Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “IC design analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Graph Theory and IC Component Design Analysis

Graph analysis in large integrated circuit (IC) designs is an essential tool for verifying design logic and timing via dynamic timing analysis (DTA). IC designs resemble graphs with each logic gate as a vertex and the conductive connections between gates as edges. Using DTA digital statistical correlations, graph condensation, and graph partitioning, it is possible to identify high-entropy component centers and paths within an IC design. Identification of high-entropy component centers (HECC) enables focused DTA, effectively lowering the computational complexity of DTA on large integrated circuit graphs. In this paper, a devised methodology termed IC layout subgraph component center identification (CCI) is used to identify described. CCI lowers DTA computationally complexity by condensing IC graphs into reduced subgraphs in which dominant logic functions are verified.

42 ENGINEERING↗

Ion Chromatography (IC) Round Robin Analyses of Low Glycolate Concentrations in Recycle Collection Tank (RCT) Post Permanganate Treatment Simulant

This work is a demonstration of Ion Chromatography (IC) analysis of low concentrations of glycolate in chemical simulant designed to mimic the matrix in the Recycle Collection Tank (RCT) at the Defense Waste Processing Facility (DWPF) after sodium permanganate oxidation treatment. The IC method was previously developed [1] and this report covers the results of round robin testing with three analytical laboratories located at the Savannah River Site (SRS). The laboratories are termed the Sensing & Metrology (S&M) laboratory at the Savannah River National Laboratory (SRNL), the Processing Science Analytical Laboratory (PSAL) at SRNL, and the DWPF laboratory at SRS. Each laboratory received four samples: (1) 200 mL of 21.3 mg/L glycolate in RCT post permanganate strike sulfite quenched simulant, (2) 200 mL of 38.0 mg/L glycolate in RCT post permanganate strike sulfite quenched simulant, (3) 200 mL of 54.9 mg/L glycolate in RCT post permanganate strike sulfite quenched simulant, and (4) 600 mL of RCT post permanganate strike sulfite quenched simulant to use for matrix matched blanks.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Simulation of materials processing: Fantasy or reality?

This experiment introduces students to the application of computer-aided design (CAD) and analysis of materials processing in the context of integrated circuit (IC) fabrication. The fabrication of modern IC's is a complex process which consists of several sequential steps. These steps involve the precise control of processing variables such as temperature, humidity, and ambient gas composition. In essence, the particular process employed during the fabrication becomes a 'recipe'. Due to economic and other considerations, CAD is becoming an indispensable part of the development of new recipes for IC fabrication. In particular, this experiment permits the students to explore the CAD of the thermal oxidation of silicon.

Jenkins, Thomas J.↗

Wind Plant Performance Prediction Benchmark Phase 1 (Technical Report)

Financial risk resulting from the uncertainty associated with developing, owning, and operating wind power plants remains a barrier to reducing the levelized cost of energy (LCOE). On average, modern wind power plants in the U.S. underperform their expected annual energy output by 3.5-4.5% , with many underperforming by over 10%. To compensate for this uncertainty, investors require a larger return on investment (ROI) and apply "knock-down" factors that mask much of the underlying sources of uncertainty. Wind energy projects thus have reduced access to low-cost capital. Furthermore, operating wind plants often take a simple approach to estimating operations & maintenance (O&M) costs (e.g. straight-line estimates based on similar plants), which can eat into profits. To overcome these issues, the wind industry must improve the models they use for estimating wind plant performance and operations. An industry consortium (IC) requested that the National Renewable Energy Laboratory (NREL) lead a Department of Energy (DOE) working group to benchmark the accuracy of wind power plant energy predictions against real operational data. The IC was also motivated by DOE and NREL's potential to characterize systematic energy underperformance, identify sources of uncertainty, and explore root causes. The Wind Plant Performance Prediction (WP3) project was created out of this request, and this report represents the successful completion of Phase 1 of the WP3 project. During the project, wind plant owners provided both pre-construction and operational data to NREL. The pre-construction data was provided to wind resource assessment (WRA) consultants so they could conduct energy yield assessments (EYA). NREL took all of the completed EYAs, along with the operational data, and conducted an operational assessment to benchmark the EYA results against actual operational data. Given the large amounts of sensitive data required for this effort, as well as historical opposition to sharing data within industry, successful completion of Phase 1 represents an unprecedented milestone for industry data sharing. To improve the accuracy and confidence of pre-construction EYAs, wind plant owners and investors need better, more certain, energy yield predictions. The WP3 Benchmark Project is an industry-driven response to this reality. For the first time, industry has taken the important step of working together at scale, sharing valuable operational data with DOE and NREL in order to investigate the sources of bias and uncertainty in these energy estimates. This IC provides wind plant preconstruction and operational data to NREL in an organized and documented fashion and provides guidance and feedback as needed. The IC also provides introspection of the design of experiment, key metrics of success, data challenges, analysis best practices, and quality of results.

