Search NASA⌕ Search

SEARCH · Search NASA

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 433 records · Page 24

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Seismic DAS Observations of a large underground chemical explosion in dry tuff

On 18 October 2023 a 16.3-ton TNT equivalent chemical explosion was detonated underground at the Nevada National Security Site, generating a seismic event (Meyers et al., 2024). The associated seismic wavefield was measured on a Distributed Acoustic Sensing (DAS) array with slant range distances from 27 m – 1123 m. The first arriving phase traveled at an apparent velocity of about 2640 m s -1 from 27 m to 420 m slant range and about 2470 m s -1 from 505 m to 1123 m slant range according to the first arrival moveouts on the DAS data. The first arrival from the explosion temporarily saturated the cable from a slant range of 27 m – 186 m and 0.009 s to 0.084 s post detonation. From 186 m slant range to 420 m slant range, peak strain rates of 5.6 x 10 6 nm m -1 s -1 were observed for the first arrival phase. For the first arrival from 505 m slant range to 1123 m slant range, peak strain rates reduced to 8.0 x 10 4 nm m -1 s -1 . A comparison of the scaled accelerations computed from DAS, the geophone pairs, and the measurements of co-located accelerometer pairs show common agreement at the scaled ranges of the single point sensors. This study adds to the body of work reporting near-source DAS observations of the seismic wavefields generated by underground chemical explosions. These results indicate that near-source DAS observations can refine interpretations of phase identification from single-point sensor observations. Phase identification could be one mechanism that contributes scatter to single point seismic measurements which would confound the performance of empirical relationships for small explosions. Removing that mechanism may therefore reduce interstation variability and increase empirical relationship performance for small explosions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

CIE Analysis Process for Engineered Systems

"CIE Analysis Process for Engineered Systems" outlines a comprehensive methodology for integrating Cyber-Informed Engineering (CIE) principles into both new and existing engineered systems. Sponsored by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER), the process aims to achieve cyber-informed decisions by producing functional security requirements for new systems and retrofitting existing systems to mitigate digital risks. The document details a step-by-step approach, including mission and function definition, digital asset awareness, consequence analysis, and mitigation analysis. It emphasizes the importance of documenting mechanical, electrical, programmable, and network components to protect system functions and provides examples and considerations for each step. The ultimate goal is to ensure that engineered systems remain resilient against cyber threats, maintaining safety, performance, and reliability.

42 - ENGINEERING↗

BeyondFingerprinting: AI-guided discovery of robust materials & processes

BeyondFingerprinting was a 2021-2024 Sandia Grand Challenge LDRD exploring the potential to develop new resilient materials and manufacturing processes by taking an artificial-intelligence (AI)-guided approach that integrates human-subject-matter expertise with algorithms enriched with physics-based constraints to unearth process-structure-property correlations. Such algorithms, trained on high-throughput experiments and simulations, are shown to serve as surrogate models that efficiently detect key “fingerprints” in materials data, prognose material performance, and guide effective process improvements. To accelerate broader adoption across mission areas, this AI-guided approach was demonstrated with three complex process-centric exemplars: electroplating, physical vapor deposition, and laser powder bed fusion. Together, these exemplars impact nearly every hardware component relevant to DOE and NNSA national security missions.

36 MATERIALS SCIENCE↗

Implications of new Reasoning Capabilities for Science and Security: Results from a Quick Initial Study

On Thursday, September 12 OpenAI released “a new series of models designed to spend more time thinking… they can reason through complex tasks and solve harder problems than previous models in science, coding, and math.” These models are referred to as o1-preview and o1-mini and appear to be first results of what had been a closely held project called Strawberry within OpenAI. The models are not described as successors in the earlier GPT series because they provide a qualitatively different type of capability, especially step-by-step reasoning.

