SEARCH · Engineering Papers
Results for “Technology and Operations”
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Towards 5G-Enabled Operational Technology for Process Monitoring and Network Slicing
Cyber-Physical Systems (CPS) are deployed to monitor physical processes in critical cyber-enabled services like power generation. However, CPS ecosystems are typically designed without robust security. While it is important to ensure optimal performance of the Operational Technology (OT) environments, security cannot be overlooked. To modernize traditional OT services, 5G technology is being integrated. 5G technology offers low latency and high availability, making it a suitable infrastructure for managing and monitoring physical processes. How-ever, integrating 5G mechanisms into large-scale OT networks introduces new implementation and performance challenges. Therefore, this paper presents a 5G-enabled CPS architecture (5G-CPS) that describes the necessary components, services, and communication protocols and conducts feasibility study to integrate 5G technology in industrial control system networks to understand the performance merits. The 5G-CPS architecture aims to minimize implementation and operational challenges associated with integrating 5G technology into constrained OT.
Center of Excellence for Operational Technology
The Center of Excellence for Operational Technology Traditional Presentation Abstract 2025 National Laboratories Information Technology Summit | Denver, CO Traditional Presentation Session Managing cybersecurity risk in Operational Technology (OT) presents a significant challenge across the Department, and critically, at many of the national laboratories. This includes IT-OT convergence, aging OT systems, cost of updating OT systems, and increased Advanced Persistent Threat efforts against OT including the 16 critical infrastructure sectors as listed in Presidential Policy Directive 21. DoE’s Office of Science and NNSA’s Office of the Chief Information Officer are taking the lead in addressing this challenge to include critical systems, by establishing the Center of Excellence (CoE) for Operational Technology. Championed by NNSA Deputy Chief Information Officer Steven McAndrews and the Office of Science Chief Information Officer Shila Cooch, the CoE for OT was chartered in February 2025 to address the challenges of OT cybersecurity and compliance. The CoE for OT will create partnerships and leverage expertise from across the NNSA National Security Enterprise and DOE Labs, Plants and Sites. The CoE will also collaborate with colleagues in other government agencies, industry partners and academia. The CoE for OT discussion at the National Laboratories Information Technology Summit ’25 will include the genesis of the CoE, stated goals, organizational structure, and the effort to attract OT subject matter experts to join the CoE effort to share knowledge and expertise. The discussion will include opportunities to get involved and contribute to this important effort. This session will be led by CoE for OT Co-Chairs Matt Kwiatkowski, Fermi National Laboratory Chief Information Security Officer, and Steven Weldon, Savannah River National Laboratory Cyber Program Director at the Georgia Cyber Center. The session will be of particular interest to CIOs, CTOs, CISOs, as well as IT and OT practitioners.
Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning
The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.
Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks
Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology
Deploying Software-Defined Networking in Operational Technology Environments
Software Defined Networking for Operational Technologies, referred to as OT-SDN, is a leading technology to secure critical infrastructure and command and control (C2) systems. As the name implies, OT-SDN networks are programmable, which allows system owners to utilize the characteristics of their physical process to inform the security of their network. There are best practices for deploying OT-SDN into an environment, whether it is all at once or over time (hybrid) that the network is converted to SDN technologies. Through the development of data mining tools and standardized process control, OT-SDN can be deployed reliably. These tools will minimize or eliminate any communication failures during the transition and provide the network owner with complete documentation of their environment. This documentation could enable or facilitate the network owner to pass any audits or policy checks (Authority to Operate) before being allowed to utilize the OT-SDN infrastructure.
Cybersecurity for the Operational Technology Environment (CyOTE)
Cybersecurity for the Operational Technology Environment (CyOTE) briefing provided to Duke Energy during their visit to INL on January 25, 2023. This is following the process to release the slides to Duke Energy.