17 WIND ENERGY↗

Engineering study on the rotary-vee engine concept

This paper provides a review of the applicable thermodynamic cycle and performance considerations when the rotary-vee mechanism is used as an internal combustion (IC) heat engine. Included is a simplified kinematic analysis and studies of the effects of design parameters on the critical pressures, torques and parasitic losses. A discussion of the principal findings is presented.

Willis, Edward A.↗

Steady state thermo-mechanics and material property definition framework for analyzing DCLL blanket in the fusion nuclear science facility

In this work, a thermo-mechanics model that relies on creating the material property definition framework (MPDF) and multiphysics coupling of the heat transfer and the solid mechanics modules is developed to determine the structural integrity of the recently designed dual cooled lead lithium (DCLL) inboard blanket (IB) for the Fusion Nuclear Science Facility under steady state loads. The MPDF is called to supply fusion relevant neutron irradiation and temperature induced changes in material properties during multiphysics finite element runs, and PbLi temperature profiles are used to approximate Magnetohydrodynamics effect and the nuclear volumetric heating on the PbLi. Neutron irradiation and temperature induced reduction of the yield and ultimate strengths of F82H steel at the first wall (FW) are quantified for one year. A blanket in an assembly with gaps between blanket sectors and another blanket in an assembly with no gaps between blanket sectors, both exposed to radiation damage that lasted for one year are analyzed. Analysis using the elastic ITER structural design criteria for in-vessel components (ITER SDC-IC) design rules and a linear isotropic-hardening-type elastoplastic material model are used where most appropriate. The IB blanket with gaps between blanket sectors will withstand the steady state combined thermal and coolant loads for one year operational period but will fail if no gaps are allowed between blanket sectors. It is recommended that a gap of about 7.62 mm should be provided between IB blanket sectors during assembly which would close up during service, stop neutron streaming, reduce stresses and reduce bending of the FW into the scrape-off layer.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Collection and Analysis of Telemetry for CyOTE Heuristics (CATCH)

The Collection and Analysis of Telemetry for CyOTE Heuristics (CATCH) provides a framework for augmenting an organization’s existing security controls with CyOTE developed analyses. CATCH collects, stores, analyzes, and creates STIX reports on anomalous data. CATCH connects the CyOTE analysis framework together with the MITRE ICS ATT&CK® patterns and highlights areas of improvement and further research. This tool is designed to enhance an organization’s security controls by providing a structured approach to collecting, storing, analyzing, and reporting anomalous data.

