Search NASASearch

SEARCH · Search NASA

Results for “Critical Infrastructure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence

Correlating Power Outage Spread with Infrastructure Interdependencies During Hurricanes

Power outages caused by extreme weather events, such as hurricanes, can significantly disrupt essential services and delay recovery efforts, underscoring the importance of enhancing our infrastructure's resilience. This study investigates the spread of power outages during hurricanes by analyzing the correlation between the network of critical infrastructure and outage propagation. We leveraged datasets from Hurricanemapping.com, the North American Energy Resilience Model Interdependency Analysis (NAERM-IA), and historical power outage data from the Oak Ridge National Laboratory (ORNL)'s EAGLE-I system. Our analysis reveals a consistent positive correlation between the extent of critical infrastructure components accessible within a certain number of steps (k-hop distance) from initial impact areas and the occurrence of power outages in broader regions. This insight suggests that understanding the interconnectedness among critical infrastructure elements is key to identifying areas indirectly affected by extreme weather events.

Bose, Avishek

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY

Center for Alternate Synchronization and Timing (CAST) PTP Network Monitoring Report

The Oak Ridge National Laboratory Center for Alternative Synchronization and Timing (CAST) performs research, development, testing, and evaluation of alternative terrestrial-based timing and synchronization infrastructure for the US power grid and other critical infrastructures. Alternative timing options reduce reliance on GPS and enhance the overall resilience of critical infrastructures. CAST infrastructure uses Precision Time Protocol (PTP) as the primary conduit for delivery of synchronization packets. CAST deploys PTP over long terrestrial links to synchronize a multitude of remote boundary clocks and downstream power grid components with the authoritative grand master clocks. Network traffic issues can severely degrade PTP accuracy. This report focuses on examining network traffic anomalies and their effects on PTP operation as well as the potential implications to CAST’s high-precision remote synchronization operations.

24 POWER TRANSMISSION AND DISTRIBUTION

Human Factors Considerations in Artificial Intelligence Applications for Nuclear Power Plants

In recent years, there has been a wave of artificial intelligence (AI) technologies that offer to solve problems from shopping habits to mortgage approvals to critical systems operations. The rapidity of the development of these systems has led to both excitement and apprehension about the roles these systems should play in our modern societies. Furthermore, this paper focuses on the critical infrastructure industry, in general, and nuclear power generation, in particular, and seeks to scrutinize how we can leverage these novel technologies in human-centered ways to maintain or enhance the established high levels of reliability and resilience in these industries. First, we discuss the broader aspects of cognitive systems and activities that are critical to understanding the human-AI space. Then we explore different approaches to explainability in AI and the notions of trust. We then move on to discuss several human factors concepts and methods and how they can support the design of human-AI teams. We then explore recent research related to nuclear power that has been undertaken and evaluate the current industry and regulatory landscapes. Finally, we discuss identified research gaps and recommendations for solving these for the critical infrastructure space.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS

GeoCricket

SAND2025-12229O Geospatial Critical Infrastructure and Census Data Stockpile Tool (GeoCricket) is a set of functions that collect critical infrastructure and census data for use in the Resilient Node Cluster Analysis Tool (ReNCAT) and Quantum Geographic Information System Social Burden Calculator. It can also act to inform other place-based work. The code queries public-facing Representational State Transfer (REST) servers to collect geospatial data related to a specific area. It then exports that data as standard geographic information system file types or as a .csv file. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Haines, John

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a framework for consequence-driven applied risk analysis, enabling utilities to prioritize and mitigate potential threats effectively, and responsibly deploy cloud applications. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY

InterGraph-CPS: A Graph-Theoretic Approach to Characterize Cross-Domain Cyber-Physical Interdependencies and Uncertainties in Electric Grid Systems for Improved Decision-Making in Operation and Response

Critical infrastructure systems such as the electric grid are increasingly cyber-physical; yet, despite the cyber-physical characteristics of critical infrastructure systems, the physical process system and communication/control network system are traditionally analyzed in siloes. As these systems become more cyber-physical, it is crucial that models and methods are available to assess the cyber physical system (CPS) interdependencies, characteristics, and event propagation for improved planning, operation, and response. Thus, we proposed an integrated structural and temporal CPS interdependency analysis framework, InterGraph-CPS, that provides insight into the CPS function during normal operation as well as disturbances. This integrated structural and temporal interdependency framework is uniquely designed for assessing CPSs by account for the challenges of analyzing cyber and physical data streams together due to data availability, data type, and time scale differences. By leveraging both structural (e.g., graph analysis) and temporal (e.g., data analytics) techniques, different CPS behaviors and configurations can be accounted for.

