Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security study”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

Shifting Left for Machine Learning: An Empirical Study of Security Weaknesses in Supervised Learning-based Projects

Context: Supervised learning-based projects (SLPs), i.e., software projects that use supervised learning algorithms, such as decision trees are useful for performing classification-related tasks. Yet, security weaknesses, such as the use of hard-coded passwords in SLPs, can make SLPs susceptible to security attacks. A characterization of security weaknesses in SLPs can help practitioners understand the security weaknesses that are frequent in SLPs and adopt adequate mitigation strategies. Objective: The goal of this paper is to help practitioners se-curely develop supervised learning-based projects by conducting an empirical study of security weaknesses in supervised learning-based projects. Methodology: We conduct an empirical study by quantifying the frequency of security weaknesses in 278 open source SLPs. Results: We identify 22 types of security weaknesses that occur in SLPs. We observe ‘use of potentially dangerous function’ to be the most frequently occurring security weakness in SLPs. Of the identified 3,964 security weaknesses, 23.79 % and 40.49 % respectively, appear for source code files used to train and test models. We also observe evidence of co-location, e.g., instances of command injection co-locates with instances of potentially dangerous function. Conclusion: Based on our findings, we advocate for a shift left approach for SLP development with security-focused code reviews, and application of security static analysis.

Bhuiyan, Farzana Ahamed↗

A Nuclear Security Enterprise Study of High-Reliability Systems, Collaboration, and Data

It may seem simple and trivial, but defining the difference between data and information is contested and has implications that may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and controlling them. Control is necessary to ensure that data and information are not inadvertently released to foreign governments, the public, or those without Need-to-Know. A primary concern in the practice of security is the control of data to avoid the inadvertent conversion to sensitive information. The complexity of this concern is further augmented when institutions are part of tightly coupled networks that informally share data and information. Additionally, those that share data as a function of legislative action—and/or formally integrate data and information system infrastructures—may be a higher security risk. This paper will present a case study that utilizes elements of literature from Knowledge Management and networks to tell a story of an issue in security—specifically, controlling the conversion of data to information.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

National Security & International Studies (Q1 FY2021 Newsletter)

Happy New Year to everyone. Activity in the office continues to be at a high pace with the addition of the Strategic Analyses and Assessments (SAA) Office from ALDX, and the Mission Integration (MI) Office (formerly known as Nuclear and Military [NMA] Office) from DDW. We are working closely to optimize the impact of our combined offices. In this issue of our newsletter, we will highlight programs from the SAA Office portfolio, delve into our interactions with the Project on Nuclear Issues (PONI) program from CSIS, introduce you to new staff in NSIS and review a new joint postdoc program with the UC Institute on Global Conflict and Cooperation and the Center for Global Security Research at LLNL. I also encourage you to take a look at the new NSIS website for more information on the office. Finally, the NSIS office will soon be kicking off a webinar series on starting with topics of interest to the Director’s Strategic Resilience Initiative and will grow beyond that. Stay tuned for more information. --John Scott, Acting Office Director, NSIS

99 GENERAL AND MISCELLANEOUS↗

Machine Learning Solutions for a Stable Grid Recovery

Grid operating security studies are typically employed to establish operating boundaries, ensuring secure and stable operation for a range of operation under NERC guidelines. However, if these boundaries are severely violated, existing system security margins will be largely unknown, as would be a secure incremental dispatch path to higher security margins while continuing to serve load. As an alternative to the use of complex optimizations over dynamic conditions, this work employs the use of machine learning to identify a sequence of secure state transitions which place the grid in a higher degree of operating security with greater static and dynamic stability margins. Several reinforcement learning solution methods were developed using deep learning neural networks, including Deep Q-learning, Mu-Zero, and the continuous algorithms Proximal Reinforcement Learning, and Advantage Actor Critic Learning. The work is demonstrated on a power grid with three control dimensions but can be scaled in size and dimensionality, which is the subject of ongoing research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Investigate the Security of Electric Vehicle (EV) Ecosystem Applications

Apps that run on mobile devices are one of critical components of the electric vehicle (EV) ecosystem and pose possible threat actor points of entry that may impact the trust and security of EV charging systems in the future. Mobile apps often rely on communication between cloud servers and users, thereby creating potential points of entry for cyberattacks. Although app stores such as Apple App Store or Google Play Store generally test the security of apps, the cyber aspects may not be sufficient for many entities including DOD, federal fleets, and commercial entities. A more thorough inspection and the ability to influence developers is imminently needed. This research studies security attributes and vulnerabilities of a sample of mobile applications that support key user functions in the EV ecosystem. The study shows that all analyzed apps have security risks, categorized as either high or medium or both and a comprehensive cybersecurity guideline for developing mobile apps is necessary.

