Search NASA⌕ Search

SEARCH · Search NASA

Results for “CyberSecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Designing a Comprehensive IDS Strategy for a Zero Trust Architecture Environment

Zero Trust Architecture or ZTA is a cybersecurity model for enterprises to structure their networked resources around to maintain total security externally and internally. In a Zero Trust environment, no part of the network is considered "trustworthy" and thus should be scrutinized and monitored extensively as is done in traditional "Trust But Verify" schemes at the network's perimeter. In this way, Zero Trust Architecture is a superior model for securing access to networked resources at the enterprise level. Fermilab, in pursuit of a better security posture, has decided to embrace this model of architecture for its network. Attaining this goal requires tremendous infrastructural, policy, and procedural adjustments that will affect all the lab's personnel and resources.

D'Antonio, Lucas↗

Integrating PCTRAN with AI-Driven Host-Intrusion Detection and Secured Container Systems for Advanced Malware Analysis (Summer Internship Report)

This study presents a solution for enhancing the security of the Personal Computer Transient Analyzer (PCTRAN) PC-based Nuclear Power Plant Simulator by integrating the software with an artificial intelligence (AI)-driven host-intrusion detection system (HIDS), in addition to a secured container system, for malware analysis. PCTRAN is a Windows XP-based software package that has the ability to simulate a variety of accident and transient conditions for nuclear power plants (NPPs). It offers a high-resolution replica of the Nuclear Steam Supply System (NSSS) and displays the status of important parameters allowing for operator interaction. By including AI-driven HIDS for the NSSS, the framework can identify security threats in real-time, ensuring the integrity of the nuclear simulation environment. Additionally, the secured container system offers the ability to isolate and analyze malware, preventing potential threats from affecting core systems. The integration process involves extensive testing and validation in order to ensure accuracy, reliability, and compliance with security policies. This framework sets a new precedent for secure simulation and training in NPP operations, and offers insight for future advancements in cybersecurity.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Reactor System Demonstration with Cyber-Attack Scenarios Using CrowPis and Arduino Microcontrollers

This study covers developing and simulating nuclear reactor system using CrowPis and Arduino microcontrollers for demonstrating cyber-attack scenarios. The team was tasked with implementing more sensors and cybersecurity aspects to the reactor program that was created by last year’s high school interns. The team received the opportunity to collaborate and obtain advice from multiple university interns that helped us gain a better perspective of our project. Our mentor’s background in nuclear science was pivotal to our understanding what we could add to the reactor program to make it as realistic as possible. The first week of our internship was spent reading as much material as possible to gain an understanding of and the background for cyber-attacks and nuclear science. Nuclear science was a new horizon for each of the high school interns on the team, so spending this time in the beginning of our internship was crucial to our success. For the remaining portion of our internship, the team collectively did our best to implement as many sensors and use as much hardware as we could to make an accurate representation of a nuclear reactor in the program that was created. This internship was a big learning experience for everyone on the team. We all gained so many insights into the nuclear world and how it can benefit our lives, as well as how so many moving pieces are needed for it to work properly.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Technical Learning and Integration of Interns in Advanced Protection Lab Space: Enhancements to Testbed and Experiments to Improve Workflows for Producing Datasets

This report presents a successful technical learning integration of student interns in the Advanced Protection Laboratory space, located in the Grid Research Integration and Deployment Center (GRID-C) at the Department of Energy’s (DOE’s) Oak Ridge National Laboratory (ORNL). The Advanced Protection Laboratory was created for the primary goal of supporting DOE’s research projects and technical staff at ORNL. As a secondary goal, the space was used for collaborating with ORNL’s intern programs, providing support to the lab’s mentors and student interns. In 2024, three student interns spent a summer in the Advanced Protection lab space and were involved in the DarkNet Distributed Ledger Technology (DLT) project. The students had a great opportunity to gain hands-on experience with communication and protective relay equipment focused on information technology, data analytics, and cybersecurity. Experiences in the lab space with real equipment and software integration offer education and professional development for students, which is especially important because of a need in the energy industry to recruit highly skilled power and communication engineers.