Advance Reactor Operational Technology Architecture Categorization
Seven generation III+ and generation IV nuclear reactor types, based on twelve reactor concepts surveyed, are examined using functional decomposition to extract relevant operational technology (OT) architecture information. This information is compared to existing nuclear power plants (NPPs) OT architectures to highlight novel and emergent cyber risks associated with next generation NPPs. These insights can help inform operational technology architecture requirements that will be unique to a given reactor type. Next generation NPPs have streamlined OT architectures relative to the current generation II commercial NPP fleet. Overall, without compensatory measures that provide sufficient and efficient cybersecurity controls, next generation NPPs will have increased cyber risk. Verification and validation of cyber-physical testbeds and cyber risk assessment methodologies may be an important next step to reduce cyber risk in the OT architecture design and testing phase. Coordination with safety requirements can result in OT architecture design being an iterative process.
Community threat intelligence and visibility for operational technology networks
Techniques are provided for community threat intelligence for operational technology networks. For a plurality of OT networks, at least one monitoring device processes OT network traffic and collects telemetry data, and a telemetry sanitization system applies a sanitization process to the telemetry data to generate sanitized telemetry data that does not include sensitive data. A computer system receives sanitized telemetry data from the telemetry sanitization systems provided for the plurality of OT networks, maintains threat intelligence data generated based on the sanitized telemetry data, and provides access to at least one of the threat intelligence data and the sanitized telemetry data to a plurality of users.
Strengthening the Security of Operational Technology: Understanding Contemporary Bill of Materials
The evolution of cyber-physical infrastructure has made its security more challenging. The last few years have witnessed a convergence of hardware and software segments in various domains, including operational technology (OT) which is responsible for carrying out critical tasks such as monitoring and controlling power grids, nuclear plants, transportation, and emergency services. Both hardware and software encapsulate numerous open source and proprietary subcomponents, making it crucial for end-users to understand the composition of the products they are using. For example, wind turbines incorporate thousands of lines of code (software) used for the turbine's design, planning, operation, and analytics in addition to the numerous hardware subcomponents that construct it. Due to the highly complex nature of software and hardware, knowledge of the components and subcomponents is required to mitigate cyber vulnerabilities and defend against cyberattacks. There has also been a transformation from a traditional linear supply chain into a global, dynamic, diverse, and interconnected system. The digitization of the supply chain makes it easier to find and exploit vulnerabilities. Critical infrastructures (e.g., power grids, oil, natural gas, water, and wastewater) rely on OT to function, and if the OT is compromised, equipment damage and potential interruption of services could result. A significant security measure to protect OT systems from disruption is to develop a supply chain bill of materials (BoM) corresponding to the software and hardware used in OT, along with attestations amongst vendors and asset owners. A supply chain BoM is a proactive way to understand the inherent vulnerabilities in the system and mitigate them in advance of being exploited. BoMs bolster the trust placed in the digital infrastructure and enhance software supply chain security by sustaining the management of component obsolescence and compliance, along with the seclusion of unsafe segments of a specific product. Adopting BoM tools is becoming increasingly important across various government sectors, as evidenced by the recent U.S. executive order on cybersecurity (NIST 2021). This paper aims to classify BoMs based on structure, functionality, component type, and architecture. The work also discusses case studies to further highlight the benefits of BoMs. In addition, it identifies missing pieces in existing BoM implementations so that future research may identify bounds on where it could expect to make improvements and directly enable researchers to identify promising areas for exploration. Further, the authors provide valuable recommendations to tool developers, researchers, and standardizing organizations (policymakers), additionally benefitting critical infrastructure owners and government executives. This aids in paving a path for future work, thereby, providing suggestions to determine a tool for consumers that best suit their needs.
Cybersecurity for the Operational Technology Environment (CyOTE)
The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop CyOTE. This research initiative addresses cybersecurity threats against operational technology (OT) networks by sharing intelligence about adversarial tactics and techniques with the energy sector. CyOTE improves the sector’s ability to detect anomalous behavior that indicates potential malicious cyber activity in OT networks.
Advanced Grid Operational Technology Edge-Level Threat Detection
This report presents a deployable solution to improve the cybersecurity situational awareness of the legacy SCADA system infrastructure in power grids. The main goal of this project is to provide system owners and operators a highly trusted, intelligent alarm system and comprehensive situational awareness of ongoing or potential cybersecurity threats on the grid network. The key contributions of this project include: (1) the development of software, the Intrusion Detection Visualizer for the Operational Technology Network (IViz-OT), to visualize and locate intrusions on the grid network; (2) testing the signature-based Hybrid Intrusion Detection for Energy Systems (HIDES) for different types of intrusions; (3) the integration of HIDES and IViz-OT into the visualization dashboard; and (4) real-time testing using a hardware-in-the-loop test bed.