97 MATHEMATICS AND COMPUTING↗

A Taxonomy and Feature set for Server-Side Identification of Proxies

Malicious actors frequently use proxies and VPNs to evade detection and hide their origin. Current challenges to information security include the use of residential proxies to blend in with normal traffic and Man-in-the-Middle phishing proxies that are used to compromise accounts protected with mult-factor authentication. We advance a taxonomy and feature set for the identification of proxied traffic based on the network layer where proxying occurs. We describe how these features apply to common proxy types and how to use these features in the classification of the proxied traffic. Collection of these additional features is feasible using existing network sensors and web servers, while only adding about 30% volume to commonly deployed network sensor logs.

97 MATHEMATICS AND COMPUTING↗

Dynamic probabilistic risk assessment and game theory for cyber security risk analysis in nuclear power plants

Nuclear Power Plants and energy systems have become more prone to cyber-attacks with their digitalization and the increased use of smart equipment. Hence, it is important to quantify the risk associated with cyber-attacks in such systems. Dynamic Probabilistic Risk Assessment which involves studying the evolution of a system due to random events and operator and attacker actions during a cyber-attack by employing a physics-based model of the system is a suitable framework to quantify cybersecurity risk in nuclear power plants. In addition to the plant dynamics, it is also important to model the strategies of the attackers and plant operators for an effective cybersecurity risk assessment. Game theory provides a set of necessary tools to model such strategic interactions. In this research, a framework that integrates dynamic probabilistic risk assessment with game theory for cybersecurity risk analysis in nuclear power plants is presented. The mathematical formulation is derived based on the theory of continuous event trees. We propose a game theory based action model, that utilizes physics-based rewards to define the strategies of attackers and operators at every decision epoch. As a case study, the risk associated with cyber-attacks on the digital components in the secondary side of a pressurized water reactor is studied using a reduced order model. A set of attacker actions and a set of operator actions are defined for the system. The operator and attacker interactions were modelled using simultaneous game, their action policies were computed using the concept of mixed strategy Nash equilibrium and the evolution of the system was studied.

97 MATHEMATICS AND COMPUTING↗

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING↗

Virtual Inspection of Advanced Manufacturing via Process-Scale Digital Twins (Abbreviated Report)

Inspection and certification comprise the most significant bottlenecks in advanced manufacturing for NNSA applications, often requiring far more time and resources than the fabrication of the parts themselves. Traditional methods, such as manual review and X-ray computed tomography, are not only slow and costly, but also struggle to provide a clear connection between manufacturing instructions and the final performance of critical components. This gap limits both the agility and assurance needed to support the modernization and safety of the United States nuclear stockpile. In response, our Strategic Initiative established a digital twin framework that integrates realtime process monitoring, automated data analysis, and immersive virtual reality collaboration into a unified inspection pipeline. By leveraging data from sensors, machine instructions, and imaging, we created high-fidelity virtual models of manufactured parts that could be rapidly analyzed and certified. This approach was first demonstrated with Direct Ink Write, and then extended to other manufacturing settings, including conventional (or “subtractive”) manufacturing and to predict the end of life performance of parts per the aging and lifetimes programs. The result is a transformational capability: inspection times have been reduced by a factor of 120,000 without loss of accuracy and while simultaneously improving traceability and confidence in part quality. This framework not only streamlines certification for critical applications, but also positions the national security enterprise to respond more flexibly to emerging challenges, supporting agile manufacturing and digital engineering practices across a broad range of mission-relevant domains.