42 ENGINEERING↗

Investigate the Security of Electric Vehicle (EV) Ecosystem Applications

Apps that run on mobile devices are one of critical components of the electric vehicle (EV) ecosystem and pose possible threat actor points of entry that may impact the trust and security of EV charging systems in the future. Mobile apps often rely on communication between cloud servers and users, thereby creating potential points of entry for cyberattacks. Although app stores such as Apple App Store or Google Play Store generally test the security of apps, the cyber aspects may not be sufficient for many entities including DOD, federal fleets, and commercial entities. A more thorough inspection and the ability to influence developers is imminently needed. This research studies security attributes and vulnerabilities of a sample of mobile applications that support key user functions in the EV ecosystem. The study shows that all analyzed apps have security risks, categorized as either high or medium or both and a comprehensive cybersecurity guideline for developing mobile apps is necessary.

33 ADVANCED PROPULSION SYSTEMS↗

Radio Frequency Spectrum Audit to Inventory Private Cellular Base Station Infrastructure

The ever-changing cellular communication landscape makes it difficult to identify, map, and localize cellular base stations. Localizing cellular base stations provides various advantages, including information security, cybersecurity, spectrum management, and interference detection. For example, the MITRE ATT&CK® (Adversarial Tactics, Techniques, and Common Knowledge architecture) [1] and Common Attack Pattern Enumeration and Classification [2] emphasize the importance of being able to minimize the cyber security threat presented by unregulated private cellular base stations (PCBS). The majority of published research looks at the malicious use of PCBSs and focuses on using data retrieved from user equipment (UE), data obtained from an application on the UE, or data shared between the UE and a mobile network to locate it. This innovative strategy, however, focuses on the passively discovered uniqueness of radio frequency (RF) transmissions from commercial cellular infrastructure received in a designated monitoring position (DMP).

42 ENGINEERING↗

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING↗

EV Charging Infrastructure Energization An Overview of Approaches for Simplifying and Accelerating Timelines to Processing EV Charging Load Service Requests

The United States has seen significant growth in electric vehicle (EV) adoption, leading to increased demand for EV charging infrastructure. Over the past decade, EV charging infrastructure site developers, site hosts, and electric distribution utilities have navigated the process to integrate chargers onto the electric grid. Site developers and site hosts have raised the alarm that the integration process for high-powered EV charging projects does not meet the needs of the EV market for timeliness or cost. High-powered charging stations typically require a load service request or an agreement with the local utility to connect to the grid. The process of energizing a new high-powered charging site can be complex and time-consuming, often taking up to 2 years. This timeline is the result of current utility energization processes having been designed for construction projects that take longer to build (i.e., buildings). The specific challenges stem from various factors, including compartmentalization in application processes, the integration of EV charging process approvals with other distributed energy resources (DERs), and the need to ensure grid reliability. The energization process needs to evolve to meet the growing demand for high-powered EV charging. This white paper compiles information gathered through various conversations with key stakeholders, including utilities, utility regulators, EV charging operators, site developers, and authorities having jurisdiction (AHJ) as well as through an extensive literature review. This document identifies the challenges and provides potential solutions to streamline the process of connecting EV charging infrastructure to the power grid in the United States, serving as a starting point for future conversations around these solutions. The solutions noted in this white paper require collaborative efforts among utilities, regulators, and EV charging infrastructure developers to streamline the grid connection process for EV charging infrastructure. They are broadly organized into four areas: 1. Increase data access and transparency: Develop automated load service request tools, integrate hosting capacity and load service request analyses, incorporate EV adoption forecasts, and provide transparency on the processing queue. 2. Improve energization processes and timing: Create fast-track options based on prescreening criteria, provide flexibility or phased approvals in the load service request/interconnection process, build internal knowledge within utilities about EV charging technologies, and provide standardized workforce training. 3. Promote economic efficiency: Right size distribution components to accurately reflect the load requirements of EV charging infrastructure, make proactive investments in grid infrastructure based on EV adoption forecasts and growth projections, and consider energy equity and environmental justice factors such as equitable access to EV charging when planning infrastructure. 4. Improve grid reliability and resilience: Use load management/power control systems (PCS) at EV charging stations, adopt and implement harmonized standards for communication protocols and information models between the EV charging and grid control infrastructure, and address cybersecurity considerations by implementing robust security measures and standards for EV charging infrastructure—with particular emphasis on clarifying the security requirements for the interface to the grid. The objective of the solutions proposed in this white paper is to accelerate the timeline and decrease costs associated with connecting EV charging infrastructure to the grid. Electric utilities, utility regulators, EV charging infrastructure developers, and site hosts will first need to understand which solutions are available in their service territory, and if warranted, which combination of solutions would support their specific needs. Through the successful implementations of solutions at scale detailed here, industry will demonstrate a new and innovative ecosystem where timely deployment and energization of EV charging infrastructure with greater grid resiliency and reliability is a reality.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Development and Validation of Smart Building Technology Modules for Academic and Professional Education (Final Technical Report)

