Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “advanced persistent threats”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Cyber Threat Landscape for Distribution Systems

INL cyber analysts will present an overview of the current threat landscape for distribution systems. We will begin with examples of known attacks that have occurred recently to motivate the threat analysis and mitigation discussed in the remainder of the presentation. Examples may include the attacks affecting wind plants in Europe in Spring 2022, ransomware attacks on city utilities and commercial distribution systems, and advanced persistent threats (APTs) including the attacks on Ukrainian electric system in 2015 and 2016, as well as more recent evidence of other APT activity. We will present the end-to-end attack paths and discuss the various attacker skills, financing, motivations, and access that contributed to these attacks. In the second part of this presentation, we will discuss mitigating the cyber threats for distribution systems. We will discuss recent publicly disclosed vulnerabilities and explain their relevant context for distribution system security. Likely attacks to affect distribution systems, such as denial-of-service (DoS), ransomware, edge-device compromise, and advanced persistent threats (APTs) will be described. In addition to an overview of these kinds of attacks, we will provide examples of the various ways in which these attacks can start and what systems they can affect. Simple, cost-effective counter-measures to these attacks will be discussed and we will emphasize how these mitigations can reduce threats when properly applied and maintained.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Challenges in Low-Inertia Power-Electronics-Dominated Grids

Here, the low inertia characteristics of the power electronics dominated grid (PEDG) introduces challenges while restoring voltage and frequency to their nominal values. These stability challenges create new cybersecurity vulnerabilities that are not thoroughly discussed in the literature. Cyber events such as false data injection (FDI), denial of service (DoS), man-in-the-middle attacks, stealthy attacks, and advanced persistent threats target PEDG to disrupt grid stability or gain financial benefits. The low inertia of PEDG (< 2s) compared to traditional grids (~10s) exacerbates these vulnerabilities. In response to stealthy attacks on state variables that supervisory layers cannot detect until significant harm occurs, the low inertia characteristics of PEDG offer substantial stealthy attack surfaces. To counteract such threats, PEDG must be equipped with ultra-fast real-time anomaly detection system and trajectory prediction mechanism to achieve effective cyberattack resiliency.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation

Advanced persistent threats and cyberattacks can impact wide-area monitoring, protection, and control (WAMPAC) system operation. Many cyber-physical system (CPS) testbeds have been developed for attack-defense experimentation and attack-resiliency tools evaluation for WAMPAC, but they are limited to a simulation-and-emulation based environment. This paper presents a quasi-realistic CPS attack-defense testbed-based framework for WAMPAC applications using the industrial substation and control center platforms such as eTerra integrated with the hardware-in-the-loop CPS smart grid testbed available at Iowa State University. The proposed framework includes various combinations of industry-grade substation and control center platforms, communication topologies, real-time digital simulators, and a novel cyber-physical distributed intrusion-and-anomaly detection system (D-IADS) for WAMPAC applications. The D-IADS includes a master at the control center and geographically distributed sensor devices at each substation. Each D-IADS sensor deployed at a substation or control center network monitors ingress and egress traffic, detect intrusions, and dispatch alerts to the D-IADS master. The D-IADS master centrally monitors and analyze the alerts and controls D-IADS sensors. We considered an EMP60 synthetic CPS grid as a case study to demonstrate the framework and proposed D-IADS for WAMPAC applications against cyberattack vectors such as Man-in-the-Middle DNP3 attack, denial-of-service, and data-integrity attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Sensor and Actuator Attacks on Hierarchical Control Systems with Domain-Aware Operator Theory

Cyber-Physical Systems (CPSs) provide opportunities for cyber attacks to have physical impacts. Advanced Persistent Threats (APTs) are a subclass of cyber threats that act stealthily to avoid detection and enable long-term attacks. Here, we build on our past work in APT modelling to combine deception-based sensor bias attacks and direct actuator manipulations in attacks against a hierarchical control system. That past work used the Koopman operator to develop a data-driven, domain-aware, optimization-based attacker model. Using an expansion of this model, we compute several different attacks, including multiple simultaneous attacks, against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. One next step of interest is to construct a defender system, built on the same modelling approach, designed to detect and mitigate such attacks.