42 ENGINEERING↗

NORTH DAKOTA CARBONSAFE PHASE III: SITE CHARACTERIZATION AND PERMITTING OF GEOLOGIC STORAGE OF CARBON DIOXIDE

The Energy & Environmental Research Center (EERC), in partnership with Minnkota Power Cooperative Inc. (Minnkota), SLB, and Computer Modelling Group Ltd. (CMG), supported wide-scale deployment of carbon capture and storage (CCS) as part of the U.S. Department of Energy (DOE) National Energy Technology Laboratory Carbon Storage Assurance Facility Enterprise (CarbonSAFE) Initiative Phase III. This phase included the acquisition, analysis, and development of information to fully characterize two storage complexes to demonstrate viable storage resources for commercial volumes of CO2 (defined by DOE as a minimum of 50 million tonnes [MMt] of CO2 within a 30-year period) (National Energy Technology Laboratory, 2024). Phase III also involved the preparation, submission, and approval of North Dakota underground injection control (UIC) Class VI storage facility permits (SFPs)—required precursors to applications for Class VI injection well permits. The presumed viability of commercial-scale CCS, situated adjacent to Minnkota’s Milton R. Young Station (MRYS), is validated by Minnkota’s continued pursuit of Project Tundra—an initiative to build the world’s largest lignite-based CCS project in central North Dakota (www.projecttundrand.com). Project Tundra comprises two scopes of work, Tundra Capture (installation of postcombustion CO2 capture at MRYS) and Tundra SGS (secure geologic storage). The efforts of North Dakota CarbonSAFE Phase III, Site Characterization and Permitting, supported Tundra SGS. Extensive site-specific characterization activities included a successful multimeasurement geophysical approach and drilling a stratigraphic test well (J-ROC 1, subsequently renamed Liberty-1) adjacent to MRYS. Core collection and analyses, downhole testing and fluid sampling, and geophysical logging were performed on J-ROC 1 and on a nearby stratigraphic test well (known as J-LOC 1), which was drilled, cored, and tested under a complementary project funded by the North Dakota Lignite Research Program. The injection tests performed on J-LOC 1 positively impacted the CarbonSAFE project, resulting in fewer proposed injection wells and significant construction, operations, and monitoring cost savings. The characterization data collected and analyses performed were integrated into geologic models, and successive numerical simulations were run to determine CO2 plume extent and subsurface pressure buildup associated with the planned CO2 injection rate of nearly 4 MMt per year. The latter doubles the CarbonSAFE Initiative goal with an estimated 100 MMt of CO2 stored in 20 years. Application of the U.S. Environmental Protection Agency’s (EPA’s) method for estimating the Class VI Rule area of review (AOR) to the overpressurized Broom Creek Formation inspired an alternative method of calculation, called risk-based AOR delineation. This peer-reviewed method was applied for the first time during the storage facility-permitting process. The two SFP applications submitted in 2021 successfully resulted in North Dakota Industrial Commission (NDIC) orders in 2022 authorizing the creation of the storage facility areas and amalgamation of pore space as well as establishing financial responsibility requirements. After approval of the SFPs, Minnkota filed in 2022 applications for permits to reenter the J-ROC 1 well and to drill two new wells—all with the intended purpose to become Class VI injection wells. To establish eligibility under the Internal Revenue Code for Section 45Q tax incentives, a monitoring, reporting, and verification (MRV) plan was prepared and submitted by Minnkota to EPA in 2022, resulting in the first such plan approved in North Dakota. Also in 2022, under the National Environmental Policy Act (NEPA), Minnkota prepared and submitted an environmental information volume (EIV) describing the proposed CCS project and associated potential environmental impacts. Based on the EIV, DOE determined that the proposed construction project required an environmental assessment, and Minnkota submitted the first draft in 2023 and a revised draft in 2024. Both submissions were followed by a public comment period. Subsequently, DOE issued a finding of no significant impact (FONSI) on September 13, 2024. A successful outreach program, strongly based in the production, presentation, and dissemination of informational material, fostered an environment to aid stakeholders in making informed decisions regarding the planned project. Opportunities for public input were provided at various steps along the way, including at county planning and zoning meetings, before and during the SFP administrative hearing, and during environmental assessment public comment periods. In addition, land/pore space owners and mineral owners had various points of contact, including granting access rights, securing pore space leasing, and mineral owner notifications. Based upon the successful storage facility permitting issued by NDIC, approval of the MRV plan by EPA, and receipt of a FONSI under the NEPA, Minnkota is continuing its pursuit of Project Tundra. In December 2023, the Office of Clean Energy Demonstrations under its Carbon Capture Demonstrations Projects Program announced funding for the capture system (Office of Clean Energy Demonstrations, 2023) and a proposal for CarbonSAFE Phase IV: Construction funding was submitted in March 2024 for the storage project. A go/no-go decision to proceed with construction and operations in the Broom Creek Formation is anticipated in 2024. References National Energy Technology Laboratory, CarbonSafe Initiative, https://netl.doe.gov/carbon-management/carbon-storage/carbonsafe (accessed August 2024). Office of Clean Energy Demonstrations, 2023, OCED selects three projects in CA, ND, and TX to reduce harmful carbon pollution, create new economic opportunities, and advance carbon reducing technologies, December, www.energy.gov/oced/articles/oced-selects-three-projects-ca-nd-and-tx-reduce-harmful-carbon-pollution-create-new (accessed August 2024).