Smart building technologies can improve building energy efficiency and resilience, reduce carbon emissions, and provide load flexibility to the grid. However, in both college curricula and building professionals’ continuing education, there is a lack of systematic instruction on smart building technologies. Slipstream, partnering with Texas A&M University (TAMU), the Society of Building Science Educators (SBSE), and the National Institute of Building Sciences (NIBS), developed a semester-long smart building curriculum for college students and 16 training videos for building professionals and the general public. The education and training cover the drivers and benefits of smart building technologies, key building energy systems, the latest sensor technologies and IoT devices, and focus on topics related to smart building controls (i.e., energy management information systems, smart building control platforms, cybersecurity, grid-interactive-efficient buildings [GEBs], smart building control methods, and occupant-centric control). The smart building curriculum for college students was taught at TAMU in the Spring semester of 2024 as part of the validation process. Student feedback was collected and summarized in a validation report by TAMU. The curriculum material was also reviewed by SBSE faculty who are interested in teaching smart building technology-related courses. Suggestions on revisions and better adoption of the materials by other faculty across the architectural, engineering, and construction (AEC) domains were compiled in a distinct validation report by SBSE. The SBSE validation report was used to create structured subsets of the curriculum material for adoption at different levels in different sub-disciplines. These subsets are categorized and offered on the SBSE website (https://www.sbse.org/courses/Smart-Building-Technologies). The 16 training videos for building professionals and the general public were previewed by 17 industry experts, and feedback and suggested changes were incorporated into the final version of these videos. The videos are organized into a smart building technology training course and published on the Whole Building Design Guide website (https://www.wbdg.org/ce/doe/bto/sbtt), which is hosted by the National Institute of Building Sciences (NIBS). Project team members created marketing materials to promote the awareness of these free, publicly available education and training resources. Outreach and marketing activities included creating short promotional videos, building project webpages, making project announcements on social media, conducting an email campaign, and directly reaching out to faculties and building professionals. This report describes the project approach, provides outlines of the training materials, along with links to resources, and identifies lessons learned in creating the content. We also suggest ways to scale the instruction of smart building concepts to empower the workforce to accelerate the adoption of smart building technologies in the real world.

99 GENERAL AND MISCELLANEOUS↗

Generative Artificial Intelligence Tools for Red Teams

This document analyzes the role of Generative Artificial Intelligence (GenAI) tools in cybersecurity, particularly for red teaming. While GenAI accelerates initial security assessments, its effectiveness wanes with complexity, necessitating experienced assessors. The review critiques marketing claims, highlights ethical concerns regarding uncensored models for cybercrime, and advocates for a robust defense strategy supported by skilled professionals.