33 ADVANCED PROPULSION SYSTEMS↗

Integrated Security-Safety Consequence Study of a Heat Pipe Reactor

This report presents a preliminary demonstration of integrated security/safety consequence modeling to support potential physical security exemption justifications under the new Title 10 Code of Federal Regulations Part 53 licensing pathway, which allows exemptions if sabotage-induced radiological consequences do not exceed 25 rem at the site boundary two hours after release without mitigative actions. A hypothetical heat pipe microreactor subjected to direct sabotage by a 150 lbs. TNT-equivalent high-explosive device was analyzed using a simplified radionuclide release estimate based on DOE-HDBK-3010-94, implemented in the MELCOR severe accident analysis code to model release transport and attenuation through reactor/building compartments, with MELCOR outputs coupled to MACCS to compute offsite doses and the distance-to-threshold metric D 25rem . Six scenarios were evaluated to examine sensitivities to release pathway/building configuration and radionuclide form (vapor versus aerosols with different size distributions). Results show a positive correlation between leak path factor and D 25rem and indicate that reactor building compartmentalization can substantially reduce consequences (a single-story configuration reduced D 25rem by roughly an order of magnitude relative to a cavity-only configuration), while vapor versus aerosol assumptions had limited impact for the modeled two-story case on the spatial grid used.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Trace explosives sampling for security applications (TESSA) study: Evaluation of procedures and methodology for contact sampling efficiency

We report the detection of trace amounts of explosive materials is critical to the security at mass transit centers (e.g., airports and railway stations). In a typical screening process, a trap is used to probe a surface of interest to collect and transfer particulate residue to a detector for analysis. The collection of residues from the surface being probed is widely viewed as the limiting step in this process. A multi-institutional study was performed to establish a methodology for the evaluation of sampling media collection efficiencies. Dry deposited residues of 1,3,5-trinitroperhydro-1,3,5-triazine (RDX), C-4 (an RDX-based explosive), and pentaerythritol tetranitrate (PETN) were harvested from acrylonitrile butadiene styrene (ABS) plastic, ballistic nylon (NYL), and uncoated aluminum surfaces using muslin, Texwipe cotton, and stainless-steel mesh traps. Transfer and collection efficiencies of the sample media were calculated based on liquid chromatography-mass spectrometry analysis. Dry transfer efficiencies (DTE%) to all tested surfaces were greater than 75%, with transfer to ABS plastic being the lowest. Collection efficiency (CE%) varied significantly across the traps and the surfaces, yet some conclusions can be drawn; nylon had the lowest CE% for all cases (~10%), and the stainless steel mesh had the lowest CE% for the evaluated traps (~20%). Though the testing parameters have been standardized among the participants to establish a framework for an independent comparison of contact sampling media and surfaces, substantial variations in the DTE% and the CE% were observed, suggesting that other variables can affect contact sampling.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

A Review of Visualization Methods for Cyber-Physical Security: Smart Grid Case Study

Cyber-Physical Systems (CPSs) are becoming increasingly complex and interconnected as they attempt to meet the demands of evolving society. As a result, monitoring and maintaining them becomes a more complex and demanding task for control system operators and cyber defenders. While the literature on visualization techniques in the context of cybersecurity is extensive, the same cannot be said for studies on visualization for the security of cyber-physical systems. This paper aims to fill that gap by: 1) defining the main features of a visualizations workflow for security visualizations in cyber-physical systems. The workflow includes the acquisition of cyber and physical data, processing of data, selection, and configuration of both visualization tools and end-user interactions. 2) Providing an overview of cyber-physical security visualization systems, with a focus on smart grids as a case study. Finally, we use the perspectives gained from this analysis to provide insights and directions for future research and design of cyber-physical visualization techniques.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Measuring Equality in Machine Learning Security Defenses: A Case Study in Speech Recognition