99 GENERAL AND MISCELLANEOUS↗

Analysis of the Space Shuttle main engine simulation

This is a final report on an analysis of the Space Shuttle Main Engine Program, a digital simulator code written in Fortran. The research was undertaken in ultimate support of future design studies of a shuttle life-extending Intelligent Control System (ICS). These studies are to be conducted by NASA Lewis Space Research Center. The primary purpose of the analysis was to define the means to achieve a faster running simulation, and to determine if additional hardware would be necessary for speeding up simulations for the ICS project. In particular, the analysis was to consider the use of custom integrators based on the Matrix Stability Region Placement (MSRP) method. In addition to speed of execution, other qualities of the software were to be examined. Among these are the accuracy of computations, the useability of the simulation system, and the maintainability of the program and data files. Accuracy involves control of truncation error of the methods, and roundoff error induced by floating point operations. It also involves the requirement that the user be fully aware of the model that the simulator is implementing.

Deabreu-Garcia, J. Alex↗

Interface Consistency: Phase I Results & Phase II Status

Future exploration missions will rely on designing and developing vehicles and complex systems from within NASA and through multiple external commercial partners to meet mission goals. Despite existing consistency-related agency requirements, NASA’s approach to commercial spaceflight development encourages providers’ flexibility and innovation. This strategy is resulting in significant design diversity across Artemis vehicles. Design best practices and guidelines champion interface consistency to promote mental model development and knowledge transfer. However, research investigating the benefits of consistency is mixed, and little is known about its role in complex systems. Determining the level of risk that system diversity presents is difficult, as there is no established method for quantifying the degree of consistency within and across interfaces, nor is there information about the differential impacts of different types of inconsistency. Phase I of this project (Characterization and Measurement) served as a starting point to better understand the construct of consistency, its application, and the range of studies and methods for measuring it. The project team created a taxonomy of consistency to apply to interfaces as a framework to guide the development of tools to assess intersystem consistency. Checklist and cognitive walkthrough methods were developed for use by human factors (HF) and human-computer interaction (HCI) experts. The Intersystem Consistency Scale (ICS) was developed for interface evaluations with crew. A pilot study evaluated the methods’ ability to distinguish differences between Artemis-like prototype pairs exhibiting either high or low design consistency. In addition, click errors and time on task were collected within the ICS (crew-like) group. Results from our exploratory analysis and lessons learned from the pilot study will be discussed. The project team will also present the status of Phase II (Risk Assessment, Standards and Guidelines). This includes incorporating feedback to redesign the assessment tools, and inputs from displays and training Subject Matter Experts to update tasks and prototype designs. The team will present the risk assessment study design to identify the types and levels of inconsistency that pose the greatest risk to performance. Plans to apply these results toward agency standards and guideline recommendations will also be discussed.

Human-Computer Interaction↗

Mars Science Laboratory CHIMRA/IC/DRT Flight Software for Sample Acquisition and Processing

The design methodologies of using sequence diagrams, multi-process functional flow diagrams, and hierarchical state machines were successfully applied in designing three MSL (Mars Science Laboratory) flight software modules responsible for handling actuator motions of the CHIMRA (Collection and Handling for In Situ Martian Rock Analysis), IC (Inlet Covers), and DRT (Dust Removal Tool) mechanisms. The methodologies were essential to specify complex interactions with other modules, support concurrent foreground and background motions, and handle various fault protections. Studying task scenarios with multi-process functional flow diagrams yielded great insight to overall design perspectives. Since the three modules require three different levels of background motion support, the methodologies presented in this paper provide an excellent comparison. All three modules are fully operational in flight.

sample processing↗

Scalable, Physical Effects Measurable Microgrid for Cyber Resilience Analysis (SPEMMCRA)

The ability to advance state of the art automated protections for industrial control systems (ICS) has as a precursor in the ability to understand the tradeoff space. That is, to enable a cyber feedback loop in a control system environment you must first consider both the security mitigation available, the benefits and the impacts to the control system functionality when the mitigation is used. More damaging impacts could be precipitated that the mitigation was intended to rectify. This paper details networked ICS that controls a simulation of the frequency response represented with the swing equation. The microgrid loads and base generation can be balanced through the control of an emulated battery and power inverter. The simulated plant, which is implemented in Raspberry Pi computers, provides an inexpensive platform to realize the physical effects of cyber attacks to show the tradeoffs of available mitigatoins. This network design can include a commercial ICS controller to introduce real world implementation of feedback controls, and provides a scalable, physical effects measurable Microgrid for cyber resilience analysis (SPEMMCRA).

