Engineering PapersSearch

SEARCH · Engineering Papers

Results for “OT”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3

Traffic Shaping to Traffic Engineering in Time-Sensitive OT Network

Modern industrial automation systems increasingly depend on network infrastructures for time-critical communication, driving the need for solutions that guarantee timely and reliable data delivery. IEEE 802.1 Time-Sensitive Networking (TSN) holds significant promise for converging Information Technology (IT) and Operational Technology (OT) networks, enabling interoperability and supporting the coexistence of mixed-critical traffic crucial for Industry 4.0 and IIoT. To achieve deterministic communication, TSN employs various traffic shapers such as the Time-Aware Shaper (TAS), Asynchronous Traffic Shaper (ATS), and Credit-Based Shaper (CBS). However, the effective deployment of TSN in industrial automation faces several challenges. These include the non-trivial mapping of diverse industrial traffic types to specific shapers, the complexity of optimizing shaper configurations. We present a model for effective traffic engineering within TSN enabled OT Network. Our experiments also demonstrate how shaping of certain traffic types get affected in absence of precise time synchronization and propose possible solutions based on experiment results. Based on our experimental results we provide recommendations on how traffic type assignments should be done and which traffic shaping mechanisms should be used for a particular traffic type.

Sarker, Taposh Kumer [University of Texas at El Pa

Multiwavelength study of OT 081: broadband modelling of a transitional blazar

ABSTRACT OT 081 is a well-known, luminous blazar that is remarkably variable in many energy bands. We present the first broadband study of the source, which includes very high energy (VHE, $E\gt $ 100 GeV) $\gamma$-ray data taken by the MAGIC (Major Atmospheric Gamma-ray Imaging Cherenkov telescopes) and H.E.S.S. (High Energy Stereoscopic System) imaging Cherenkov telescopes. The discovery of VHE $\gamma$-ray emission happened during a high state of $\gamma$-ray activity in July 2016, observed by many instruments from radio to VHE $\gamma$-rays. We identify four states of activity of the source, one of which includes VHE $\gamma$-ray emission. Variability in the VHE domain is found on daily time-scales. The intrinsic VHE spectrum can be described by a power law with index $3.27\pm 0.44_{\rm stat}\pm 0.15_{\rm sys}$ (MAGIC) and $3.39\pm 0.58_{\rm stat}\pm 0.64_{\rm sys}$ (H.E.S.S.) in the energy range of 55–300 and 120–500 GeV, respectively. The broadband emission cannot be successfully reproduced by a simple one-zone synchrotron self-Compton model. Instead, an additional external Compton component is required. We test a lepto-hadronic model that reproduces the data set well and a proton-synchrotron-dominated model that requires an extreme proton luminosity. Emission models that are able to successfully represent the data place the emitting region well outside of the broad-line region to a location at which the radiative environment is dominated by the infrared thermal radiation field of the dusty torus. In the scenario described by this flaring activity, the source appears to be a flat spectrum radio quasar (FSRQ), in contrast with past categorizations. This suggests that the source can be considered to be a transitional blazar, intermediate between BL Lac and FSRQ objects.

Abe, H.

IT vs. OT: Trends and Incidents

This presentation discusses the differences between information systems (IT) and operational systems (OT) and why that difference is important in the context of cybersecurity for the energy sector.

29 - ENERGY PLANNING, POLICY AND ECONOMY

OT Defender Presentation - Hacker Mindset

Presentation on hacker mindset and what utilities may be up against from lone hackers or professional groups, with ideas on how to improve defensive posture.