Over the past decade, the machine learning security community has developed a myriad of defenses for evasion attacks. An understudied question in that community is: for whom do these defenses defend? This work considers common approaches to defending learned systems and how security defenses result in performance inequities across different sub-populations. We outline appropriate parity metrics for analysis and begin to answer this question through empirical results of the fairness implications of machine learning security methods. We find that many methods that have been proposed can cause direct harm, like false rejection and unequal benefits from robustness training. The framework we propose for measuring defense equality can be applied to robustly trained models, preprocessing-based defenses, and rejection methods. We identify a set of datasets with a user-centered application and a reasonable computational cost suitable for case studies in measuring the equality of defenses. In our case study of speech command recognition, we show how such adversarial training and augmentation have non-equal but complex protections for social subgroups across gender, accent, and age in relation to user coverage. We present a comparison of equality between two rejection-based defenses: randomized smoothing and neural rejection, finding randomized smoothing more equitable due to the sampling mechanism for minority groups. This represents the first work examining the disparity in the adversarial robustness in the speech domain and the fairness evaluation of rejection-based defenses.

• Artificial intelligence (AI) / machine learning ↗

Building Blocks for Secure and Prosperous Defense Critical Supply Chains: A Case Study from Microelectronics

Securing defense-critical supply chains, built on resilient and sustainable microelectronics fabrication and deployment, is a national imperative and one that requires an investment in basic and applied research, development, and deployment into industries in (and out of) the Defense Industrial Base (DIB). Critical next steps include the development of pilots for revolutionary concepts in a new formal verification model and the Cyber-Physical Passport (CPP) concept for chain of custody. Critical infrastructure leadership should take action with a sense of urgency. Working in conjunction with the Under Secretary for Acquisition and Sustainment, the Assistant Secretary of Defense for Research and Engineering should establish pilot programs with the Defense Advanced Research Projects Agency and the service labs to build and test both concepts in legacy and new system development.. Additionally, the Pentagon may be aware that an existing Manufacturing Innovation Institute is piloting, with the semiconductor industry, cyber innovations to provide verifiable security properties and guarantees of physical functions to build a more cyber secure, resilient and efficient micro-electronics supply chain.

99 GENERAL AND MISCELLANEOUS↗

Joint scheduling of energy, fast and primary frequency response reserves in integrated transmission–distribution networks

Inverter-based distributed energy resources (DERs) connected to distribution networks (DNs) can provide fast frequency support, but their reserve deliverability depends on feeder constraints and differs from synchronous primary frequency response (PFR). Existing transmission–distribution coordination studies usually treat reserve generically or neglect feeder-level feasibility, while frequency-security scheduling studies rarely represent distribution feeders explicitly. This paper develops a bi-level day-ahead scheduling framework for integrated transmission–distribution networks that jointly clears energy, transmission-side PFR, and distribution-side fast frequency response (FFR) under exogenous hourly inertia and largest-loss inputs from an external unit commitment (UC) schedule. The transmission problem is modeled with DC-optimal power flow (OPF) and closed-form second-order cone (SOC) frequency-security constraints, whereas each DN is represented by a reserve-aware branch-flow AC-OPF so that scheduled fast reserves remain deliverable during activation. The bi-level problem is reformulated through Karush–Kuhn–Tucker (KKT) conditions into a mixed-integer SOC program, and a penalty term is used to tighten the distribution-network relaxation. In the reduced test system, lower exogenous inertia increased the required primary response from 179.64 MW to 191.08 MW, distribution-side fast response reduced total frequency-response procurement by up to 4.9%, and neglecting distribution constraints overstated the combined distribution-side energy and reserve award by up to 18%. In the expanded study, the largest case was solved in 2.02 s with a 0.00% optimality gap. Time-domain simulations kept the frequency nadir above 59.0 Hz in all tested hours. These results demonstrate the value of fast-response modeling and distribution-feasible reserve delivery in coordinated market clearing.

