Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Industrial Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Self-Supervised and Interpretable Anomaly Detection Using Network Transformers

Machine learning and deep neural networks (DNNs) have been proposed as a tool to identify anomalies in computer network communications. However, due the obfuscated nature of off-the-shelf machine learning models, their output often does not provide enough information to isolate the source of the anomaly to take corrective measures. In this article, we introduce the network transformer (NeT), a DNN model for anomaly detection that incorporates the graph structure of the communication network in order to improve interpretability. Further, the presented approach has the following advantages: first, enhanced interpretability by incorporating the graph structure of computer networks; second, provides a hierarchical set of features that enables analysis at different levels of granularity; second, self-supervised training that does not require labeled data. The NeT model was evaluated on a set of anomalous scenarios executed in a real industrial control system. The presented approach successfully identified the anomalies, the devices affected, and the specific connections causing the anomalies, providing a data-driven hierarchical approach to analyze the behavior of a cyber network.

97 MATHEMATICS AND COMPUTING↗

Detecting Hardware Trojans in PCBs Using Side Channel Loopbacks

Malicious modifications to printed circuit boards (PCBs) are known as hardware Trojans. These may arise when malafide third parties alter PCBs premanufacturing or postmanufacturing and are a concern in safety-critical applications, such as industrial control systems. In this research, we examine how data-driven detection can be utilized to detect such Trojans at run-time. We develop a flexible and reconfigurable PCB test bed derived from the popular open-source programmable logic controller (PLC) platform “OpenPLC.” We then develop a Trojan detection framework, which utilizes and analyzes multimodal side channels (e.g., timing, magnetic signals, power, and hardware performance counters). We consider defender-configurable input/output (I/O) loopback test, comparison with design-document baselines, and magnetometer-aided monitoring of system behavior under defender-chosen excitations. Our approach can extend to golden-free environments. Golden (known-good) versions of the PCBs are assumed not available, but design information, datasheets, and component-level data are available. We demonstrate the efficacy of our approach on a range of Trojans instantiated in the test bed.

42 ENGINEERING↗

Mitigation of External Exposure of Energy Delivery System (MEEDS).

MEEDS is a cybersecurity solution that empowers under resourced owners and operators of critical energy infrastructure to rapidly identify and detect the publicly exposed and vulnerable operational technology (OT) and other critical Industrial Control and Energy Delivery Systems.

Mylrea, Michael↗

Cytrics Repository Of Analysis Tools And Engineering Resources

Cybersecurity Testing for Resilient Industrial Control Systems (CyTRICS) is a DOE-funded project that works with vendors to evaluate the cybersecurity of equipment used in US critical infrastructure. In the process of testing systems, CyTRICS researchers often develop custom tools. The tools in this repository were developed during multiple CyTRICS tests to assist with the testing process. They help solve problems encountered by CyTRICS researchers and address uncommon testing subjects for which limited tooling is available. They are useful to other researchers working on similar systems and architectures.

Laird, SutterE↗

AdCyDER Attack Simulator

SF-25-117 A framework for simulating various cyber attacks on industrial control systems and SCADA environments.

Blakely, Benjamin↗

Cyote-attack Chain Estimator

Attack Chain Estimator (ACE) Application Overview The Attack Chain Estimator (ACE) Application is a sophisticated tool designed for the ingestion, classification, sequencing, and enrichment of cybersecurity threat reports. This application leverages advanced machine learning models and extensive historical data to provide comprehensive insights into cyber threats, specifically targeting Industrial Control Systems (ICS). Purpose The primary functions of the ACE Application include: Ingestion of Cybersecurity Threat Reporting: Capable of ingesting text-based threat reports in markdown or text file format. Supports ingestion of structured data from other sources in STIX/JSON format. Classification of Report’s Text-Based Events: Utilizes a DeBERTa classifier, specifically trained on cybersecurity data, to map the events to MITRE ATT&CK for ICS Tactics and Techniques. Classification is performed using multiple Jupyter notebooks and machine learning workflows hosted as FastAPI microservices: regex_data deberta_base_35_train_hft_classifier_mlflow.ipynb hft_regex_classifier_mlflow.ipynb param_train_hft_classifier_mlflow.ipynb regex_tactic_tech.ipynb Ordering of Tactics, Techniques, and Observable Events: Sequences the identified tactics, techniques, and events to form a coherent attack chain. Enrichment with Historical Attack Chain Details: Enhances the attack chain with details from historical attacks using a Markov model developed from CyOTE Precursor Analysis Report data. The Markov model is available as a FastAPI endpoint for seamless integration. Enrichment with Adversary Emulation Capabilities Data: Integrates adversary emulation capabilities data using MITRE Caldera for OT adversary abilities UUIDs. Export of Output Files: Provides options to export the enriched attack chain in JSON or CSV formats. Routing of Output to Other Applications: Facilitates routing of output to various platforms and applications, including: Threat Intelligence Platforms COREII Scout for Threat Intelligence Analysis COREII Modeling and Simulation for Adversary Emulation Technical Description The ACE Application is an advanced cybersecurity tool designed to provide detailed threat analysis and sequence generation. It is built on a robust architecture that integrates natural language processing, machine learning, and historical data modeling. Key Components: Data Ingestion Module: Handles the input of threat reports and data from various formats, ensuring flexibility in data sources. Classification Engine: Employs DeBERTa-based classifiers hosted as FastAPI microservices to analyze and classify threat report events in accordance with the MITRE ATT&CK framework for ICS. Sequence Generator: Orders the classified events into a logical attack chain, providing clear insight into the sequence of tactics and techniques used in the threat. Enrichment Engine: Integrates historical data and adversary emulation capabilities to enhance the attack chain with valuable context and additional details. The historical data enrichment is powered by a Markov model, which is available as a FastAPI endpoint. Export and Routing Module: Facilitates the export of the enriched attack chain in multiple formats and routes the output to designated applications for further analysis or emulation.