koopman operator, Cyber-Physical Security, machine↗

Metagames and Hypergames for Deception-Robust Control

Cyber-physical systems (CPSs) consist of computing and communication devices integrated with physical components such as sensors and actuators. Increasing connectivity to the Internet for remote monitoring and control has made CPSs more vulnerable to deliberate attacks, which are distinctly different from random perturbations in the system. This provides a way for purely cyber attacks to have physical consequences. Stuxnet is a prominent example of such an attack, one in which the malware acted over an extended period of time while deliberately remaining undetected. Such attacks can be described as Advanced Persistent Threats (APTs) -- long-term, stealthy attacks. Here, we extend our previous work on hypergames to develop defender strategies that are robust to deception and do not rely on attack detection. We prove that the defender can bound the attacker payoff with these strategies even when the attacker can choose between different attack modes, and we numerically demonstrate our approach on a realistic building control system. Finally, we discuss next steps in extending this approach towards an operational capability.

hypergames, cyber-physical systems, robust control↗

Center of Excellence for Operational Technology

The Center of Excellence for Operational Technology Traditional Presentation Abstract 2025 National Laboratories Information Technology Summit | Denver, CO Traditional Presentation Session Managing cybersecurity risk in Operational Technology (OT) presents a significant challenge across the Department, and critically, at many of the national laboratories. This includes IT-OT convergence, aging OT systems, cost of updating OT systems, and increased Advanced Persistent Threat efforts against OT including the 16 critical infrastructure sectors as listed in Presidential Policy Directive 21. DoE’s Office of Science and NNSA’s Office of the Chief Information Officer are taking the lead in addressing this challenge to include critical systems, by establishing the Center of Excellence (CoE) for Operational Technology. Championed by NNSA Deputy Chief Information Officer Steven McAndrews and the Office of Science Chief Information Officer Shila Cooch, the CoE for OT was chartered in February 2025 to address the challenges of OT cybersecurity and compliance. The CoE for OT will create partnerships and leverage expertise from across the NNSA National Security Enterprise and DOE Labs, Plants and Sites. The CoE will also collaborate with colleagues in other government agencies, industry partners and academia. The CoE for OT discussion at the National Laboratories Information Technology Summit ’25 will include the genesis of the CoE, stated goals, organizational structure, and the effort to attract OT subject matter experts to join the CoE effort to share knowledge and expertise. The discussion will include opportunities to get involved and contribute to this important effort. This session will be led by CoE for OT Co-Chairs Matt Kwiatkowski, Fermi National Laboratory Chief Information Security Officer, and Steven Weldon, Savannah River National Laboratory Cyber Program Director at the Georgia Cyber Center. The session will be of particular interest to CIOs, CTOs, CISOs, as well as IT and OT practitioners.

Kwiatkowski, Matt [Fermilab]↗

Clean Energy Cybersecurity Accelerator Cohort 1: Authentication and Authorization

In the 2023 National Cybersecurity Strategy, the Biden-Harris Administration defines the need for a "defensible, resilient digital ecosystem where it is costlier to attack systems than defend them." The strategy cites the Clean Energy Cybersecurity Accelerator (CECA) as an exemplary effort to bolster the security and resilience of clean energy generation. These efforts help "secure the clean energy grid of the future and [generate] security best practices that extend to other critical infrastructure sectors" and promise broad and far-reaching impacts to bridge the capabilities of private industry and the needs of energy production. Cohort 1 of CECA launched in the fall of 2022 with a focus on solutions that provide strong authentication and authorization for industrial control systems to mitigate attacks on the energy grid. Authentication and authorization verify that the identity (authentication) and permissions (authorization) of a user or device are aligned with their assigned roles. Weaknesses in either can have serious repercussions. To assess the strength of Cohort 1's solutions, CECA devised threat scenarios grounded in historical precedents: the CECA team reviewed exploits from real-world case studies of state-sponsored actors to match the assessment's attack paths and targets. Cohort 1 results provided the energy industry, product vendors, and related agencies valuable insights into the efficacy and applicability of solutions in common system configurations under realistic threat scenarios. The results of the assessment highlight points for interrogation and improvement in subsequent technology iterations. CECA's evaluations are part of an ongoing conversation and collaboration to bolster U.S. cyber resilience against adversaries today and in the future.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Design and Development of a High Fidelity Cyber-Physical Testbed

