Search NASA⌕ Search

SEARCH · Search NASA

Results for “CyberSecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Cognitive IoT and Edge Computing for Intrusion Detection with Federated TinyML

Internet of Things (IoT) and Edge Computing (EC) are rapidly becoming an integral part of the modern society. By 2030, there is estimated to be over 40 billion active and connected IoT devices [1]. This rapid progress also comes with a significant implication on cybersecurity. Back-end infrastructure and systems have a much broader attack than they did previously due to vulnerable IoT/EC devices being connected to wireless networks. This expanding attack surface is a growing concern because IoT/EC are increasingly being used in critical systems such as power grids, health care, and smart homes. To effectively address a problem of this scale, cognitive cyber methods—which can autonomously detect and react to cyber attacks as they develop—are needed. To address this, we bring Artificial Intelligence (AI) and Machine Learning (ML) to IoT/EC devices, using tinyML to monitor voluminous IoT data against cyber threats, and using Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. We propose a novel three-layer architecture: (1) an IoT layer for tinyML-based inference, (2) an edge layer for ML model training, and (3) a cloud layer for FL operations. Using the publicly available 11-class N-BaIoT dataset [2], we demonstrate that this architecture mitigates resource constraints at the IoT layer while improving detection accuracy over standard two-layer designs. An outlier-resistant scaler, feature reduction, and quantization enable the tinyML model to maintain detection accuracy with a reduced model size. Additionally, federated learning that only utilizes the intersection (across heterogenous devices) of the reduced feature set achieves superior detection accuracy compared to locally trained models.

Li, Mingyan [ORNL] (ORCID:0009000569532640)↗

Modeling Grid Data Flows for Transmission and Distribution Operations: Review, Design, Next Steps

Operational scenarios of the power grids grow multifold to accommodate the diverse needs of both the utilities and end consumers, and the various other stakeholders in-between. To comprehensively model and apply analytics to support objectives and business functions of grid sectors, a reliable approach to characterize and design data flows is crucial. The flows bridge business functions with communications protocols, stakeholders such as the grid actors, and data interfaces comprising different data objects. Additionally, constraints applied to the flow such as cybersecurity, trust, privacy, and ownership among others intersect these entities, requiring the delineation of their interactions under different scenarios. This paper aims to not only highlight relevant research in the space of grid data flows, but also proposes, for the transmission-distribution sector, a novel modeling approach that marries the aforementioned entities: objectives, business functions, data interfaces, communication protocols, data stakeholders, and flow constraints. It elaborates on the design philosophy and the significance of each entity within the model and applies it to an example function of fault location, isolation and service restoration (FLISR). Finally, the next steps to extend the application of this data flow model for other practical operational scenarios are discussed.

Sundararajan, Aditya [ORNL] (ORCID:000000033577854↗

Lamellar: A Rust-based Asynchronous Tasking and PGAS Runtime for High Performance Computing

Cybersecurity is one of the largest concerns in modern computing, impacting and dictating how governments, private corporations, and individuals interact with and live in an increasingly digital world. The NSA has recently released a memo [ 1] on “Software Memory Safety” where they highlight that both Microsoft and Google have stated around 70% of software vulnerabilities were due to memory safety issues. Although languages such as C and C++ provide freedom and flexibility with memory management, guaran- teeing safety falls mostly on the developer. The NSA recommends using “memory safe” languages whenever possible. In this paper we introduce Lamellar, an asynchronous tasking and PGAS HPC runtime written in Rust, one such "memory safe" language. We describe the entire Lamellar stack, from network interfaces to high- level abstractions such as distributed LamellarArrays and Active Messages. We conclude by showing comparable performance to legacy PGAS runtimes (e.g. OpenSHMEM) on a subset of the BALE kernel suite while maintaining strong memory safety principles.

HPC Software Systems, Rust Programming Language, P↗

Enhancing Automotive Intrusion Detection Through Multi-Modal Fusion: A CAN FD-LiDAR Approach