Peck, Wesley↗

Ultra-Low Disorder Graphene Quantum Dot-Based Spin Qubits for Cyber Secure Fossil Energy Infrastructure (Final Technical Report)

The overarching goal of the proposed project is to demonstrate the feasibility of creating ultralow local disorder graphene quantum dots (GQDs)-based high-speed, high-fidelity spin quantum bits (qubits) for extremely cyber-secure coal energy plants of the future. Despite their inherent benefits, the coherence times in the state-of-the-art GQD qubits are still low primarily due to the local disorder in GQD devices generated during lithographic fabrication of GQDs. Hence, the focus of this research is to prepare ultralow disorder GQDs (e.g., edge roughness ~0.5nm) and evaluate the low temperature (~mK) charge/spin transport characteristics of the engineered GQD qubit platform. To achieve minimal disorder in GQD qubits, we employ a novel approach that combines nanotomy (novel GQD fabrication technique developed by the PI) and scanning probe microscopy-atomic oxidation lithography (SPM-AOL).

20 FOSSIL-FUELED POWER PLANTS↗

Draft Feasibility Assessment for Use of AI in Preparing Transportation Safety Analysis Reports

Preparing transportation safety analysis reports for microreactors is time and labor intensive, requiring extensive cross referencing to Federal regulations, previously approved documents, and expert review comments across structural, thermal, criticality, shielding, containment, and security. These burdens are magnified by the novelty of microreactor technologies and the evolving regulatory landscape, as well as current workforce constraints. Generative AI and supporting machine learning tools present an opportunity to accelerate drafting timelines, lift generalized writing burdens, and systematically enforce regulatory adherence through retrieval augmented generation and other knowledge retrieval and mapping methods. This draft report presents a preliminary feasibility assessment of the use of AI to expedite the preparation of microreactor transportation safety analysis reports and proposes an initial methodology for doing so.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

LivChat.....So Far

This presentation provides an overview of LivChat, a managed ChatGPT service developed by Lawrence Livermore National Laboratory (LLNL) under the auspices of the U.S. Department of Energy. The initiative was driven by a high demand for generative AI services, the need for enhanced security, and the goal of increasing productivity across various use cases. The development journey involved exploring open-source models and iterating with OpenAI/Azure solutions. The presentation delves into the architecture of LivChat, highlighting its user interface (UI) and backend components. The backend is designed to be separate, RESTful, integrative, and scalable, ensuring robust performance and adaptability. Despite the advanced technology, the presentation emphasizes that LivChat is not a magical solution but a sophisticated tool that requires realistic expectations. Looking ahead, the presentation outlines future directions for LivChat, including training, retrieval-augmented generation (RAG), and innovative ingestion methods. These advancements aim to further enhance the capabilities and applications of LivChat, ensuring it remains at the forefront of generative AI services.

Computer science↗

Enterprise Artificial Intelligence Strategy for Los Alamos National Laboratory

In the 1984 martial arts drama film, The Karate Kid, a young Daniel LaRusso is unexpectedly placed in an adversarial environment unable to eYectively adapt to a series of new threats and limitations. Fortunately for the main character, once placed under the tutelage of a Mr. Miyagi, he finds resiliency not through the adoption of new tools, but a re-focused set of fundamentals. Much in the same way that Daniel learns waxing on and buYing oY car wax by hand has rewards for Karate, LANL is choosing the harder path of self-hosting Large Language Models (LLMs) for enterprise use instead of only relying on buying access to a hosted AI service like Azure’s OpenAI Application Programming Interface (API). We also are not willing to wait for software-as-a-service (SAAS) AI services to meet us where we need to be from a FedRAMP accreditation standpoint. Our operations regularly depend on access at CUI, UCNI, ITAR and other FIPS-199 moderate-impact data levels and hosting our own services gives us the right security and compliance posture to be useful across the broad range of our work at LANL. With the rise in threats to critical infrastructure, cloud service providers (CSPs), and supply chain attacks from both state and non-state actors, we are not placing the bet that SAAS hosted AI services will be available when we need them. Should a major event occur, we do not want our staY and operations left without a pathway for us to fix the problem and resume the use of AI tools.