97 MATHEMATICS AND COMPUTING↗

Demonstration of Utility Managed Smart Charging for Multiple Benefit Streams (Final Report)

In the summer of 2020, the U.S. Department of Energy (DOE) awarded funding to Exelon’s Maryland utilities—Baltimore Gas and Electric (BGE), Delmarva Power & Light (DPL), and Potomac Electric Power Company (Pepco)—to implement the Smart Charge Management (SCM) pilot. This initiative aimed to design and implement managed electric vehicle (EV) charging strategies, evaluate the grid impacts of EV charging, and assess the utilities' ability to control EV load based on real-time grid conditions. The SCM pilot explored four aspects for continued improvement: (1) cybersecurity and managed charging functionality testing of two vendor platforms—WeaveGrid (telematics-based) and Shell Recharge Solutions (network-based)—which pursued charge scheduling and optimization through distinct approaches; (2) an analysis by Argonne National Laboratory (ANL) modeling team of three potential SCM enrollment scenarios within BGE and Pepco service territories over the next decade to assess future scalability; (3) employing customer engagement strategies, including surveys and a responsive pricing approach; and (4) the launch and implementation of pilots in Exelon’s Maryland territories in collaboration with WeaveGrid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Support for the Core Research Activities and Studies of the Computer Science and Telecommunications Board (DE-SC0020446 Final Technical Report)

Supported the core operations of the National Academies' Computer Science and Telecommunications Board (CSTB). Helped support planning and conducting of board meetings, identification of priority topics in computer science and other areas of computing and communications technologies, and oversight for CSTB's portfolio of studies and convenings. Activities shaped and overseen included: a workshop on Al for scientific discovery; collaborative work with other Academies units on a study on foundational research gaps and future directions for digital twins; a study on current capabilities, future prospects, and governance of facial recognition technologies, a study on post- exascale computing; a study on fostering responsible computing research, collaborative work with other Academies units on automated research workflows for accelerated scientific discovery; a study on meeting federal cybersecurity workforce needs, and a study of the ecosystem driving information technology innovation.

97 MATHEMATICS AND COMPUTING↗

Master Services Agreement - Flexible Feeder/Distribution System Support: Cooperative Research and Development (Final Report)

PGE will engage NREL on a broad range of projects related to the integration of distributed energy resources (DERs) into the utility's operations. This portfolio of work could include projects focused on DER adoption models, advanced distribution management system (ADMS) and distributed energy management system (DERMS) design, DER dispatch strategy development, and DER valuation framework development. Additional topics could include long-term energy planning, renewable energy, energy efficiency and demand-side management. As well as technology evaluations and design guidance for building retrofits and new construction projects, energy and energy infrastructure planning, policies, and markets (and their analysis), energy storage, energy security and resilience (including energy system-related cybersecurity), transportation and mobility, technology integration analysis. Additionally, other assistance as requested by PGE consistent with NREL’s expertise.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Optimized V1G and V2G Electric Vehicle Fleet Management and Grid Transaction at Marine Corps Air Station Miramar in San Diego, CA