42 ENGINEERING↗

Automated radiation hard ASIC design tool

A commercial based, foundry independent, compiler design tool (ChipCrafter) with custom radiation hardened library cells is described. A unique analysis approach allows low hardness risk for Application Specific IC's (ASIC's). Accomplishments, radiation test results, and applications are described.

White, Mike↗

Extraction and Separation Modeling of Orion Test Vehicles with ADAMS Simulation

The Capsule Parachute Assembly System (CPAS) project has increased efforts to demonstrate the performance of fully integrated parachute systems at both higher dynamic pressures and in the presence of wake fields using a Parachute Compartment Drop Test Vehicle (PCDTV) and a Parachute Test Vehicle (PTV), respectively. Modeling the extraction and separation events has proven challenging and an understanding of the physics is required to reduce the risk of separation malfunctions. The need for extraction and separation modeling is critical to a successful CPAS test campaign. Current PTV-alone simulations, such as Decelerator System Simulation (DSS), require accurate initial conditions (ICs) drawn from a separation model. Automatic Dynamic Analysis of Mechanical Systems (ADAMS), a Commercial off the Shelf (COTS) tool, was employed to provide insight into the multi-body six degree of freedom (DOF) interaction between parachute test hardware and external and internal forces. Components of the model include a composite extraction parachute, primary vehicle (PTV or PCDTV), platform cradle, a release mechanism, aircraft ramp, and a programmer parachute with attach points. Independent aerodynamic forces were applied to the mated test vehicle/platform cradle and the separated test vehicle and platform cradle. The aero coefficients were determined from real time lookup tables which were functions of both angle of attack ( ) and sideslip ( ). The atmospheric properties were also determined from a real time lookup table characteristic of the Yuma Proving Grounds (YPG) atmosphere relative to the planned test month. Representative geometries were constructed in ADAMS with measured mass properties generated for each independent vehicle. Derived smart separation parameters were included in ADAMS as sensors with defined pitch and pitch rate criteria used to refine inputs to analogous avionics systems for optimal separation conditions. Key design variables were dispersed in a Monte Carlo analysis to provide the maximum expected range of the state variables at programmer deployment to be used as ICs in DSS. Extensive comparisons were made with Decelerator System Simulation Application (DSSA) to validate the mated portion of the ADAMS extraction trajectory. Results of the comparisons improved the fidelity of ADAMS with a ramp pitch profile update from DSSA. Post-test reconstructions resulted in improvements to extraction parachute drag area knock-down factors, extraction line modeling, and the inclusion of ball-to-socket attachments used as a release mechanism on the PTV. Modeling of two Extraction parachutes was based on United States Air Force (USAF) tow test data and integrated into ADAMS for nominal and Monte Carlo trajectory assessments. Video overlay of ADAMS animations and actual C-12 chase plane test videos supported analysis and observation efforts of extraction and separation events. The COTS ADAMS simulation has been integrated with NASA based simulations to provide complete end to end trajectories with a focus on the extraction, separation, and programmer deployment sequence. The flexibility of modifying ADAMS inputs has proven useful for sensitivity studies and extraction/separation modeling efforts. 1

