Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Consequence-Driven Cyber-Informed Engineering”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

Signal Decomposition for Intrusion Detection in Reliability Assessment in Cyber Resilience (Summary Report)

The complexity of assuring cyber resilience for physical process interactions in connected systems such as energy grids increases dramatically as the coupling between processes becomes more direct and responsive. An example of this growing complexity is provided by Integrated Energy Systems (IES), in which various processes such as nuclear heat generation and commodity production are being directly coupled for increased responsiveness to highly variable signals such as market pricing or electricity demand. As such, the potential attack surface of the coupled processes is larger than the two processes independently. Securing these complex systems requires two-fold monitoring: cybersecure monitoring for potential malicious incursion, and physics monitoring for system tampering. Physics monitoring includes analyzing the behavior of the signals within the system for anomalous behavior. This analysis has been shown to be insufficient if approached by only data-driven machine learning and artificial intelligence (MLAI) techniques or only low-level model comparison. Previous efforts at Purdue University suggested combining high-fidelity models with MLAI algorithms as a basis for a software tool for detecting anomalies in physical processes. This work built on that suggestion, developing an advanced library for signal decomposition and analysis using both MLAI and high-fidelity physics algorithms for greatly improved anomaly detection, especially false data injection. This software can be used as part of a secure imbedded intelligence (SEI) system designed under Consequence-driven Cyber-informed Engineering (CCE) for complex coupled systems. This library established a foundation for online and posteriori analysis of digital signals for the purpose of detecting potential malicious tampering in digital signals representing physical processes. Demonstrations carried out throughout the development highlight the effective use of characterization algorithms to detect signal perturbations, particularly triangle attack-style perturbations, in three wide-ranging applications: seismic monitoring, nuclear thermal hydraulics system simulation, and custom manufacturing.

97 MATHEMATICS AND COMPUTING↗

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS↗

Function-based Taxonomy Implementation

Function-based taxonomies are relational mapping tools used to clearly illustrate how an organization delivers Critical Functions by using various people, processes, technologies, information, and infrastructure (PPTII). Critical Functions are the actions or activities that make up the organization’s primary purpose. Enabling Functions are the combination of PPTII used by the organization to deliver their Critical Functions. A function-based taxonomy provides a framework to categorize information and related artifacts that document an organization’s unique implementation of PPTII for Critical Function delivery. The ideal state of a function-based taxonomy is to organize the existing knowledge the organization already has throughout their numerous systems, policies, people, procedures, and configurations. A well-organized taxonomy helps organizations to effectively leverage their knowledge by clearly identifying dependencies and connections. This document is the result of combined engineering and analytical experience and describes a repeatable method for producing function-based taxonomies.

42 ENGINEERING↗

Cyber-Informed Engineering Implementation Guide

This Implementation Guide describes the principles of Cyber-Informed Engineering (CIE) and outlines questions that engineering teams should consider during each phase of a system’s lifecycle to effectively employ these principles. It describes what it means to engineer systems in a cyber-informed way, rather than offering a comprehensive, step-by-step process or procedure for CIE implementation. This guide complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Engineers and technicians that design critical energy infrastructure installations can use this Implementation Guide to integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. The guide is aimed at system or design engineers, rather than software engineers or operational cybersecurity practitioners. The engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. CIE expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences.

42 ENGINEERING↗

CRITICAL FUNCTION ASSURANCE: Understanding Critical Function and Critical Function Delivery is Foundational for Meaningful ICS Security Improvement and Policy Efforts

Modern life is enabled by a complex and interdependent web of critical functions, including energy, communications, transportation, food, and water. Automation has significantly reduced or replaced human interactions in the delivery of these functions, resulting in a web of goods and services that are made available 24/7 only through unique and intentional deployments of microprocessors, software, and firmware technologies. The prospect of cyber-enabled sabotage of these processes disrupts traditional risk determination models. Critical Function Assurance (CFA) is a foundational approach to identifying, prioritizing, and mitigating the risk that is inherent in the delivery of critical functions that depend on digital technology. It provides rapid focus to what matters most and illuminates elements and areas of risk that otherwise are often overlooked. This focus enables effective application of available security resources and optimizes security strategy and policy efforts. This paper introduces CFA to decision makers and risk executives (including CEOs, COOs, CFOs, and CISOs) whose organizations support and deliver the critical functions that underpin national defense, societal health and safety, and a vibrant economy.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Defense Technical Assistance - Infographic 4/24/25

Defense Technical Assistance (TA) Infographic designed to inform potential pilot partnerships with military installation about the TA opportunities available. - Secure and reliable energy is crucial for the operational readiness and resilience of military installations. The Department of Energy’s Grid Deployment Office has funded a new initiative at Idaho National Laboratory to conduct technical, on-site assessments that aim to secure the power infrastructure of military bases reliant on civilian utilities for their operations, both CONUS and OCONUS. Including how the assessments work and INL capabilities, partnership model as well as outcomes.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

The evolution of the Human Systems and Simulation Laboratory in nuclear power research

The events at Three Mile Island in the United States brought about fundamental changes in the ways that simulation would be used in nuclear operations. The need for research simulators was identified to scientifically study human-centered risk and make recommendations for process control system designs. This paper documents the human factors research conducted at the Human Systems and Simulation Laboratory (HSSL) since its inception in 2010 at Idaho National Laboratory. The facility’s primary purposes are to provide support to utilities for system upgrades and to validate modernized control room concepts. In the last decade, however, as nuclear industry needs have evolved, so too have the purposes of the HSSL. Thus, beyond control room modernization, human factors researchers have evaluated the security of nuclear infrastructure from cyber adversaries and evaluated human-in-the-loop simulations for joint operations with an integrated hydrogen generation plant. Lastly, our review presents research using human reliability analysis techniques with data collected from HSSL-based studies and concludes with potential future directions for the HSSL, including severe accident management and advanced control room technologies.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