In order to ensure that future critical infrastructure systems are resilient to various types of such advanced and persistent threats, it is important to develop and integrate tailored solutions that holistically address cyber-attack detection and mitigation in a timely manner such that adverse system impacts that impact a large population are avoided. Further, it is essential to create environments that allow control, protection and communication to exist within a realistic environment to analyze the effects of adverse conditions and system operating modes. This project aims to establish a high-fidelity testbed environment for modeling and simulating a single microgrid all the way up to a network of microgrids along with baseline controls, protection, and associated cyber communication. This is an important activity because accurately modeling and simulating the various power-electronics-based DERs and loads in a microgrid is critical to adequately capturing their behaviors over a wide range of off-normal conditions, as well as to evaluate the resilience of the system using the developed controls. The work presented in this report focuses on the process of building this high-fidelity testbed and the associated experimentation it enables. The model enables the creation of high-fidelity use cases and associated datasets that have been used extensively within the initiative to study resilience and support novel control development and prototyping. The work heavily leverages existing capability that is part of the high-fidelity cyber-physical system experimentation lab to create a power hardware-in-the-loop setup. The report also details the creation of an automated model building platform that can enable high-fidelity real-time models to be built without much effort allowing existing low-fidelity models to be analyzed in higher fidelity. Lastly, the report also discusses efforts center around scaling to large complex power system models to make the experimentation more effective.

97 MATHEMATICS AND COMPUTING↗

Analytical Tools to Assess Polymer Biodegradation: A Critical Review and Recommendations

Many petroleum-derived plastic materials are highly recalcitrant and persistent in the environment, posing significant threats to human and ecological receptors due to their accumulation in ecosystems. In recent years, research efforts have focused on advancing biological methods for polymer degradation. Enzymatic depolymerization has emerged as particularly relevant for biobased plastic recycling, potentially scalable for industrial use. Biodegradation involves adsorption to the plastic solid surface, followed by an interfacial reaction, resulting in cleavage of bonds of polymer chains exposed on the surface. Here, widely varying substrate-specific kinetics are observed, with the polymer’s properties possessing a significant impact on the rate of this interfacial catalysis. Thus, there is a critical need for sensitive and accurate characterization of the material surface during and after interfacial depolymerization to fully understand the reaction mechanisms. Here, we provide a critical review of a range of techniques used in the analysis of material surfaces to characterize the chemical, topological, and morphological features relevant to the study of enzymatic biocatalysis, including microscopy techniques, spectroscopic techniques (e.g., X-ray diffraction analysis, Fourier transform infrared attenuated total reflectance spectroscopy, and mass spectrometry detection of analytes associated with degradation). Techniques for evaluation of surface energy and topology in their relevancy for sensitive detection of biological surface modifications are also discussed. In addition, this paper provides an overview of the strengths of these techniques and compares their performance in both sensitivity and throughput, including emerging techniques, which can be useful, particularly for the rapid analysis of the surface properties of polymeric materials in high-throughput screening of candidate biocatalysts. This research serves as a starting point in selecting and applying appropriate methodologies that provide direct evidence to the ongoing biotic degradation of polymeric materials.

Colachis, Matthew↗

Agnostic capture of pathogens for the detection and diagnostics of emerging threats

The continued emergence of pathogens, whether novel, re-emerging, or engineered, poses a persistent global biosecurity and public health challenge. Recent outbreaks, including COVID-19, Lassa fever, Marburg virus, mpox, and avian influenza, underscore the urgent need for robust systems that enable rapid surveillance, early diagnosis, and timely countermeasures before widespread human transmission occurs. In this article, we focus on early detection technologies and systematically evaluate current diagnostic and sensing modalities. We highlight sequencing and spectroscopy as two complementary approaches capable of providing broad, agnostic detection and rich biological insight. Our analysis emphasizes that scientific innovation alone is insufficient: effective preparedness also requires improved data curation, integration, and sharing to build AI-ready resources that accelerate future responses. We argue for coordinated advances in both technological capabilities and supporting infrastructure to enable the rapid identification and characterization of emerging pathogens and to fully leverage modern science against evolving infectious threats.