Fraire, Usbaldo, Jr.↗

Cyote-attack Chain Estimator

Attack Chain Estimator (ACE) Application Overview The Attack Chain Estimator (ACE) Application is a sophisticated tool designed for the ingestion, classification, sequencing, and enrichment of cybersecurity threat reports. This application leverages advanced machine learning models and extensive historical data to provide comprehensive insights into cyber threats, specifically targeting Industrial Control Systems (ICS). Purpose The primary functions of the ACE Application include: Ingestion of Cybersecurity Threat Reporting: Capable of ingesting text-based threat reports in markdown or text file format. Supports ingestion of structured data from other sources in STIX/JSON format. Classification of Report’s Text-Based Events: Utilizes a DeBERTa classifier, specifically trained on cybersecurity data, to map the events to MITRE ATT&CK for ICS Tactics and Techniques. Classification is performed using multiple Jupyter notebooks and machine learning workflows hosted as FastAPI microservices: regex_data deberta_base_35_train_hft_classifier_mlflow.ipynb hft_regex_classifier_mlflow.ipynb param_train_hft_classifier_mlflow.ipynb regex_tactic_tech.ipynb Ordering of Tactics, Techniques, and Observable Events: Sequences the identified tactics, techniques, and events to form a coherent attack chain. Enrichment with Historical Attack Chain Details: Enhances the attack chain with details from historical attacks using a Markov model developed from CyOTE Precursor Analysis Report data. The Markov model is available as a FastAPI endpoint for seamless integration. Enrichment with Adversary Emulation Capabilities Data: Integrates adversary emulation capabilities data using MITRE Caldera for OT adversary abilities UUIDs. Export of Output Files: Provides options to export the enriched attack chain in JSON or CSV formats. Routing of Output to Other Applications: Facilitates routing of output to various platforms and applications, including: Threat Intelligence Platforms COREII Scout for Threat Intelligence Analysis COREII Modeling and Simulation for Adversary Emulation Technical Description The ACE Application is an advanced cybersecurity tool designed to provide detailed threat analysis and sequence generation. It is built on a robust architecture that integrates natural language processing, machine learning, and historical data modeling. Key Components: Data Ingestion Module: Handles the input of threat reports and data from various formats, ensuring flexibility in data sources. Classification Engine: Employs DeBERTa-based classifiers hosted as FastAPI microservices to analyze and classify threat report events in accordance with the MITRE ATT&CK framework for ICS. Sequence Generator: Orders the classified events into a logical attack chain, providing clear insight into the sequence of tactics and techniques used in the threat. Enrichment Engine: Integrates historical data and adversary emulation capabilities to enhance the attack chain with valuable context and additional details. The historical data enrichment is powered by a Markov model, which is available as a FastAPI endpoint. Export and Routing Module: Facilitates the export of the enriched attack chain in multiple formats and routes the output to designated applications for further analysis or emulation.

Paul, Tony [Idaho National Laboratory (INL), Idaho↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Prototyping and implementing flight qualifiable semicustom CMOS P-well bulk integrated circuits in the JPL environment

Presently, there are many difficulties associated with implementing application specific custom or semi-custom (standard cell based) integrated circuits (ICs) into JPL flight projects. One of the primary difficulties is developing prototype semi-custom integrated circuits for use and evaluation in engineering prototype flight hardware. The prototype semi-custom ICs must be extremely cost-effective and yet still representative of flight qualifiable versions of the design. A second difficulty is encountered in the transport of the design from engineering prototype quality to flight quality. Normally, flight quality integrated circuits have stringent quality standards, must be radiation resistant and should consume minimal power. It is often not necessary or cost effective, however, to impose such stringent quality standards on engineering models developed for systems analysis in controlled lab environments. This article presents work originally initiated for ground based applications that also addresses these two problems. Furthermore, this article suggests a method that has been shown successful in prototyping flight quality semi-custom ICs through the Metal Oxide Semiconductor Implementation Service (MOSIS) program run by the University of Southern California's Information Sciences Institute. The method has been used successfully to design and fabricate through the MOSIS three different semi-custom prototype CMOS p-well chips. The three designs make use of the work presented and were designed consistent with design techniques and structures that are flight qualifiable, allowing one hour transfer of the design from engineering model status to flight qualifiable foundry-ready status through methods outlined in this article.

Olson, E. M.↗

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