Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “CyTRICS”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

CyTRICS Impact-Based Prioritization Process

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS prioritization process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS prioritization process was premised largely upon the impact which could result to an energy sector industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. CyTRICS has termed this process the “CyTRICS Impact-based Prioritization Process.” This paper describes the factors identified for use in the Impact-based Prioritization process and identifies the rationale for inclusion. During development, three National Laboratories piloted this prioritization process and generated prioritization scores for seven systems. Following the piloting of the process, laboratory subject matter experts (SME) validated that the numerical scores generated by the prioritization process were consistent with their knowledge of the impact that may occur should any of these systems be disrupted. The following document explains how to perform the prioritization process to generate prioritization scores for energy sector systems. After outlining assumptions required to conduct the process, it describes how to identify and elicit data which can be leveraged to evaluate a system and assign numerical values for each factor. The prioritization process uses different weights on different factors; rationale for each weight is included within the paper. Additionally, the paper includes some recommendations for future enhancements to prioritization, including lessons learned from developing and piloting the process. Finally, a comprehensive appendix includes example documents to be leveraged by those looking to execute the prioritization process.

99 GENERAL AND MISCELLANEOUS↗

Cytrics Repository Of Analysis Tools And Engineering Resources

Cybersecurity Testing for Resilient Industrial Control Systems (CyTRICS) is a DOE-funded project that works with vendors to evaluate the cybersecurity of equipment used in US critical infrastructure. In the process of testing systems, CyTRICS researchers often develop custom tools. The tools in this repository were developed during multiple CyTRICS tests to assist with the testing process. They help solve problems encountered by CyTRICS researchers and address uncommon testing subjects for which limited tooling is available. They are useful to other researchers working on similar systems and architectures.

Laird, SutterE↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

CyTRICS™ Assessment Report: Whole Home Battery Applications

This report examines the software supply chain security posture of mobile applications developed for consumer whole-house battery and energy-management products. While these applications are not currently integrated with critical infrastructure, their growing role in connected energy domain spaces underscores the importance of understanding the external dependencies, permission structures, and runtime behaviors that could introduce systemic risk; particularly, if adoption expands into more critical environments.

25 ENERGY STORAGE↗

Prioritizing ICS Beachhead Systems for Cyber Vulnerability Testing

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS Prioritization Process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS Prioritization Process was premised largely upon the impact which could result to an industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. The worldwide compromise of the SolarWinds Orion platform, first reported in December 2020, through malicious interference with the digital patching cycle was a watershed event in cyber supply chain security. The SolarWinds compromised demonstrated the strategic importance of certain types of ubiquitous software, and the ability to generate widespread cybersecurity effects. To address this challenge and as a part of the Department of Energy’s response to the SolarWinds compromise, DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) directed the National Laboratories to evolve the CyTRICS Prioritization Process methodology to encompass additional factors related to the strategic importance of digital components. CESER directed CyTRICS researchers to identify, characterize, and append strategic factors to the CyTRICS Prioritization Process to provide additional weight to these characteristics. National Laboratory expert researchers identified functionality, distribution, and platform characteristics for digital components in ICS and OT that they assessed would be likely targeted in strategic initial-access cyber attack. CyTRICS has termed these factors “ICS Beachhead Systems,” leveraging a definition first advanced by Schneider Electric, which is intended as a blanket term to encompass digital components, products, and systems in OT. This paper describes the ICS Beachhead Systems identified and the rationale for inclusion. As a next step in the research and refinement process, the National Laboratories will validate this initial set of characteristics against digital components evaluated by the CyTRICS program and current implementation of the CyTRICS Prioritization Process. After validation, CyTRICS researchers will then develop a scoring methodology to generate a quantitative score to assess the degree to which a digital component is characterized as an ICS Beachhead System. Finally, the National Laboratories will append this scoring to the existing CyTRICS Prioritization Process algorithm.

97 MATHEMATICS AND COMPUTING↗

SLIA Reference Architecture Models

The SLIA Reference Architecture Models project, sponsored by the DOE CESER Energy CyberSense Program (Oct 2024–Sep 2025), advanced LLNL’s PySCES simulation tool to better support CyTRICS Prioritization and Initial Risk Assessment (PIRA) reference architectures. Key achievements include enhancements to the PySCES transmission substation facility model, expanded asset coverage, and enhancements to the PySCES code base. Software improvements reduced code complexity, migrated PySCES to Python version 3.11, introduced an object-oriented design, and added a schema database for easier updates and validation. New features support device criticality assessments and a more precise parametric simulation mode. Remaining gaps include model validation, workflow limitations, Monte Carlo convergence issues, full device criticality metric implementation, model fidelity, and general software improvements. Continued development is recommended to address these gaps and fully align PySCES with CyTRICS PIRA requirements.

97 MATHEMATICS AND COMPUTING↗

Idaho National Laboratory Energy Cybersecurity Programs Update

This brief presentation provides a status update on three Idaho National Laboratory energy cybersecurity programs of particular interest to NERC Reliability and Security Technical Committee annual in-person Security Groups summit. Public information on the following three programs is included: Cybersecurity for Operational Technology Environments (CyOTE™) program Cyber-Informed Engineering (CIE) Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, and associated high-level information on the Energy Software Bill of Materials POC, Executive Order 14017, and the Energy Cyber Sense Act

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Managing Cyber Supply Chain Risk for Renewable Energy Technologies

On July 1, 2021, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) hosted a virtual workshop facilitated by the National Renewable Energy Laboratory (NREL). Cybersecurity supply chain experts, researchers, and leaders in government and industry came together to share information on current and future challenges in securing emerging technologies and technical architecture. From a cybersecurity perspective, we need to move from a cybersecurity approach that focuses principally on legacy asset owners to one that incorporates more emphasis on end-point device manufacturers and third-party integrators. Cybersecurity for the global digital supply chain for manufacturers of consumer end-point devices—such as smart solar inverters and smart electric vehicle (EV) chargers—will be critical to the future cyber health of the grid.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