As vehicles become smarter and more autonomous, they increasingly depend on advanced sensors and communication technologies to operate securely. However, such growing dependence on technology—whether it’s CAN (Controller Area Network) for internal communication or LiDAR (Light Detection and Ranging) for sensing the world around them—also expands the attack surface for the types of cyber attacks. Traditional intrusion detection systems (IDS) typically monitor these systems in isolation, limiting their ability to detect sophisticated, crosssystem attacks. To address this, we propose a multi-modal fusion approach that combines real-world CAN FD signals (from the HCRL dataset) with LiDAR features (from the nuScenes dataset) to enhance attack detection. Our method employs a twostage ensemble approach. Calibrated XGBoost and LightGBM models initially process CAN FD (Fuzzing Data) and LiDAR data independently, detecting timing anomalies and space abnormalities. They are subsequently logarithmically combined with a logistic regression meta-model along with 17 engineered features capturing cross-modal behavior, prediction conflicts, and nonlinear interactions. This approach achieves an AUC of 0.87 and an F1-score of 0.82, surpassing single-modality baselines and early fusion methods, at merely 2 ms inference latency. Compared with deep learning competitors, it is 3 times more efficient, providing a lightweight, interpretable, and real time solution to automotive cybersecurity.

97 MATHEMATICS AND COMPUTING↗

Detect the Unobservable: Abnormality Detection in mixed Autonomy for Lane Change Maneuver with Following Vehicles’ Trajectories Only

Highly Automated Vehicles (HAVs) and Advanced Driver-Assistance Systems (ADAS) are transforming modern transportation with enhanced mobility, safety, and efficiency. Despite their advantages, cybersecurity vulnerabilities in these systems can lead to abnormal behavior, posing significant risks to surrounding human-driven vehicles (HDVs) in mixed traffic environments. Here, this article addresses the challenge of detecting abnormal lateral movements of HAVs/ADAS vehicles using only trajectory profiles of following HDVs. Specifically, we propose a novel modeling approach that captures both normal and abnormal lateral behaviors through vehicle kinematics, integrated decision-making processes, vehicle control using symbolic regression for lane change vehicles. Additionally, we introduce an abnormality detection framework that relies on observable HDV data, even in occlusion scenarios. The framework evaluates the sensitivity of various car-following models to detect abnormal behaviors, providing insights into the interaction between HAVs/ADAS and HDVs in mixed autonomy systems.

Connected and Automated vehicles↗

Engineering Controls Database

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

Source record↗

Cyber-informed Engineering Microgrid Analysis Tool

The Cyber-Informed Engineering Microgrid Analysis Tool (CIEMAT) leverages the Department of Energy’s Cyber-Informed Engineering to prompt engineering designers and operators through an analysis of the critical functions to be supported by a microgrid installations, the criticality of those functions, the impacts of denial, disruption or misuse of those functions on the microgrid and dependent functions, and the mitigations which could best prevent impacts to those functions resulting from cyber attack. Through use of this tool, microgrid designers and operators can quickly identify appropriate engineering mitigations to limit impacts from cyber attack and functions where engineering and operational staff can prioritize and guide the application of cybersecurity protections to best support the resiliency of the system.

Wright, VirginiaL [Idaho National Laboratory (INL)↗

Cyber-informed Engineering Battery Analysis Tool

The Cyber-Informed Engineering Battery Analysis Tool (CIEBAT) leverages the Department of Energy’s Cyber-Informed Engineering to prompt engineering designers and operators through an analysis of the critical functions to be supported by a BESS installation, the criticality of those functions, the impacts of denial, disruption or misuse of those functions within the BESS system, and the mitigations which could best prevent impacts to those functions resulting from cyber attack. Through use of this tool, BESS designers and operators can quickly identify appropriate engineering mitigation opportunities to limit impacts from cyber attack and functions where engineering and operational staff can prioritize and guide the application of cybersecurity protections to best support the resiliency of the system.

Lampe, BenjaminR [Idaho National Laboratory (INL),↗

Cyber Knowledge Alignment

An automated workflow and introduces new approaches to curate existing cybersecurity knowledge from multiple sources. It also proposes AI/ML-based methods to infer knowledge alignments across different repositories.

Purohit, Sumit [Pacific Northwest National Laborat↗

Optimal Mitigation Planning For Adversarial Scenarios

We propose a generalized framework which performs an optimal partitioning of a limited budget into various organizational sectors in order to improve the cybersecurity of a smart device or component in the Cyber Physical Energy System (CPS). The framework identifies the adversarial threats and possible attack sequences which can be performed to exploit cyber vulnerabilities of the component. Thereafter, we formulate an Mixed Integer Linear Programming (MILP) optimization problem which aims to evaluate the optimal budget partitions in order to minimize the number of highly likely attack sequences. Though we provide results for using the framework in CPES, the proposed methodology can be extended for multiple domains with a set of known adversarial and mitigation actions.

