Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber Research”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

An Old Guys Perspective of Cyber - Journey Through INL Cyber Research

An overview of the history of cybersecurity at INL and how it has evolved with today's Critical Infrastructure, including the advancement of Electric Vehicles (EVs) and the EV charging infrastructure. Recent and future research efforts are included to demonstrate the current state of the art and where this technology might progress. With maybe a little Fear, Uncertainty, and Doubt (FUD) mixed in...

99 GENERAL AND MISCELLANEOUS↗

Ultrasound Interim cyber-physical research evaluation

Recent events have presented Medical Practitioners with concerns about safety and privacy implications associated with GE’s VScan MIot Ultrasound Device. Concerns relate to the devices potential risk to broadcast location data that can pose serious risks to device users and patients. This report was commission in collaboration with Augusta University to determine if device concerns pose real threat to operators and patients. In effort to ensure all potential threat vectors are targeted, the initial step was to analyze the supply chain. Here the devices are CT scanned to look for any hardware anomalies that could present threat vectors to users of these devices. (See SRNL-STI-2024-00225 for detailed analysis). No anomalies were found associated with the hardware utilized within the GE VScan Air.

42 ENGINEERING↗

Understanding How Organizations Handle Cybersecurity

If there is anything we can learn from the media, it is the frequency and severity of cyber-attacks is increasing and there are not enough qualified people to combat the risk organizations are facing. Current estimates say there are 3.5 million available cybersecurity related jobs globally and there has been a 350% growth in cybersecurity jobs since 2013 (Group, 2020). The Idaho Cyber Research Project (ICRP) is focused on finding an implementing solution to the problems in the workforce development pipeline. Our team consists of Cohort 2 of the ICRP, we are tasked with solving issues faced by organizations hiring new cyber personnel. To provide solutions to these issues we focused our research on four components of workforce availability and competency: resume and transcript analysis, apprenticeships, cyber incident response plan development, and adversarial mindset training. From this research we have produced the following focus areas and subsequent steps for each component of workforce capability: transcript and knowledge skills abilities (KSA) focused analysis, cybersecurity apprenticeships programs, the value of an adversarial mindset, and a guide to setting up cyber incident response plans for underprepared organizations. These solutions can be further developed and implemented to reduce the gap in workforce demand and talent.

97 MATHEMATICS AND COMPUTING↗

Cyber Halo Innovation Research Program (CHIRP) Handbook: CHIRP Program Document 2026

The Cyber Halo Innovation Research Program (CHIRP) handbook outlines a comprehensive framework designed to advance space cybersecurity education, workforce development, recruitment efforts for United States Space Force (USSF) Space Systems Command (SSC) and the Department of the Airforce, and foster students’ professional growth. It provides an overview of CHIRP's objectives and strategic focus, establishing the foundation for participant engagement through a network of collaborations with academic institutions, contracted industry partners, training and certification organizations, federal agencies, and community organizations. It states a clear participation strategy for SSC and Pacific Northwest National Laboratory (PNNL) for program execution and successful support for student transition to a career in space cybersecurity.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Halo Innovation Research Program (CHIRP) Student Research Report: Program Analysis

The Cybersecurity and Space Systems Research Program (CHIRP) conducted multi-year, mission-focused research addressing emerging cybersecurity challenges affecting space and ground systems. Students from California State University San Bernardino (CSUSB), University of Texas El Paso (UTEP), and California State University Dominguez Hills (CSUDH) conducted structured research, developed proof-of-concept demonstrations, participated in applied cybersecurity training, and collaborated with Space Systems Command (SSC), academic, and industry partners. This report documents the research questions, methodologies, findings, demonstrations, and student contributions associated with each cohort. It also summarizes the program’s workforce-development outcomes, including applied cybersecurity training, professional certifications, technical credentials, and partnerships with organizations such as CT Cubed, Inc. and ISC2. Collectively, CHIRP strengthened the space-cybersecurity workforce pipeline and produced research and prototype efforts that may inform future cybersecurity assessments, test and evaluation activities, cyber-range development, acquisition planning, operational training, and mission-assurance initiatives.

McKenzie, Penny L.↗

Situational Awareness of Grid Anomalies (SAGA)

The modern power industry becomes more vulnerable to cyber events due to the growing interconnectivity, interdependence, and complexity of the electric power grid. High-fidelity modeling and simulation tools that support the preventative risk analysis on potential cyber-relevant events is essential for ensuring the situational awareness of the system operator as it provides an inexpensive and risk-free environment to test the system responses under various cyber-relevant events and hereby can support research on cyber anomaly detection, optimal protective resource allocation, and mitigation measures. In this webinar, we will share NREL's cybersecurity research capabilities by highlighting the development of a scalable cyber-physical event test bed and demonstration with real hardware in the loop. The developed cyber-physical event test bed is backboned by an integrated transmission, distribution, and communication dynamic co-simulation framework and a plug-and-play cyber event generation module. It is designed to be modular and compatible with parallel computing, and thereby supports large-scale system simulations at an affordable computation cost. The test bed can capture millisecond-to-minutes dynamic frequency and voltage responses under cyber events from the bulk transmission system to the active distribution systems and distributed energy resources at the grid edge.

co-simulation↗

Advanced Research on Integrated Energy Systems Cyber Range

As digital technologies expand to meet the needs of a more autonomous, interconnected, and advanced power system, new cybersecurity complexities and vulnerabilities arise. The ARIES Cyber Range enables the energy sector to evaluate these evolutions and validate cybersecurity solutions without impacting live systems. Combining power grid-scale hardware with emulation and simulation approaches, the ARIES Cyber Range can faithfully replicate modern energy systems - from grid physics to communication networks, and everything in between - with real-world fidelity. At NLR, researchers and partners are answering complex power system cybersecurity questions, examining emerging threats to the electric sector, and de risking new security technologies, all at a mission-relevant speed that keeps pace with rapidly evolving systems and hazards.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

The NREL Cyber Range

With the National Renewable Energy Laboratory's (NREL's) cyber range, researchers can replicate cybersecurity scenarios as they would occur on real, complex energy systems. With supercomputing and advanced emulation capabilities, the cyber range allows users to build digital twins of real systems and connect the emulated environment to actual physical devices throughout NREL's laboratories. The space offers unlimited potential to test the frontier of energy systems security.

cyber range↗

Critical Roles of Information, Analysis, Research, and Operations in the Cyber Realm

PNNL has developed an adaptive cyber integration framework (ACIF) to facilitate the timely sharing of cyber threat information along with the advancement of situational awareness tools to enhance protection against and respond to critical infrastructure cybersecurity threats. The ACIF comprises components implemented iteratively to achieve research and mission goals. The ACIF components include data generation technologies, analytic tools development and maturation, data enrichment and fusion, trust building with stakeholders, investigative research, analytic rigor, production, and dissemination. Each component, its importance to the ACIF, and how they can be adopted and applied across other information-sharing sectors and domains are discussed in this paper.

Cyber Threat Intelligence, Cyber Security, Data En↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Wintap

Wintap is an extensible, general purpose agent framework for the Windows operating system. It provides an easy-to-use plugin architecture, an integrated streaming analytics engine, and real-time event subscriptions for host-based data. Wintap can support a wide variety of applications across production operations, cyber security operations, and cyber security research.

Frye, DavidJ↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