Paul, Tony [Idaho National Laboratory (INL), Idaho↗

Understanding the Drivers of Atlantic Multidecadal Variability using a Stochastic Model Hierarchy

The relative importance of ocean and atmospheric dynamics in generating Atlantic Multidecadal Variability (AMV) remains an open question. Comparisons between climate models with SLAB and fully-dynamic (FULL) ocean components are often used to explore this question, but cannot reveal how individual ocean processes generate these differences. We build a hierarchy of physically interpretable stochastic models to investigate the contribution of two upper-ocean processes to AMV: the role of seasonal variation and mixed-layer entrainment. This interpretability arises from the stochastic model’s simplified representation of sea surface temperature (SST), considering only the local upper ocean response to white-noise atmospheric forcing and its impact on surface heat exchange. We focus on understanding differences between SLAB and FULL non-eddy resolving pre-industrial control simulations of the Community Earth System Model 1 (CESM), and estimate the stochastic model parameters from each respective simulation. Despite its simplicity, the stochastic model reproduces temporal characteristics of SST variability in the SPG, including reemergence, seasonal-to-interannual persistence and power spectra. Furthermore, unrealistically persistent SST of the CESM-SLAB ocean simulation is reproduced in the equivalent stochastic model configuration where the mixed-layer depth (MLD) is constant. The stochastic model also reveals that vertical entrainment primarily damps SST variability, thus explaining why SLAB exhibits larger SST variance than FULL. Here, the stochastic model driven by temporally stochastic, spatially coherent forcing patterns reproduces the canonical AMV pattern. However, the amplitude of low-frequency variability remains underestimated, suggesting a role for ocean dynamics beyond entrainment.

54 ENVIRONMENTAL SCIENCES↗

Digital Biosecurity Pilot Project

Security models for the bioeconomy have largely been developed on risk profiles borrowed from the financial industry and, in some cases, industrial control systems. The bioeconomy, however, has unique characteristics that require domain-specific knowledge of the risks to environmental, health and economic impact from directly targeted attacks. Key questions need to be assessed and answered for any facility engaged in bioproduction. These include: how much technical information must the attacker possess in order to target a specific process or facility? Which processes cause the largest economic impact if disrupted? Can an attacker lead companies down the wrong path of research, leading to irrecoverable losses of time, resources and capital? Can attackers disrupt venture capital strategies and affect financial returns? What are the resources required to attack key workflows, and subsequently what is the cost of defense? What strategies are effective against such attackers, and what are their cost? Can government provide an active role in assurance of material, process and results for critical bioeconomic infrastructure?