99 - GENERAL AND MISCELLANEOUS

Center of Excellence for Operational Technology

The Center of Excellence for Operational Technology Traditional Presentation Abstract 2025 National Laboratories Information Technology Summit | Denver, CO Traditional Presentation Session Managing cybersecurity risk in Operational Technology (OT) presents a significant challenge across the Department, and critically, at many of the national laboratories. This includes IT-OT convergence, aging OT systems, cost of updating OT systems, and increased Advanced Persistent Threat efforts against OT including the 16 critical infrastructure sectors as listed in Presidential Policy Directive 21. DoE’s Office of Science and NNSA’s Office of the Chief Information Officer are taking the lead in addressing this challenge to include critical systems, by establishing the Center of Excellence (CoE) for Operational Technology. Championed by NNSA Deputy Chief Information Officer Steven McAndrews and the Office of Science Chief Information Officer Shila Cooch, the CoE for OT was chartered in February 2025 to address the challenges of OT cybersecurity and compliance. The CoE for OT will create partnerships and leverage expertise from across the NNSA National Security Enterprise and DOE Labs, Plants and Sites. The CoE will also collaborate with colleagues in other government agencies, industry partners and academia. The CoE for OT discussion at the National Laboratories Information Technology Summit ’25 will include the genesis of the CoE, stated goals, organizational structure, and the effort to attract OT subject matter experts to join the CoE effort to share knowledge and expertise. The discussion will include opportunities to get involved and contribute to this important effort. This session will be led by CoE for OT Co-Chairs Matt Kwiatkowski, Fermi National Laboratory Chief Information Security Officer, and Steven Weldon, Savannah River National Laboratory Cyber Program Director at the Georgia Cyber Center. The session will be of particular interest to CIOs, CTOs, CISOs, as well as IT and OT practitioners.

Kwiatkowski, Matt [Fermilab]

Open Source Software Prevalence Ingest Tool

The OSSP Ingest Tool accepts user-input organizational information, ingests IT/OT asset lists in Excel format, and ingests the associated CycloneDX SBOM's. It then performs analytics demonstrating the ability to answer the follow research questions: o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability to differentiate running from not-running OSS components. o RQ1c: Ability to differentiate based on the originator of the component, because a supplier may have modified it after retrieval from the upstream software source. o RQ2. Ability to correlate the identity of a single OSS component across multiple OT devices, mitigating common name variations such as differences in capitalization, '-' vs '_', and so on. o RQ3. Ability to perform subset analysis of OSS components across multiple OT devices o RQ3a: Ability to perform subset analysis across OSS libraries, generating density & distribution graphs to identify commonly-used libraries and outliers. o RQ3b: Ability to perform subset analysis of a single OSS library, generating density & distribution by CI sector, by device type, by device make/model, and/or by firmware version. o RQ3c: Ability to perform subset analysis by grouping OSS libraries according to programming language, then overlay with RQ4b. o RQ3d: Ability to perform subset analysis by OSS upstream source, providing insight into degree of modifications performed by suppliers. o RQ4. Ability to identify dependencies (transitive and direct) of each differentiated OSS library within each OT device, and enable RQ1,2,3 iteratively for dependencies. o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability Page

Kapadia, Shayna [Lawrence Livermore National Labor

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G

Accelerating template generation in resonant anomaly detection searches with optimal transport

We introduce Resonant Anomaly Detection with Optimal Transport (RAD-OT), a method for generating signal templates in resonant anomaly detection searches. RAD-OT leverages the fact that the samples from the conditional probability density of the target features vary approximately linearly along the optimal transport path connecting the resonant feature. This does not assume that the conditional density itself is linear with the resonant feature, allowing RAD-OT to efficiently capture multimodal relationships, changes in resolution, etc. By solving the optimal transport problem, RAD-OT can quickly build a template by interpolating between the background distributions in two sideband regions. We demonstrate the performance of RAD-OT using the LHC Olympics R&D dataset, where we find comparable sensitivity and improved stability with respect to deep learning-based approaches.

Automation

Design and construction of the CMS Outer Tracker for the phase-2 upgrade

The High-Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000–4000 fb −1 over 10 years of operation with the peak instantaneous luminosity reaching about 5–7.5 × 1 0 34 cm −2 s −1 . During Long Shutdown 3, several components of the CMS detector will undergo major improvements, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have increased radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger for the first time at a hadron collider, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely-spaced silicon sensors read out by front-end ASICs that can correlate hits in the two sensors to create short track segments, used in the Level-1 track finder. The modules come in two flavors: strip-strip and pixel-strip, containing different sensor configurations and multiple ASICs. This contribution presents the Phase-2 OT, the finalization of the OT module design, and the quality assurance and control procedures used to ensure that the modules fulfill both the specifications from the assembly steps as well as the proper communication among the ASICs.