Micro Baselines for Operational Technology Environments
Critical infrastructure stakeholders need to baseline their networks to understand expected communications. Top-down approaches to baselining rely on observables that are generally available but lack properties upon which traditional statistical tools depend. We propose to construct micro-baselines: signatures within operational networks based on observables associated with specific events. Such observables are informed by precursor analysis reports of historical cyber attacks on operational environments developed by Cybersecurity for Operational Technology Environments (CyOTE). Baseline measurements depend upon context beyond the cyber domain. An energy plant's baseline running in the summer may statistically differ from a similar facility in a colder region. Domain knowledge must be integrated to apply general micro-baselining algorithms to a facility-specific context. Therefore, we propose to explore the feasibility of transferring micro baselining algorithms across different facilities. Facilities that implement the same processes in different geographic locations will be compared relative to observable measurements used in micro-baselining for comparable events. One evaluation approach would condition or augment dynamic observables measured within a facility network testbed with additional observables derived from geographic context or infrastructure dependencies such as those provided by the All-Hazards Analysis tool.
Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology
This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.
Augmenting LLM-Based Agents for Improved Performance in Pentesting and Commissioning Operational Technology in Critical Infrastructure
Artificial intelligence (AI), and more specifically large language models (LLMs) have the potential for use in penetration testing (“pentesting”) against devices, networks, and computer systems in information technology (IT). We explore the possibility of extending pentesting from IT systems to operational technology (OT) systems, which are more obscure than IT systems in their protocols and design. A challenge therefore exists when applying pretrained LLMs to OT systems as corpora are likely to underrepresent OT systems in comparison to other more prevalent systems. We evaluate augmentations of LLMs with various methods, especially retrieval augmented generation (RAG), to improve performance of the LLMs in the OT domain. In addition to pentesting, some of the testing of these OT devices may include commissioning to ensure that the newly installed devices work correctly. Our framework may also be applied in such cases.
Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)
Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.
Engineering Services in a Mission Critical Environment: Engineering Services - Science and Technology Operations’ Infrastructure Support at Los Alamos National Laboratory
As an engineering team within a facilities-driven organization, Engineering Services – Science and Technology Operations (ES-STO), supports Los Alamos National Laboratory (LANL), playing a pivotal role in the U.S. nuclear stockpile mission. This report outlines ES-STO’s contributions through the installation of crucial systems such as HVAC units, compressors, and scientific specialty equipment, as well as providing expert consultation to optimize laboratory operations. ES-STO’s goal is to ensure that LANL's infrastructure and research facilities are aligned with mission-critical needs, supporting both operational efficiency and safety in the nuclear stockpile management and maintenance. This report discusses the installation processes, ongoing consultations, and the significant impact of our efforts on national security objectives.
Operational Technology Behavioral Analytics (OTBA) (Final Technical Report DE-FE0031640)
This final report provides a summary of the methodology, findings, lessons learned, and insights from an investigation into the feasibility of the Operational Technology Behavioral Analytics (OTBA) cybersecurity approach. The concept was evaluated with data from the National Carbon Capture Center (NCCC) – a U.S. Department of Energy (DOE) funded facility that is managed and operated by Southern Company Services, Inc. at Alabama Power Company’s E. C. Gaston generating power plant in Wilsonville, Alabama. Appropriate data sources for the post-combustion carbon capture system were identified. Infrastructure was deployed to monitor, capture and archive data for the system. Critical parameters for each subsystem were identified and analyzed. Machine-learning algorithms were used to establish and characterize normal operations and subsequently identify anomalies. This effort yielded valuable insights and formed the basis of a data-centric strategy for detecting cyber-attacks along with a coordinated response philosophy. A significant takeaway is that the OTBA cybersecurity approach is quite portable; it can be applied to other critical infrastructure beyond fossil power generation.