Purohit, Sumit [Pacific Northwest National Laborat↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗

POWER DATA PIPELINE

SF-25-081 Utility software for creating high-performance data pipelines to extract, load, and transform raw electric power systems measurements. For use with anomaly detection models training workflows. The software supports the project: Adaptive Cybersecurity for DER: A Game-Theoretic and Machine Learning approach for Real-Time Threat Detection and Mitigation

Plathottam, Silby Jose [Argonne National Laborator↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

CIEPAT (Cyber-Informed Engineering Photovoltaic Analysis Tool) [SWR-25-171]

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

Etigowni, Sriharsha [National Laboratory of the Ro↗

CIECAT (Cyber-Informed Engineering Commercial Buildings Analysis Tool) [SWR-25-172]

The Cyber-Informed Engineering Commercial Buildings Analysis Tool (CIECAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Commercial Buildings by incorporating Cyber-Informed Engineering (CIE) principles into the Commercial Buildings.

Etigowni, Sriharsha [National Laboratory of the Ro↗

Ground-motions site and event specificity: Insights from assessing a suite of simulated ground motions in the San Francisco Bay Area

This article presents the results of a research that is part of a larger collaborative effort between the Lawrence Berkeley National Laboratory and the Pacific Earthquake Engineering Research Center, funded by the US Department of Energy Office of Cybersecurity, Energy Security and Emergency Response. The main objective of this study is to assess a suite of near and far-field simulated ground motions obtained from 20 realizations of an M7 Hayward Fault earthquake in the San Francisco Bay Area, California USA, and inform the selection of rupture simulation parameters leading to strong motions. To this aim, comparisons are conducted with NGA-W2 and directivity ground-motion models and a selected population of records. An archetypal steel moment-resisting frame is utilized to assess infrastructure response distributions. The analyses carried out for each simulated event and subdomain with consistent properties in terms of shallow shear-wave velocity proved to be instrumental for better interpreting the differences between simulated motions and empirical models. The main reasons identified for variances between simulations and empirical relationships included (1) directivity effects fully captured by the simulations across the full breadth of rupture models; (2) site vicinity to ruptures that incorporate large-slip patches, particularly if these are in the forward-directivity direction; and (3) presence of geologic structures that can “trap” seismic waves and produce ground motions with large amplitude and long signal duration. The analyses carried out in this work provide a path for interpreting ground-motion site and event specificity obtained from a suite of physics-based simulations, differing only in the rupture model characterization, to inform the selection of simulation scenarios for site-specific engineering analyses under strong excitations. Evidence from this work points to the possibility that current hazard models may underestimate ground-motion intensities in areas where the combined effect of directivity and site conditions results in large ground-motion amplitudes.

58 GEOSCIENCES↗

Robotic automation of maintenance work in nuclear power plants a cross-sector survey and roadmap

Nuclear power plants face increasing cost pressures, workforce constraints (aging workforce and skilled labor shortages), and safety requirements that are accelerating interest in robotic systems for inspection and maintenance. We conducted semi-structured interviews with personnel from seven U.S. nuclear utilities and compared deployment models, operational use cases, and integration practices with those reported by participants in the oil, gas, and petrochemical sector. In nuclear plants, robotic use remains concentrated in inspection—particularly indoor unmanned aerial vehicles and submersible remotely operated vehicles—with limited application to physical maintenance tasks. Reported near-term value includes reduced radiological and industrial risk, reduced outage labor, and improved data for planning and condition assessment. Key barriers include integration and data-interoperability constraints, operator qualification requirements, cybersecurity review burden, and difficulty demonstrating reliability in plant-representative environments. Cross-sector benchmarking highlights organizational and deployment practices that may help nuclear plants scale from pilots to routine use. We propose a deployment-oriented roadmap emphasizing modular payload strategies, representative qualification pathways and testing environments, and improved data governance to support safe and economically justified expansion of robotics in operating nuclear power plants.

11 - NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

The Integration of The Cloudflare WAF

HTTP Strict Transport Security (HSTS) is a standard that ensures website visitor’s traffic is always sent using HTTPS ensuring that all traffic is protected during transit. This initiative was adopted in 2012 by the IETF and has grown in popularity all around the world. Because the traffic is encrypted with TLS/SSL, it can be used by attackers to bypass various cybersecurity capabilities such as a site firewall. To address this lack of visibility into encrypted traffic in motion, the CST at Fermilab acquired the Cloudflare Web Application Firewall (WAF). To help in the implementation and integration of the Cloudflare WAF, I was directed to learn about and aid in this process. This has been a profound learning experience into the on-goings of project management, web application firewalls, collaboration, and networking.

Blum, Ethan T.↗