Search NASA⌕ Search

SEARCH · Search NASA

Results for “CyberSecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Precursor Analysis Report: Blackmatter Ransomware Attack on New Cooperative 2021

The BlackMatter Ransomware Attack on New Cooperative 2021 Precursor Analysis Report leverages publicly available information about the New Cooperative cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The BlackMatter ransomware was first identified in July 2021 and is reported to have infected more than 50 corporations around the world. , The Iowa-based grain cooperative, New Cooperative, was impacted by the BlackMatter ransomware on or before 18 September 2021. The adversary likely resided on New Cooperative’s networks for 15 days prior to encrypting its network and demanding New Cooperative pay $5.9 million in ransom by 25 September to unlock systems and prevent 1 terabyte (TB) of sensitive data from being publicly released. It is not clear if New Cooperative paid the ransom. The full impact of the ransomware attack is not known; however, according to New Cooperative’s general manager, the attack caused the company’s automated processes to revert back to processes used in the 1970s. , As of 6 October, only 50 percent of New Cooperative’s operations were utilizing automated processes. The company took eight weeks to rebuild the entire network and information technology (IT) systems from the ground up, which puts the date of fully recovery around 13 November. Researchers and analysts identified 20 unique techniques utilized during the attack with a total of 404 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Seventeen of the identified techniques used during the New Cooperative cyber attack were precursors to the triggering event. Analysis identified 360 observables associated with these precursor techniques, 284 of which were assessed to have an increased likelihood of being perceived in the 15 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Interdisciplinary Approaches to Cyber-vulnerability Impact Assessment for Energy Critical Infrastructure

As energy infrastructure becomes more interconnected, understanding cybersecurity risks to production systems requires integrating operational and computer security knowledge. We interviewed 18 experts working in the field of energy critical infrastructure to compare what information they find necessary to assess the impact of computer vulnerabilities on energy operational technology. These experts came from two groups: 1) computer security experts and 2) energy sector operations experts. We find that both groups responded similarly for general categories of information and displayed knowledge about both domains, perhaps due to their interdisciplinary work at the same organization. Yet, we found notable differences in the details of their responses and in their stated perceptions of each group’s approaches to impact assessment. Their suggestions for collaboration across domains highlighted how these two groups can work together to help each other secure the energy grid. Our findings inform the development of interdisciplinary security approaches in critical-infrastructure contexts.

97 MATHEMATICS AND COMPUTING↗

Threats to DERs and Tools to Mitigate Them

As the pace of renewable energy development increases, so does the challenge and opportunity to develop innovative solutions to secure renewable technologies. Four national laboratories National Renewable Energy Laboratory, Sandia National Laboratories, Pacific Northwest National Laboratory, and Idaho National Laboratory are working together to increase cybersecurity maturity levels for solar stakeholders. INL will discuss a DER threat briefing and operator tools and training developed under the Securing Solar for the Grid (S2G) project.

14 SOLAR ENERGY↗

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

An Old Guys Perspective of Cyber - Journey Through INL Cyber Research

An overview of the history of cybersecurity at INL and how it has evolved with today's Critical Infrastructure, including the advancement of Electric Vehicles (EVs) and the EV charging infrastructure. Recent and future research efforts are included to demonstrate the current state of the art and where this technology might progress. With maybe a little Fear, Uncertainty, and Doubt (FUD) mixed in...

99 GENERAL AND MISCELLANEOUS↗

Summer 2024 INL Intern Poster Session Submission - Brian Schumitz

This LRS submission is my poster for the INL Intern Poster Session, Summer 2024. Abstract: The Software Engineering and Cybersecurity Lab (SECL) at Montana State University has developed PIQUE, a system for evaluating software quality. PIQUE's adaptability allows for language-specific static-analysis operations, including a model for assessing cloud microservice ecosystems. These ecosystems often rely on Docker for efficient deployment and management of containerized services. Our research focuses on evaluating the network quality within these microservice ecosystems. To automate this process, we're utilizing Snort, an open-source intrusion detection system renowned for its ability to detect and log network traffic. By leveraging Snort's customizable rules, we aim to construct comprehensive testing methods for measuring and quantifying the network quality based on traffic between Docker containers. This research aims to enhance the overall security and reliability of cloud microservice ecosystems by providing automated and robust quality evaluation mechanisms, ultimately contributing to the advancement of software engineering practices in these environments