Environmental health↗

Hurricanes and turbulent floods threaten arsenic-contaminated coastal soils and vulnerable communities

Coastal environments, particularly those adjacent to Superfund sites, are at increased risk of contaminant release during natural disasters, posing serious threats to nearby communities. To investigate this issue, we employed an advanced laboratory flood simulator to impose arsenic-contaminated sediments to turbulent flooding events. We further monitored changes in arsenic collocation and solid-phase speciation using advanced synchrotron radiation-based techniques to understand the impacts of flooding on arsenic mobility. Our results demonstrate that turbulent conditions significantly enhance the resuspension of arsenic-rich sediments, resulting in increased arsenic release into the water. This mobilization is driven by the erosion of the reduced sediments and the redox-mediated transformation and dissolution of Fe and Mn (oxyhydr) oxides, which promote the release of As(III). We found that arsenic speciation on resuspended particles is closely tied to shear stress, with As(V) prevailing at low stress and the more toxic As(III) dominating at higher stress levels. In the post-erosion phase, solid-phase As(III) decreased while dissolved As(III) increased, indicating ongoing desorption. The persistence of multiple arsenic species on resuspended particles marks them as potential long-range transport vectors. Thus, the environmental impact of flooding and sediment resuspension extends beyond the event itself, raising longer-term concerns for arsenic mobility. Our comprehensive geospatial analysis revealed substantial overlap between arsenic-contaminated soils and regions at high risk of flooding and hurricanes across the conterminous United States. This overlap disproportionately impacts economically disadvantaged and marginalized communities. Approximately 40 million Americans reside within 10 kilometers of these high-risk contaminated zones, with nearly 28 million exposed to hurricane threats and around 18 million vulnerable to flooding risks. Alarmingly, over 40% of those affected by hurricanes and 33% of those impacted by flooding belong to underrepresented minority and low-income populations. These findings highlight the urgent need for targeted mitigation strategies to protect public health and address environmental justice concerns.

54 ENVIRONMENTAL SCIENCES↗

We Must Stop Fossil Fuel Emissions to Protect Permafrost Ecosystems

Climate change is an existential threat to the vast global permafrost domain. The diverse human cultures, ecological communities, and biogeochemical cycles of this tenth of the planet depend on the persistence of frozen conditions. The complexity, immensity, and remoteness of permafrost ecosystems make it difficult to grasp how quickly things are changing and what can be done about it. Here, we summarize terrestrial and marine changes in the permafrost domain with an eye toward global policy. While many questions remain, we know that continued fossil fuel burning is incompatible with the continued existence of the permafrost domain as we know it. If we fail to protect permafrost ecosystems, the consequences for human rights, biosphere integrity, and global climate will be severe. The policy implications are clear: the faster we reduce human emissions and draw down atmospheric CO 2 , the more of the permafrost domain we can save. Emissions reduction targets must be strengthened and accompanied by support for local peoples to protect intact ecological communities and natural carbon sinks within the permafrost domain. Some proposed geoengineering interventions such as solar shading, surface albedo modification, and vegetation manipulations are unproven and may exacerbate environmental injustice without providing lasting protection. Conversely, astounding advances in renewable energy have reopened viable pathways to halve human greenhouse gas emissions by 2030 and effectively stop them well before 2050. We call on leaders, corporations, researchers, and citizens everywhere to acknowledge the global importance of the permafrost domain and work towards climate restoration and empowerment of Indigenous and immigrant communities in these regions.

