that at the very least will help improve some aspects of the geologic models of coal basins and the effect of an influx of non-coal sediments.

REE, CM, ash, volcanic ash, coal↗

Enterprise Artificial Intelligence Strategy for Los Alamos National Laboratory

In the 1984 martial arts drama film, The Karate Kid, a young Daniel LaRusso is unexpectedly placed in an adversarial environment unable to eYectively adapt to a series of new threats and limitations. Fortunately for the main character, once placed under the tutelage of a Mr. Miyagi, he finds resiliency not through the adoption of new tools, but a re-focused set of fundamentals. Much in the same way that Daniel learns waxing on and buYing oY car wax by hand has rewards for Karate, LANL is choosing the harder path of self-hosting Large Language Models (LLMs) for enterprise use instead of only relying on buying access to a hosted AI service like Azure’s OpenAI Application Programming Interface (API). We also are not willing to wait for software-as-a-service (SAAS) AI services to meet us where we need to be from a FedRAMP accreditation standpoint. Our operations regularly depend on access at CUI, UCNI, ITAR and other FIPS-199 moderate-impact data levels and hosting our own services gives us the right security and compliance posture to be useful across the broad range of our work at LANL. With the rise in threats to critical infrastructure, cloud service providers (CSPs), and supply chain attacks from both state and non-state actors, we are not placing the bet that SAAS hosted AI services will be available when we need them. Should a major event occur, we do not want our staY and operations left without a pathway for us to fix the problem and resume the use of AI tools.

42 ENGINEERING↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Strengthening Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Based Infrastructure

In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.

Huang, Peng-Hao↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

Sovereign Credit Rating Processes Adapted to Critical Infrastructure Cyber Risk Assessment

United States critical infrastructure entities are increasingly targeted by motivated and capable threat actors and must be prepared to assess and treat a diverse range of cyber risks. Consequently, this necessitates some form of analytical process to evaluate risks and inform cyber security investment decisions. A potential solution for structuring cyber risk evaluation exists within the field of sovereign credit ratings – where agencies employ mature approaches that integrate quantitative and qualitative data to produce a singular value of assessment. Adapting such approaches, we present a novel criterion and methodology for measuring and communicating the likelihood element of cyber risk. The methodology is composed of three sequential phases: a quantitative baseline organized by distinct capability frames, a bounded qualitative adjustment per frame, and a greater-bounded qualitative adjustment spanning the entire process. The process culminates in publication of a cyber capability rating that communicates a critical infrastructure entity’s ability and willingness to mitigate discontinuous function due to cyberattack.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

A Review of Edge Computing Technology and Its Applications in Power Systems

Recent advancements in network-connected devices have led to a rapid increase in the deployment of smart devices and enhanced grid connectivity, resulting in a surge in data generation and expanded deployment to the edge of systems. Classic cloud computing infrastructures are increasingly challenged by the demands for large bandwidth, low latency, fast response speed, and strong security. Therefore, edge computing has emerged as a critical technology to address these challenges, gaining widespread adoption across various sectors. This paper introduces the advent and capabilities of edge computing, reviews its state-of-the-art architectural advancements, and explores its communication techniques. A comprehensive analysis of edge computing technologies is also presented. Furthermore, this paper highlights the transformative role of edge computing in various areas, particularly emphasizing its role in power systems. It summarizes edge computing applications in power systems that are oriented from the architectures, such as power system monitoring, smart meter management, data collection and analysis, resource management, etc. Additionally, the paper discusses the future opportunities of edge computing in enhancing power system applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