Noh, Seung-Gil↗

Vulnerability Assessments for Power-Electronics-Based Smart Grids

Here, in this paper, a novel method is proposed to evaluate the cyber security of the power-electronics-based smart grids (PESG). The proposed method considers the performance and stability of both the individual inverter and the grid. To our knowledge, this is a first attempt to evaluate the performance and stability of PESG due to cyber attacks. We first develop impedance-based modeling and cyber-attack modeling for PESG. Then we propose innovative two security criteria to evaluate the security of PESG, including stability-based and metrics-based. For metrics-based criteria, we propose to use both total harmonic distortion (THD) and space phasor model (SPM) to evaluate the inverter performance. The simulation results with a two-inverter-based power grid verify the validity and accuracy of the proposed security evaluation method. Results have shown that the performance and stability of PESG are significantly affected by cyber attacks, and thus there is indeed a need to further study cyber security issues of PESG.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Bennett-Brassard 1984 quantum key distribution using conjugate homodyne detection

Optical homodyne detection has been widely used in continuous-variable (CV) quantum information processing for measuring field quadrature. In this paper we explore the possibility of operating a conjugate homodyne detection system in “photon counting” mode to implement discrete-variable (DV) quantum key distribution (QKD). A conjugate homodyne detection system, which consists of a beam splitter followed by two optical homodyne detectors, can simultaneously measure a pair of conjugate quadratures X and P of the incoming quantum state. In classical electrodynamics, X 2 + P 2 is proportional to the energy (the photon number) of the input light. In quantum optics, X and P do not commute and thus the above photon-number measurement is intrinsically noisy. This implies that a blind application of standard security proofs of QKD could result in pessimistic performance. We overcome this obstacle by taking advantage of two special features of the proposed detection scheme. First, the fundamental detection noise associated with vacuum fluctuations cannot be manipulated by an external adversary. Second, the ability to reconstruct the photon number distribution at the receiver's end can place additional constraints on possible attacks from the adversary. As an example, we study the security of the BB84 QKD using conjugate homodyne detection and evaluate its performance through numerical simulations. This study may open the door to a family of QKD protocols, complementary to the well-established DV-QKD based on single-photon detection and CV-QKD based on coherent detection.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Multi-level optimization with the koopman operator for data-driven, domain-aware, and dynamic system security

Cyber-Physical Systems (CPSs) like the power grid are critically important but also increasingly vulnerable; ensuring reliable system operation in the face of disruptions is becoming more and more challenging. Multi-Level Optimization (MLO) is a powerful way to model adversarial interactions, which naturally makes it applicable to studying CPS security. However, MLO typically does not address underlying system dynamics, and incorporating nonlinear dynamics is generally infeasible. In this paper, we show how to combine MLO with the Koopman Operator (KO) to remedy this. The KO maps nonlinear dynamics to a lifted space in which those dynamics are linear, thus making it ideal for use with MLO. Moreover, the structure of the KO also provides convenient ways to incorporate domain knowledge into the data-driven process of learning the KO representation of a given system. Here we then demonstrate the use of MLO-KO on a small example problem taken from the power grid domain, discuss the scalability and computational cost of MLO-KO, and identify future research directions for this work.

42 ENGINEERING↗

Foundations of Rigorous Cyber Experimentation

This report presents the results of the “Foundations of Rigorous Cyber Experimentation” (FORCE) Laboratory Directed Research and Development (LDRD) project. This project is a companion project to the “Science and Engineering of Cyber security through Uncertainty quantification and Rigorous Experimentation” (SECURE) Grand Challenge LDRD project. This project leverages the offline, controlled nature of cyber experimentation technologies in general, and emulation testbeds in particular, to assess how uncertainties in network conditions affect uncertainties in key metrics. We conduct extensive experimentation using a Firewheel emulation-based cyber testbed model of Invisible Internet Project (I2P) networks to understand a de-anonymization attack formerly presented in the literature. Our goals in this analysis are to see if we can leverage emulation testbeds to produce reliably repeatable experimental networks at scale, identify significant parameters influencing experimental results, replicate the previous results, quantify uncertainty associated with the predictions, and apply multi-fidelity techniques to forecast results to real-world network scales. The I2P networks we study are up to three orders of magnitude larger than the networks studied in SECURE and presented additional challenges to identify significant parameters. The key contributions of this project are the application of SECURE techniques such as UQ to a scenario of interest and scaling the SECURE techniques to larger network sizes. This report describes the experimental methods and results of these studies in more detail. In addition, the process of constructing these large-scale experiments tested the limits of the Firewheel emulation-based technologies. Therefore, another contribution of this work is that it informed the Firewheel developers of scaling limitations, which were subsequently corrected.

97 MATHEMATICS AND COMPUTING↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