59 BASIC BIOLOGICAL SCIENCES↗

RAMSeS: Rapid Analysis of Mission Software Systems

Over the past few decades, software has become ubiquitous as it has been integrated into nearly every aspect of society, including household appliances, consumer electronics, industrial control systems, public utilities, government operations, and military systems. Consequently, many critical national security questions can no longer be answered convincingly without understanding software, including its purpose, its capabilities, its flaws, its communication, or how it processes and stores data. As software continues to become larger, more complex, and more widespread, our ability to answer important mission questions and reason about software in a timely way is falling behind. Today, to achieve such understanding of third-party software, we rely predominantly on the ability of reverse engineering experts to manually answer each particular mission question for every software system of interest. This approach often requires heroic human effort that nevertheless fails to meet current mission needs and will never scale to meet future needs. The result is an emerging crisis: a massive and expanding gap between the national security need to answer mission questions about software and our ability to do so. Sandia National Laboratories has established the Rapid Analysis of Mission Software Systems (RAMSeS) effort, a collaborative long-term effort aimed at dramatically improving our nation’s ability to answer mission questions about third-party software by growing an ecosystem of tools that augment the human reverse engineer through automation, interoperability, and reuse. Focusing on static analysis of binary programs, we are attempting to identify reusable software analysis components that advance our ability to reason about software, to automate useful aspects of the software analysis process, and to integrate new methodologies and capabilities into a working ecosystem of tools and experts. We aim to integrate existing tools where possible, adapt tools when modest modifications will enable them to interoperate, and implement missing capability when necessary. Although we do hope to automate a growing set of analysis tasks, we will approach this goal incrementally by assisting the human in an ever-widening range of tasks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

First Report of the Nuclear Data Subcommittee of the Nuclear Science Advisory Committee

Accurate, reliable nuclear data is essential for the success of Federal missions such as nonproliferation, nuclear forensics, homeland security, national defense, space exploration, clean energy generation, and scientific research. Data access is also key to innovative commercial developments such as new medicines, automated industrial controls, energy exploration, energy security, nuclear reactor design, and isotope production. The United States Nuclear Data Program (USNDP) is the domestic custodian of nuclear data. In its April 2022 meeting, the DOE/NSF Nuclear Science Advisory Committee was charged with preparing two reports on nuclear data. In this first report, we review recent accomplishments of the USNDP and discuss complementary and collaborative international efforts. Detailed descriptions of nuclear data needs for basic science, nonproliferation, national security, nuclear energy together with medical and space applications are also presented. Lastly, a set of specific cross-cutting nuclear data needs with relevance for multiple applications areas are also identified for further discussion in a follow-on report planned for release at the end of January 2023.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Toward a Resilient Cybersecure Hydropower Fleet: Cybersecurity Landscape and Roadmap 2021

With this roadmap, Pacific Northwest National Laboratory (PNNL) hopes to assist the U.S. Department of Energy’s (DOE’s) Water Power Technologies Office (WPTO) in improving the cybersecurity of hydropower plants across the nation. This effort draws upon collected data from the dams sector, from industrial control system cybersecurity threat reports, from similar work focused on neighboring sectors, and from frank discussions with owners, operators, and vendors. While remaining tightly focused on the needs of hydropower projects, during this landscape study and development of the resulting roadmap, the research team sought to remain informed by the larger energy sector’s vision and direction so that the topics and milestones may fit within a larger vision common to the whole.

13 HYDRO ENERGY↗

Cyber-CHAMP White Paper

Cyber-CHAMP white paper intern school assignment. Worldwide there is a tremendous shortfall in the cybersecurity workforce. By 2021, researchers have forecasted a deficit of 3.5 million cyber professionals. As workforce capabilities diminished, the world's cybersecurity threats have continued to multiply. Industrial control systems (ICSs) and their operational technology (OT) components became more vulnerable to attack and compromise. When an ICS is compromised, attackers can cause widespread impacts on national security, public health, and safety. This capacity makes ICSs attractive targets, with 90% of surveyed OT organizations reporting a damaging cyberattack in the last two years. To address the risk to ICSs, personnel must be competent in operational best practices and the latest threats. While frameworks for information technology (IT) cybersecurity education have been developed, educational standards for OT cybersecurity are nonexistent.

97 MATHEMATICS AND COMPUTING↗

Advanced Reactor Cyber Analysis and Development Environment (ARCADE) for System-Level Design Analysis

Cybersecurity is a persistent concern to the safety and security of Nuclear Power Plants (NPPs), but has lacked data-driven, evidence-based research. Rigorous cybersecurity analysis is critical for the licensing of advanced reactors using a performance-based approach. One tool that enables cybersecurity analysis is modeling and simulation. The nuclear industry makes extensive use of modeling and simulation throughout the decision process but lacks a method to incorporate cybersecurity analysis with existing models. To meet this need, the Advanced Reactor Cyber Analysis and Development Environment (ARCADE) was developed. ARCADE is a suite of publicly available tools that can be used to develop emulations of industrial control system devices and networks and integrate those emulations with physics simulators. This integration of cyber emulations and physics models enables rigorous cyber-physical analysis of cyber-attacks on NPP systems. This report provides an overview of key considerations for using ARCADE with existing physics models and demonstrates ARCADE’s capabilities for cybersecurity analysis. Using a model of the Small Modular Advanced High Temperature Reactor (SmAHTR), ARCADE was able to determine the sensitivity of the primary heat exchangers (PHX) to coordinated cyber-attacks. The analysis determined that while the PHX’s failures cause disruption to the reactor, they did not cause any safety limits to be exceeded because of the plant design, including passive safety features. Further development of ARCADE will enable rigorous, repeatable, and automated cyber-physical analysis of advanced reactor control systems. These efforts will also help reduce regulatory uncertainty by presenting similar types of cybersecurity analyses in a common format, driving standard approaches and reporting.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