24 POWER TRANSMISSION AND DISTRIBUTION

Cyber-Informed Engineering: Standards Development Organization Quick Start Guide

Cyber-Informed Engineering (CIE) is an emerging methodology focused on identifying and reducing high-consequence events that may affect physical critical infrastructure systems as a result of their dependence on digital technology. CIE, developed by National Laboratories and promoted by the Department of Energy (DOE), incorporates consequence-focused planning into the design and engineering process from the earliest stages of a project. This guide provides a concise overview of CIE and offers practical insight into how Standards Development Organizations (SDOs) can interpret CIE principles and apply those concepts in updates to various standards. It is important to remember that CIE extends beyond a compliance checklist, emphasizing a broader, interpretive approach. Instead, it encourages an interpretive mindset - a "turning of 'what if' to 'even if'" approach that anticipates and engineers out high-consequence events. The authors encourage SDOs to establish and promote CIE principles as enhancements for more resilient-by-design outcomes across critical infrastructure energy sectors. The 12 core principles of CIE outline specific behaviors and actions that SDOs and engineers may adopt to enhance system resilience. This guide applies these principles in a manner intended to be relevant across various technologies and threat landscapes. We welcome institutions and vendors to identify new or different framework alignments and mappings as we collectively work towards a safer and more reliable digital landscape.

97 MATHEMATICS AND COMPUTING

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING

Building Cybersecurity Educational Materials for Students: The Windfarm Capture-The-Flag Exercise

Securing and protecting critical infrastructure in an increasingly digital world is vital but it is all too often an afterthought. It is especially important that students become aware of internet safety and security at an early age. However, the availability of interactive and educational cybersecurity material targeted toward students is minimal in the United States. Here we show an example of interactive cyber security educational material that an educator can use in their classroom to encourage students to think about the interaction between real-world physical objects, cyber security, and information security. By putting together a “capture-the-flag” exercise, students can see in real time how hackers and cybercriminals exploit vulnerabilities and gain access information. The students try to “capture” the “flag” (i.e., information) in the wind farm by looking for oddities in the code or by taking advantage of weaknesses in everyday protocols. Students can also see how cybersecurity interacts with the power grid through the wind farm project scenario and how a hacker could cause serious problems to a critical infrastructure sector. Our goal for the project is getting students interested in cybersecurity and help them develop an awareness of how important having robust security systems is. We also hope that this project demonstrates the importance of introducing these concepts early and inspires others to create similar projects geared toward students.

97 MATHEMATICS AND COMPUTING

Advanced Computational Techniques for Improving Resilience of Critical Energy Infrastructure under Cyber-Physical Attacks

In this chapter, we present recent advances in improving the resilience of cyber-physical systems, especially with regards to energy systems. We provide discussions around various types of cyber-physical events that can cause disruptions and new advances in optimization, control, and reinforcement learning (RL) to deal with the challenges posed by such cyber-physical events. The presented methods range from distributed robust optimization, autonomous and coordinated control, reinforcement learning based resilient control and topology reconfiguration in Inter-System resilient control.

Nazir, Mohammad Nawaf [BATTELLE (PACIFIC NW LAB)]

Critical Energy Infrastructure Cybersecurity: Enhanced Cyber Resilience for Federal Energy Systems

This presentation is an overview of FEMP Resilient and Secure Infrastructure and Facilities. An educational and interactive workshop centered on resilient and secure federal infrastructure and facilities, with a focus on inverter-based resources at Federal sites, building automation systems, and Federal supply chains. This workshop will illustrate an all-hazards scenario and discuss how Federal agencies can be positioned to resist these real-world scenarios.

97 MATHEMATICS AND COMPUTING

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION