Search NASA⌕ Search

SEARCH · Search NASA

Results for “CyberSecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Integrating a Microgrid Controller with a Local OpenADR Server

When military microgrids isolate themselves from the main electrical grid, they must locally balance electricity supply and demand. Since local generation may be limited, the current strategy is to shed all but the most critical loads by tripping smart circuit breakers, which must then be reset manually (e.g., ESTCP project EW-201350). This strategy is typically applied at the building level, meaning that entire buildings housing mission critical activities must be excluded from any load management, while those considered non-critical may lose service entirely. The remotely controlled switchgear needed to manage load in this way is very expensive ($\$30,000$-$\$50,000$ per building). While effective at shedding load, this strategy disrupts installation operation and risks damaging equipment during both disconnection and re-energization. With the goals of lowering costs, protecting equipment, and enhancing the agility of DoD microgrids, this report demonstrates the use of cybersecure automated demand response (ADR) technology to manage microgrid loads during grid-independent (a.k.a. "islanded") operation. This automated approach achieves load shedding and shifting through communication signals sent to equipment controllers rather than by cutting off the flow of electricity within the microgrid itself. Because it operates only on the base network, with no connection to external entities, this strategy avoids the main cybersecurity concern raised by past applications of ADR on military bases.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗

Planning Roadmap for DER Integration in India: Industry Best Practices and Resource Guide

Ensuring safe, reliable, cost-effective DER integration at scale requires holistic planning, broad stakeholder engagement, and should address key development areas such as standards adoption, equipment testing and certification, interoperability and cybersecurity, interconnection procedures, and advanced forecasting and DER management. Each of these areas currently represent significant challenges for utilities, regulators, OEMs, developers, and even consumers worldwide. India has already seen significant growth of DERs and has announced targets for substantial growth yet to come, with the potential for DERs to make up a non-negligible portion of the country's overall generation capacity. As such, it is of critical importance that Indian stakeholders consider the potential impacts of wide-spread adoption of DERs and take preemptive action related to the five development areas listed here, among others. India should consider strategies including the adoption of key DER standards related to interconnection, testing, and cybersecurity; enabling effective and secure communication channels for DER interoperability; testing and certifying DER equipment in accredited testing laboratories; building robust, streamlined interconnection procedures; and revamping legacy system planning structures to incorporate DERs in a holistic planning framework.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems may become more widely deployed throughout the country, and so it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity of the facility, and the company that owns the facility. The two main ways bad actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when companies conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks associated with a generic hydrogen storage system by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Resilient Energy Delivery and Control Systems (REDCS) (Final Technical Report)

US critical infrastructure is increasingly the target of cyberattacks, where disturbances could cause considerable damage and disruption. To help provide a new layer of cyber-physical protection for one key energy delivery system, natural gas pipelines, GE Vernova Advanced Research along with partners Florida State University and Intel Corporation created an innovative technology called "Resilient Energy Delivery and Control Systems" (REDCS). This cybersecurity package helps detect anomalies caused by cyberattacks, isolate the subsystem being impacted by the attack, and provide functions that can allow for resiliency – giving better situational awareness to the operators and cybersecurity specialists or in the future perform closed loop control for continued operation while compromised.

03 NATURAL GAS↗

Utility-Scale Operational Consequences for Solar Grid Services

This report delves into the critical aspects of grid services provided by solar inverter-based resources (IBRs), with an emphasis on the evolving landscape of microgrids, virtual power plants (VPPs), aggregators, and distributed energy resource management systems (DERMS). As the energy sector undergoes a transformative shift towards more decentralized and resilient grid architectures, understanding the multifaceted risks associated with these technologies becomes paramount. The report categorizes these risks into organizational, technical, and procedural domains, providing a thorough risk assessment framework that stakeholders can utilize to anticipate and mitigate potential issues. In addressing the increasing complexity of grid interconnections, the report highlights the importance of Cyber-Informed Engineering (CIE). By embedding engineering controls and cybersecurity measures into the early stages of system design, this approach aims to fortify grid infrastructure against emerging cyber threats. The analysis includes an exploration of best practices and strategies for integrating CIE principles to enhance grid security and resilience. To provide practical insights, the report conducts a detailed consequence analysis of various grid services and cyber mitigations that can be applied through the interconnection process. This analysis evaluates the potential impacts of different failure modes and vulnerabilities, offering a clear understanding of the consequences that could arise from disruptions within the energy grid. The findings are further enriched by a series of case studies that illustrate real-world scenarios and lessons learned from past incidents. Through this comprehensive examination of grid services and their criticality, the report aims to prepare industry professionals with the knowledge and tools necessary to navigate the complexities of modern energy systems. By providing a comprehensive approach that includes risk assessment, cybersecurity, and consequence analysis, solar stakeholders can more effectively guarantee the reliability, efficiency, and security of the energy grid.

14 SOLAR ENERGY↗

Secure and Resilient Operations Using Open-Source Distributed Systems Platform (OpenDSP)

The goal of this project is to identify and address cybersecurity gaps by developing a multi-layer multi-channel cyber-physical defense and survival mechanism for operating distribution networks with high penetration of solar / inverter-based resource (IBR) / distributed energy resource (DER). The proposed security enhancements are built upon the distributed framework and solution architecture for both information technology (IT) and operational technology (OT) systems. The technical solutions consist of two composite functionalities and six layers: proactive defense (vulnerability assessment, communication protection, and attack detection, as layers 1-3), and adaptive self-healing (attack-resilient control, adaptive recovery, and resilient survival, as layers 4-6). These layers, built on and extended from DHS CISA Cyber Framework, establish an integrated and robust cybersecurity framework for operating large-scale distribution networks.

14 SOLAR ENERGY↗

Countering Weapons of Mass Destruction (CWMD) Zero Trust Framework: CWMD Zero Trust Principles Model

The research focuses on the critical need for enhanced cybersecurity within the Countering Weapons of Mass Destruction (CWMD) Office, specifically targeting Chemical, Biological, Radiological, and Nuclear devices. Traditional perimeter-based security models are insufficient against modern cyber threats, prompting a shift toward Zero Trust principles (ZTP) that emphasize continuous verification and stringent security for all devices. Federal directives mandate the adoption of Zero Trust (ZT) across agencies, supported by guidelines from National Institute of Standards and Technology (NIST), U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Defense (DoD) and National Security Agency (NSA). The research involved mapping ZT guidance from these agencies to develop tailored CWMD ZTP. The study identified gaps and areas for improvement, including clear transitional guidance from traditional to ZT architectures and the focus on explicit cross cutting capabilities. Design improvements are recommended to ensure increased comprehensive protection and resilience against sophisticated cyber threats for Chemical, Biological, Radiological, and Nuclear (CBRN) devices. Collaborative efforts among federal agencies are essential for the successful deployment of an optimized ZT guidance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Aggregation and Grid Security Workshop Report

The Aggregation and Grid Security Workshop - held on June 17-18, 2025, National Laboratory of the Rockies (NLR) in Golden, Colorado - brought together approximately 40 external stakeholders from the energy sector, including VPP owner/operators, aggregators, OEMs, utilities, testing & certification labs, trade associations, and cybersecurity vendors. Led by key facilitators, the workshop focused on addressing cybersecurity challenges and enhancing grid resilience for aggregated Distributed Energy Resources (DERs) and Virtual Power Plants (VPPs). The workshop was catalyzed by recognition that traditional, rearward-looking regulatory frameworks are insufficient to keep pace with technological change. There is a "missing understanding" of risk, an "absent security basis" for managing it, and an "untenable responsibility" due to unclear ownership and requirements. The workshop aimed to shift the mindset from reacting to past crises to proactively preparing for emerging threats, fostering forward resilience through risk simulation and collaborative action. This report summarizes the outcomes of the workshop, marking it a significant step toward a secure, reliable and affordable energy future.

14 SOLAR ENERGY↗

Cyber Labeling for Energy Industrial IoT

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security and Emergency Response (CESER), at the request of the Deputy National Security Advisor for Cyber and Emerging Technologies, Anne Neuberger, initiated research in 2023 to develop a cybersecurity labeling proof-of-concept for energy products to expand on the Federal Communications Commission’s (FCC) proposed U.S. Cyber Trust Mark program. DOE mobilized researchers from six National Laboratories to develop and gather feedback on a proof-of concept label for solar inverters and smart meters, which serve as representative products for market-facing energy sector Industrial Internet of Things (IIoT). This report details the research team’s process across two phases and the resulting findings, which include challenges facing cyber labeling programs and recommendations to implement an expanded IIoT cyber labeling program in the U.S.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

Empirical Analysis and Automated Classification of Security Bug Reports

With the ever expanding amount of sensitive data being placed into computer systems, the need for effective cybersecurity is of utmost importance. However, there is a shortage of detailed empirical studies of security vulnerabilities from which cybersecurity metrics and best practices could be determined. This thesis has two main research goals: (1) to explore the distribution and characteristics of security vulnerabilities based on the information provided in bug tracking systems and (2) to develop data analytics approaches for automatic classification of bug reports as security or non-security related. This work is based on using three NASA datasets as case studies. The empirical analysis showed that the majority of software vulnerabilities belong only to a small number of types. Addressing these types of vulnerabilities will consequently lead to cost efficient improvement of software security. Since this analysis requires labeling of each bug report in the bug tracking system, we explored using machine learning to automate the classification of each bug report as a security or non-security related (two-class classification), as well as each security related bug report as specific security type (multiclass classification). In addition to using supervised machine learning algorithms, a novel unsupervised machine learning approach is proposed. An ac- curacy of 92%, recall of 96%, precision of 92%, probability of false alarm of 4%, F-Score of 81% and G-Score of 90% were the best results achieved during two-class classification. Furthermore, an accuracy of 80%, recall of 80%, precision of 94%, and F-score of 85% were the best results achieved during multiclass classification.

Cybersecurity↗

Cyber Threats and Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Urban Air Mobility↗

Cyber Threats & Security Controls Analysis for Urban Air Mobility Environments

Since the cyber threat landscape changes daily, cybersecurity needs to be an ongoing activity for every organization within the UAM environments. This paper will provide information on identified cyber threats and controls associated with an instance of the Urban Air Mobility (UAM) environment. The MITRE ATT&CK model and framework and the selection of cyber threats and the National Institute of Standards and Technology publications for security control identification and cybersecurity risk identification will be leveraged for analysis.

Cyber Threats↗

Simulation and Modeling Concepts for Secure Airspace Operations

With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. This paper examines cyber security vulnerabilities of Urban Air Mobility operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, thus, improving the cyber resiliency of the current and future air traffic management system.

Cybersecurity↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

Immutable Secure Data Exchange and Storage for Urban Air Mobility Environments

Urban air mobility (UAM) is a concept that proposes to develop short-range aerial vehicles to overcome increasing surface congestion. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within the UAM environment. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. To address these challenges, this research focuses on the secure data exchange and storage of this decentralized UAM environment. The intent of this research is to leverage a permissioned blockchain approach to address cybersecurity threats that may impact a UAM environment.

Urban Air Mobility↗

A Blockchain Case Study for Urban Air Mobility Operational Intent

To realize the potential of Urban Air Mobility (UAM), an assurance of cybersecurity is critical for public acceptance. UAM is a concept that proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical takeoff and landing (VTOL) aircraft to overcome increasing surface congestion. The growth in the development of UAM systems, and the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. The intent of this work is to leverage a permissioned blockchain to simulate secure data exchange and storage for the UAM operational intent use case. In this case study, two vehicle operators are operating in the same airspace. Their intent is to fly vehicles that land at a shared vertiport, securely.

Urban Air Mobility↗