42 ENGINEERING↗

CI-MOR Final Report: Analysis and Validation of Critical Infrastructure Models using Model Order Reduction

This report summarizes the research and capabilities developed as part of the project “Analysis and Validation of Critical Infrastructure Models using Model Order Reduction” (CI-MOR) LDRD project. CI-MOR research enables the solution of large, complex optimization models that naturally arise in national security challenges involving critical infrastructures. Specifically, CI-MOR researchers developed methods to (1) rigorously approximate complex, nonlinear optimization formulations, (2) identify alternative near-optimal solutions, (3) accelerate optimization workflows used for complex applications, and (4) rigorously integrate domain knowledge in stochastic-process models. This report provides an overview of the research done in CI-MOR, and we describe application exemplars used to illustrate CI-MOR capabilities. Furthermore, we describe the software developed by CI-MOR that researchers can leverage to analyze new applications.

97 MATHEMATICS AND COMPUTING↗

Arctic Critical Infrastructure: Assessing and Predicting the Risk to Critical Permafrost Infrastructure from Climate Change: A New Thermomechanical Approach

This study presents the development of a computational framework designed to predict the interaction between permafrost and infrastructure, addressing potential failure modes and mitigation strategies in the context of climate change. The framework, rooted in advanced modeling and simulation (mod/sim) techniques, integrates thermomechanical coupling to account for the complex interplay between heat flow, ice content, and mechanical behavior in permafrost. Existing models fail to fully capture these dynamics, particularly as they relate to the effects of ice saturation on structural integrity. Our innovative Arctic Coastal Erosion (ACE) framework fills this gap by coupling thermal and mechanical models to accurately simulate subsidence and deformation in permafrost environments. We applied the ACE framework to a representative runway, demonstrating its capability to predict settlement due to rising temperatures and subsequent permafrost thaw. This proof-of-concept showcases the potential of the framework to evaluate risks to Arctic infrastructure, which supports over four million people and 70% of existing permafrost-based structures. By simulating various infrastructure types and environmental conditions, our research offers insights into failure mechanisms and evaluates structural solutions to mitigate risk. The anticipated deliverables, including a prototype runway exemplar, position this project as a critical advancement in permafrost infrastructure modeling, with applications in national security and resilience planning.

54 ENVIRONMENTAL SCIENCES↗

Integrity Enhancing Protocols: Performance and Recommendations for Nuclear Systems

In today’s communication landscape there are multiple technologies and protocols used for communication between end devices. Within security paradigms for these protocols, integrity management is a common goal of system designers. Communication protocols focused on maintaining message integrity can provide assurance that some received data has not been altered or tampered with. While integrity is often coupled with confidentiality in protocol design, this analysis focuses on an evaluation of only integrity protocols. This report outlines various ways message integrity may be preserved with respect to high performance operational technology (OT) systems. It describes a series of experiments and an evaluation framework used to evaluate the performance of the identified integrity approaches regarding common system design goals. Finally, it addresses the testing environment utilized and closes the report with a summary of experimental results.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Science & Technology Review December 2025 - Optimizing Future Design

At Lawrence Livermore National Laboratory, we focus on science and technology research to ensure our nation’s security. We also apply that expertise to solve other important national problems in energy, bioscience, and the environment. Science & Technology Review is published eight times a year to communicate, to a broad audience, the Laboratory’s scientific and technological accomplishments in fulfilling its primary missions. The publication’s goal is to help readers understand these accomplishments and appreciate their value to the individual citizen, the nation, and the world.

36 MATERIALS SCIENCE↗