The overall technical goal of the project was to demonstrate an all-electric bi-directional non-tactical fleet at Marine Corps Air Station (MCAS) Miramar that was integrated and controlled with other distributed energy resources (DERs) (i.e., PV, stationary battery, and building loads) to provide resilience to critical electric loads in the event of grid outages, to minimize charging costs, and to provide economic energy resources to electricity markets. In this project, the specific, technical objectives were: 1. Demonstrate that bi-directional electric vehicles can provide critical complementary services to fixed storage batteries in microgrid applications while performing function as non-tactical vehicles. 2. Demonstrate participation of bi-directional (V2G) and unidirectional (V1G) PEVs for demand management and minimization of charging costs. 3. Demonstrate integration of multiple DERs for grid service participation. US Marine Corps Air Station (MCAS) Miramar in San Diego was the site of this electric vehicle-to-microgrid-utility grid test and demonstration project. Existing microgrid assets in this study included (1) a public works building; (2) a 30-kW rooftop photovoltaic (PV) system and (3) a separate 250 kW carport PV system. In this project, six bi-directional V2G vans were located at the MCAS Miramar’s showcase building-scale microgrid to develop and test technical capabilities that V2G can provide in microgrid applications (e.g., cost reduction and resiliency). These resources provided aggregated demand management and simulated participation in current retail DR programs. The vehicles used in this demonstration were selected because they provided functionality that MCAS Miramar needed, 15 passenger transport and facilities work cargo carrying capacity, and bi-directional charging capability that the research project required. All vehicles in this study were manufactured and distributed by VIA Motors, Inc. There were six vehicles total and each was VIA’s VTRUX eREV V2G model, a modified General Motors Chevrolet 2500 2WD van. Three of the vans were configured as passenger vans and the other three were configured as cargo vans. Each van had an on-board bi-direcrtional inverter/charger, Bel Power Solutions model 350INVCHGT150-120-240-8G nominally rated at +/-15 kW. The VIA van’s charging connector follows the J1772 charging protocol. The bi-directional EVSEs demonstrated in this study were manufactured by Coritech, Inc. Each VGI-80-AC charging station enabled enhanced V2G charging capability to a Clipper Creek CS-100 charging module. The enhanced capabilities included ethernet communication following the SEP2.0 protocol with a distributed energy resource function set and an operator screen displaying real-time SOC, voltage, and current. The VGI-80-AC charging stations are classified as level 2 with a maximum current output of 80 A or effectively 19 kW. The VIA van’s onboard charger limited the charging and discharging power to 15 kW in each direction. A control computer was installed in the EWOC and connected to an existing monitor. The V2G control communication network was a completely stand-alone closed system that did not have any connection to any other networks on the base. A cybersecure remote communication connection was created with a cellular modem, firewall hardware, and a virtual private network configuration.

24 POWER TRANSMISSION AND DISTRIBUTION↗

V-INT: Automated Vulnerability Intelligence and Risk Assessment

The project team, including the University of Arkansas (UA) as the lead, the University of Arkansas at Little Rock (UALR), Network Perception (NP), and Bastazo, has successfully researched, developed, and demonstrated the V-INT toolset, and also integrated it into the commercial products of NP (i.e., NP-View) and Bastazo (i.e., Spartan). The end product is a cybersecurity software tool for energy utilities that can automatically assess the risks of software vulnerabilities in an organization’s assets considering the organization’s firewall policies. It allows security operators to identify the small portion of vulnerabilities that poses true threats to their system (i.e., those that are not protected by firewall policies) and prioritize the mitigation of these vulnerabilities to minimize risks. It also allows security operators to identify the vulnerability-induced attack paths under their organization’s firewall policy, providing effective decision supports for mitigating potential attacks.

97 MATHEMATICS AND COMPUTING↗

Electric Grid Security (EGS) FY24 Annual Report

Sandia’s Electric Grid Security program advances a national vision of a secure, resilient, and affordable electric system for all users. Our achievements reflect a strategic approach combining technology development; modeling, simulation, and data analytics; and partnered demonstrations and outreach to further the adoption of advanced grid and storage technologies. Our FY24 efforts leverage the strengths of our partnerships—spanning Sandia’s core science and technology competencies as well as external technology leaders—to develop the solutions today which enable the grid of tomorrow. Key accomplishments in this report that support our strategy span our technical program areas and include: • The advancement of energy storage technologies, including creation of a national Long Duration Energy Storage Consortium; • Applications of artificial intelligence and machine learning to enhanced grid operations and planning; • Development of solid-state power conversion technologies and a new medium-voltage research lab; • New technologies to assess wildfire vulnerabilities and mitigate potential impacts; • Advanced applications of new cybersecurity technologies with industry partners; • Contributions to understanding the impacts of electromagnetic pulses and geomagnetic disturbances on grid components; and • Digital twin development for hybrid microgrids with multiple generators, storage, and loads.

24 POWER TRANSMISSION AND DISTRIBUTION↗