National Security Programs - Cyber: MMAREJBLIGE – Modular Multi Agent Grid Emulation for Joined Breakdowns in Linked Generative Emulations - 23-0644

Modular Multi Agent Grid Emulations for Joined Breakdowns in Linked Generative Emulations (MMAREJBLIGE) introduces an agent-based modeling framework into real-time cyber-physical emulation to achieve a context-aware environment that introduces operator/attacker/external-condition variability to improve emulation fidelity and testing rigor. We detail our agent framework design, internal communication via message passing, and time synchronization, as well as the individual components of the system. We include a brief analysis of several scenarios run on a real-time, hardware-in-the-loop, Industrial Control Systems (ICS) test-bed which include normal operation, physical disruption, disruption with mitigation, and disruption with mitigation during a cyber denial-of-service (DOS) attack.

42 ENGINEERING↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Reactor System Facility Modification to Detect Compromised Human Machine Interfaces

This study focuses on a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture to aid in the discovery and mitigation of compromised Human Machine Interface (HMI)/Instrumentation & Control (I&C) based systems for modifying a prototypical reactor condition test facility called the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). This is achieved through a three-layered combination of network security solutions, hash-based algorithms, and blockchain technologies. Hash algorithms are mathematical functions used to generate a predetermined set of fixed-length values. They are widely used in computer security to verify the integrity of system information and data, both on a local network and the wider internet. Even small amounts of unauthorized system modification will cause the hash algorithm to output a set of characters that deviate significantly from its original value. Assisting secure hash functions, blockchain technology is a secure and distributed technology used to provide an immutable set of records replicated on all devices within a decentralized network. Blockchain offers a cost-effective solution to detect system compromise by providing a traceable breadcrumb trail of all network activity and data modification happening on a system. If both are used in conjunction with network monitoring tools, the integration of this three-pronged approach can become an asset in detecting suspected system compromises before any real damage can occur.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

5G integrated edge computing platform for efficient component monitoring in coal-fired power plants

This project developed a cutting-edge 5G-integrated edge computing framework to enhance operational efficiency and reliability in coal-fired power plants through real-time component monitoring and anomaly detection. The initiative focused on leveraging distributed machine learning, federated learning, and 5G-based dynamic network slicing to support scalable, fault-tolerant monitoring environments to meet the operational requirements in industrial control systems. With a Distributed Edge Computing Service (DECS) orchestration, this project enabled federated learning at edge for condition monitoring and introduced adaptive client selection strategies to minimize communication overhead. Scalable distributed training was achieved using the Horovod framework, thus enhancing performance across edge nodes. In the realm of 5G networking, the project designed and deployed reconfigurable, QoS-aware network slicing tailored for operational technology (OT) environments, integrating software-defined networks to bolster cyber-resilience and enabling dynamic slicing for federated learning workloads. A significant milestone was the development of a virtualized ICS environment with 5G core integration—which allowed elastic and fault tolerant distributed training on real-world datasets such as NASA Bearings, Hydraulic Systems, and TEP. To broaden the impact of the project, a TRL-3 virtualized ICS testbed for research and education was designed. This project engaged several graduate and undergraduate students to conduct research on the cutting-edge technology, and it resulted in one PhD dissertation, one MS thesis, and over 14 peer-reviewed publications. With the support of this project students also participated in national cybersecurity competitions to improve their professional development skills.

20 FOSSIL-FUELED POWER PLANTS↗

Catalysis Driven by Confined Hot Carriers at the Liquid/Metal/Zeolite Interface

In chemical industry controlling the activity and selectivity of a chemical conversion process is of immense importance. Traditionally, dissipation of thermal energy drives transformation of reactants, which may lead to formation of a variety of products; it remains a key challenge to design a process that dissociation and formation of specific chemical bonds can be triggered to form certain desirable products with very high selectivity, preferably at low temperatures. Introduction of light-sensitive solid materials into catalysis provides a powerful, alternate strategy for this purpose.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