Zoi, Irene [Fermilab] (ORCID:0000000257389446)

Optimal Transport for $e/\pi^0$ Particle Classification in LArTPC Neutrino Experiments

The efficient classification of electromagnetic activity from $\pi^0$ and electrons is a notoriously challenging problem in the reconstruction of neutrino interactions in Liquid Argon Time Projection Chamber (LArTPC) detectors. We address this problem using the mathematical framework of Optimal Transport (OT), which has been successfully employed for event classification in other HEP contexts and is ideally suited to the high-resolution calorimetry of LArTPCs. Using a publicly available simulated dataset from the MicroBooNE collaboration, we show that OT methods achieve state-of-the-art reconstruction performance in $e/\pi^0$ classification. The success of this first application indicates the broader promise of OT methods for LArTPC-based neutrino experiments. This work motivates integrating OT in the reconstruction frameworks of LArTPC experiments such as SBN and DUNE more broadly. Since $\pi^0$s are a significant background for both oscillation experiments and BSM searches, OT can lead to sizeable improvements in the selection efficiency for these analyses by introducing a novel method with which to achieve $\pi^0$ rejection.

Caratelli, David [UC, Santa Barbara]

Augmenting LLM-Based Agents for Improved Performance in Pentesting and Commissioning Operational Technology in Critical Infrastructure

Artificial intelligence (AI), and more specifically large language models (LLMs) have the potential for use in penetration testing (“pentesting”) against devices, networks, and computer systems in information technology (IT). We explore the possibility of extending pentesting from IT systems to operational technology (OT) systems, which are more obscure than IT systems in their protocols and design. A challenge therefore exists when applying pretrained LLMs to OT systems as corpora are likely to underrepresent OT systems in comparison to other more prevalent systems. We evaluate augmentations of LLMs with various methods, especially retrieval augmented generation (RAG), to improve performance of the LLMs in the OT domain. In addition to pentesting, some of the testing of these OT devices may include commissioning to ensure that the newly installed devices work correctly. Our framework may also be applied in such cases.

97 MATHEMATICS AND COMPUTING

Engineering Out Industry 4.0 Cyber Risk Presentation for EnCyCriS

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

99 GENERAL AND MISCELLANEOUS

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity

Design and Construction of the CMS Outer Tracker for the Phase-2 Upgrade

The High Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000-4000~fb$^{-1}$ after 10 years of operation with peak instantaneous luminosity reaching about 5-7.5$\times10^{34}$cm$^{-2}$s$^{-1}$. During Long Shutdown 3, several components of the CMS detector will undergo major changes, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have high radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger, for the first time at hadron colliders, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely spaced silicon sensors read out by front-end ASICs, which can correlate hits in the two sensors creating short track segments (stubs), used for tracking in the L1 track finder. The modules come in two flavors: strip-strip (2S) and pixel-strip (PS), containing different sensor configurations and multiple ASICs. This contribution will present the design of the Phase-2 OT, the first results with pre-production devices, and the quality assurance procedures used to ensure the functionality of the modules: from fulfilling the precision specification of the module assembly procedure to ensuring the proper communication among the module's ASICs.

43 PARTICLE ACCELERATORS

Unveiling the nature of Ga-based chalcogenides for electrical switching selectors

Three-dimensional phase-change memory with stackable crossbar architecture is a promising technology to meet the urgent demands for high-density storage and rapid information processing in the era of explosive data growth. The performance depends strongly on the properties of ovonic threshold switching (OTS) selectors, which control the on/off states of memory units. Amorphous GaS serves as an outstanding OTS material, distinguished by its sizable mobility gap and high crystallization temperature, while the underlying mechanism continues to be inadequately comprehended. Here, in this work, we systematically studied the structural and electronic properties of amorphous Ga-X (X = S/Se/Te) using first-principles calculations. The results show that Ga atoms adopt tetrahedral motifs, while S/Se/Te atoms predominantly exhibit the structure of a distorted triangular pyramid. This structural arrangement is ascribed to the substantial dative bonds formed by the lone-pair electrons of the anions and the vacant sp3 orbitals around Ga atoms. Large mobility gaps (e.g., GaS: 2.43 eV, GaSe: 1.76 eV, GaTe: 1.26 eV) and distinct mid-gap states (e.g., ∼0.66 eV above valence band tail) ensure that these three chalcogenide glasses can be switched on under an external electric field while effectively suppressing leakage current without a bias, and the defect electronic states originate from short, robust Ga-Ga bonds due to the formation of distorted chain-like local structures. Our research elucidates the mechanisms of amorphous Ga-X as OTS materials, enriching the spectrum of electrical switching selectors by incorporating III-VI chalcogenides. This inclusion offers novel opportunities for the refinement and optimization of high-density integrated memory systems.

36 MATERIALS SCIENCE