97 MATHEMATICS AND COMPUTING↗

Field Programmable Gate Array Data Capture for Control Systems

Some Industrial Control Systems (ICS) networks are based on protocols such as Serial and Industrial Ethernet. These protocols currently have no existing cybersecurity monitoring tools, leaving a large gap in the cyber defense of critical infrastructure. In order to analyze such ICS traffic, it is first necessary to implement methods of capturing the ICS data. Whereas traditional methods of analyzing data would use microprocessors, the nature of high-speed analog data can be difficult to implement on such a versatile processor, as they are rather inefficient for doing a single task. Whereas Field Programmable Gate Arrays (FPGAs) provide an adequate tool in analyzing high speed data, as despite the lack of program versatility, Programmable Logic can implement a solution with minimal clock cycles, allowing time for each new packet of data to be captured before a new data sample is taken.

42 ENGINEERING↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Sequence-Based Anomaly Detection in Critical Infrastructure Networks

United States critical infrastructure faces new cyber threats from adversarial nation-state actors in the form of malware-free attacks. Traditional cybersecurity techniques use rules-based methods to identify indicators of compromise on networks, often missing these sophisticated attacks. Our approach leverages multiple state of the art machine learning models in a pipeline to identify abnormal network events through sequential analysis. We combine both device and packet-level information into individual events to characterize anomalous network actions. The model is trained and tested on real network traffic from the Idaho National Lab High Performance Computing (HPC) with greater than 98% precision. It is capable of flagging malicious tactics used by adversaries in malware-free attacks, severe changes to the network, and abnormal user activity by network devices.

99 - GENERAL AND MISCELLANEOUS↗

Energy Sector Threat Brief: 2024 Round Up

What major and minor cybersecurity events affected the energy sector in the last year? What trends were observed in the events, disclosure of vulnerabilities, and other headline news? This talk will focus on real-world events put in the context of an evolving geo-political landscape. We will discuss events that had operational impact as well as events affecting third-parties with exploration of how the impact of incidents is changing as more stakeholders are involved in new projects and the complexity of the modern grid. We will focus on lessons learned from the 2024 trends that operators and their partners can apply to stay ahead of the threats in 2025.

14 - SOLAR ENERGY↗

IT vs. OT: Trends and Incidents

This presentation discusses the differences between information systems (IT) and operational systems (OT) and why that difference is important in the context of cybersecurity for the energy sector.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

BESS Digital Assurance, Supply Chain Risk Management, and Emerging Regulation Session One - Abridged

The TADA BESS Supply Chain Workshops are designed to equip participants with the knowledge and tools necessary to address the evolving challenges at the intersection of battery energy storage systems (BESS), cybersecurity, and supply chain vulnerabilities. The workshops emphasize the application of Cyber-Informed Engineering (CIE) principles using INL’s procurement guide and the CIE-BAT tool. Attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their BESS projects. Additionally, the program fosters a collaborative network of practitioners and provides guidance on navigating emerging regulatory requirements, including FEOC rules under the OBBB framework, to assess and enhance organizational readiness. This is Session 1 of 3.

25 - ENERGY STORAGE↗

Large Load Integration - Task List and Overview

Large Load Integration Tasks: Task 1 – Workshops Support stakeholder engagement across industry to promote collaboration and identify solutions to challenges that will guide other work Task 2 – Ancillary Services Characterize different types of large loads to assess under what conditions they may be utilized to provide grid stability services Task 3 – Communications Explore the cybersecurity and communications infrastructure required to enable large loads to interface with grid operations to provide ancillary services Task 4 – Nuclear Integration Explore risks and methods for supporting large load energy needs with SMRs and incorporating them into the wider power system Task 5 – Decision Support and TA Provide support to stakeholders through the creation of planning tools and direct technical assistance.

24 - POWER TRANSMISSION AND DISTRIBUTION↗