The Energy Transition: Advanced Nuclear Needed but Address Climate Vulnerabilities Now

The term “Energy Transition” is an attempt to capture an elaborate set of activities related to the modernization and decarbonization of energy grids. Performed concurrently and often in an ad hoc manner across local, state, regional and national boundaries, it is bringing chaos to what should arguably be one of the most conservatively managed of all critical infrastructure sectors. What’s more, with climate change producing an increasing tempo of extreme events, confidence in the intended resilient and redundant structure of the electric grids is likely to ebb. Even without these climate induced stressors, the nation’s electric grid was built for an earlier century. In addition to a drive towards greater efficiency via digitization and a continuing price decline in distributed energy resources (DERs), one could argue that climate change concerns are the primary driver of the energy transition. Non-CO2 emitting generation sources like wind and solar have become an important part of the overall generation fleet, albeit ones that cannot be counted upon to provide dispatchable power. Current projections indicate deployment of even larger percentages of DERs in coming years. Until far better storage capabilities arrive, the variability of wind and solar, inconsistent performance of traditional thermal generation plants, and energy delivery failures associated with natural gas pipelines will reinforce mounting reliability concerns. This pertains to both electric transmission and distribution. The recent shuttering of nuclear power plants in Germany, Japan, the US and elsewhere are also putting more downward pressure on dispatchable generation. Russia’s attack on Ukraine has roiled energy markets worldwide and forced some countries to return to coal as a primary fuel. In view circumstances such as these, it is essential that significant changes be made to policies and planning criteria, and to the standards and code on which they are based. Given the accelerating pace of extreme weather events, this needs to occur as soon as possible.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Engineering-In Cybersecurity

Cyber-Informed Engineering is a framework which allows engineers to build resiliency to the impacts of cyber attack into engineered systems starting in the early design phases. This article introduces the framework and provides a description of some of its principles and resources for learning more.

42 ENGINEERING↗

Cyber-Informed Engineering

Briefings provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.

42 ENGINEERING↗

Applying Cyber-Informed Engineering to Power System Operations

This presentation covers the interaction of the discipline of system operations with the growing body of knowledge around Cyber-Informed Engineering (CIE). First is discussion of a number of fundamental concepts for system operators - organizational division of responsibilities, human and machine cooperation, goals, and priorities. The next section covers the reasons why CIE was developed, what it is, and the key design and operational, and organizational principles of CIE. Finally, some thoughts on how CIE can be applied to power system operations are offered, along with some examples of how an organization can approach applying CIE principles in their particular circumstances.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A National Secure-by-Design Strategy

The US National Cybersecurity Strategy published March 2, 2023 uses plain language to communicate that the US is calling for a major change in how we prioritize the security of software systems used in critical infrastructure. It acknowledges that our current approach, which is essentially, “let the buyer beware,” leaves entities who are least able to assess or defend vulnerable software responsible for the impacts of designed-in weaknesses while the makers of the technology bear no liability. The strategy recommends a security-by-design approach, recommending that software vendors be held liable to uphold a “duty of care” to consumers and for systems to be designed to “fail safely and recover quickly” . For energy infrastructure, the strategy calls out the need to implement the National Cyber-Informed Engineering Strategy to achieve higher confidence security for energy infrastructures. The Idaho National Laboratory, a pioneer in cyber-informed engineering concepts, is at the forefront of organizations educating others in industry, academia, and government on how to apply these concepts to real-world challenges. In this brief, we'll outline some of the basic principles of security-by-design and offer examples of how, in a water sector context, they're being put into successful practice.

42 ENGINEERING↗

Idaho National Laboratory Energy Cybersecurity Programs Update

This brief presentation provides a status update on three Idaho National Laboratory energy cybersecurity programs of particular interest to NERC Reliability and Security Technical Committee annual in-person Security Groups summit. Public information on the following three programs is included: Cybersecurity for Operational Technology Environments (CyOTE™) program Cyber-Informed Engineering (CIE) Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, and associated high-level information on the Energy Software Bill of Materials POC, Executive Order 14017, and the Energy Cyber Sense Act

24 POWER TRANSMISSION AND DISTRIBUTION↗

HOP and Cybersecurity: Leveraging safety and reliability experience to improve digital security culture

This presentation will introduce participants to key mental models on how to think about and understand safety and the organizational attributes that support it from three of the leading voices in the discipline – David Marx, Dr. Erik Hollnagel and Dr. Todd Conklin – and from there we ask the simple question of “how can we apply this to cybersecurity?” Opportunities, similarities, and differences from the history of accomplishment applying human and organizational performance principles to safety and reliability can be collectively leveraged to the meet the challenge of cybersecurity for OT/ICS/cyber-physical systems. This is the same intent as the "Cybersecurity Culture" principle of Cyber-Informed Engineering (CIE).

42 ENGINEERING↗

Using Cyber-Informed Engineering for Cyber Defense Workbook

This workbook was prepared for a detailed workshop in Cyber-Informed Engineering. It is designed to provide an audience of electrical cooperative engineering staff with an opportunity to practice leveraging the principles of Cyber-Informed Engineering for a hypothetical system upgrade. This workbook contains material describing the fictional project, information about Cyber-Informed Engineering, hands-on exercises, and a copy of the slides presented during the workshop. It can stand alone as a CIE resource.

42 ENGINEERING↗