54 ENVIRONMENTAL SCIENCES↗

Autonomous System Subversion Tactics: Prototypes and Recommended Countermeasures

One of the fielding requirements for Advanced and Small Modular Reactors (AR/SMR) is the ability to support remote and autonomous operations. Autonomous Control Systems (ACS) are found on platforms such as Autonomous Space Vehicles, Cruise Missiles, and advanced driver-assistance systems. Each of these ACS implementations depends upon a set of decision support subsystems responsible for supporting Autonomous Mission Managers (names vary based upon field and author preferences). These Autonomous Mission Managers receive inputs from system sensors (e.g., LIDAR collection from an automobile travelling down a street; transients from a nuclear reactor), and perform a set of classifications (e.g., Red Traffic Light; Small Pedestrian at 10m; Load Rejection; Single Coolant Pump Trip), and then use these classifications in combination with recommendation algorithms to achieve platform goals (e.g., Stop the Vehicle at the Traffic Light, Avoid the Small Pedestrian; Trip the Reactor to prevent a Safety Event). The design, implementation, and fielding of an ACS capability will alter the cyber-attack surface such that existing risk management plans will need to be updated to include how to protect and defend against data-science and decision-support-system attack classes. These attack classes would include protection of the design and training environments where algorithm selection and testing and training data would be obvious attack vectors. These attack classes would also require an informed set of detection and response procedures to identify anomalous behaviors and document best practices for anomaly assessment and vulnerability mitigation and remediation. Last year we published a Cyber Threat Assessment Methodology for Autonomous and Remote Operations for AR/SMRs along with a companion publication on Cyber Attack and Defense Use Cases. The focus of the methodology was on describing and enumerating ACS processes, components, and functions such that security engineers could: evaluate subversion options against the target; identify threat actor attributes and capabilities derived from each subversion option; and identify security controls and response countermeasures. The Use Cases document offered detailed methodology examples including an assessment of a Military Base SMR, an Autonomous System Decision Loop, and implementation of AR/SMR Machine Learning algorithms. Our proposal at the end of last year was to focus on implementation of subversion prototypes related to the last Use Case area: AR/SMR Machine Learning (ML) Algorithms. We included six attack scenarios in our Use Cases paper: a Poisoning Attack against ML functions implemented using an FPGA; a Trojaning Attack against ML classifiers exploiting the excitability of Nuclear Engineers; a Backdooring Attack against ML Training environments to ensure persistence of an attack vector; a False Positive Evasion Attack against multi-factor Access Control Systems using clever inputs; an Inference Attack against ML models by an Insider with access to the Operational environment; and an Adversarial Reprogramming Attack against a Material Access Control Video Surveillance System. At the beginning of this year these six attack scenarios were provided to our research teams at Georgia Tech and Idaho State University and each team successfully implemented a subversion attack against a ML implementation to include transient misclassifications. While this is a notable outcome from this type of research, this paper offers the reader insight into not only how to structure and execute these types of attacks, but into the thought process behind how the researcher investigated the problem space, performed initial algorithm implementation, and the trial-and-error behind arriving at the successful subversion prototypes. We include in this paper a set of associated Scenarios on how these subversion prototypes could be implemented and an initial set of guidance for AR/SMR architects, Nuclear Regulators, and Cyber Defenders to implement awareness and defense capabilities into their current operational portfolios.

42 ENGINEERING↗

Gut microbiota carbon and sulfur metabolisms support Salmonella infections

Abstract Salmonella enterica serovar Typhimurium is a pervasive enteric pathogen and ongoing global threat to public health. Ecological studies in the Salmonella impacted gut remain underrepresented in the literature, discounting microbiome mediated interactions that may inform Salmonella physiology during colonization and infection. To understand the microbial ecology of Salmonella remodeling of the gut microbiome, we performed multi-omics on fecal microbial communities from untreated and Salmonella-infected mice. Reconstructed genomes recruited metatranscriptomic and metabolomic data providing a strain-resolved view of the expressed metabolisms of the microbiome during Salmonella infection. These data informed possible Salmonella interactions with members of the gut microbiome that were previously uncharacterized. Salmonella-induced inflammation significantly reduced the diversity of genomes that recruited transcripts in the gut microbiome, yet increased transcript mapping was observed for seven members, among which Luxibacter and Ligilactobacillus transcript read recruitment was most prevalent. Metatranscriptomic insights from Salmonella and other persistent taxa in the inflamed microbiome further expounded the necessity for oxidative tolerance mechanisms to endure the host inflammatory responses to infection. In the inflamed gut lactate was a key metabolite, with microbiota production and consumption reported amongst members with detected transcript recruitment. We also showed that organic sulfur sources could be converted by gut microbiota to yield inorganic sulfur pools that become oxidized in the inflamed gut, resulting in thiosulfate and tetrathionate that support Salmonella respiration. This research advances physiological microbiome insights beyond prior amplicon-based approaches, with the transcriptionally active organismal and metabolic pathways outlined here offering intriguing intervention targets in the Salmonella-infected intestine.

59 BASIC BIOLOGICAL SCIENCES↗