Search NASA⌕ Search

SEARCH · Search NASA

Results for “Attack Surface”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Residential Vehicle-to-Home Backup Power Capabilities: Key Findings from a ComEd Beneficial Electrification R&D Pilot

This report summarizes key findings from a collaborative technical study of residential, non-grid-tied vehicle-to-home (V2H) backup power systems in Commonwealth Edison’s (ComEd’s) service territory. The work integrates (1) a feeder-level technoeconomic analysis (TEA) using historical outage-event data and simulated electric-vehicle (EV) driving/charging profiles to estimate potential reliability and customer interruption-cost impacts under V2H and vehicle-to-grid (V2G) adoption scenarios; (2) controlled laboratory performance testing of a representative V2H backup ecosystem to characterize transfer-to-backup behavior, sustained power delivery, efficiency trends, and repeatable reliability limitations; and (3) a cybersecurity assessment aligned with NIST Cybersecurity Framework (CSF) 2.0 and ISO/SAE 21434 to evaluate interface-level risk drivers and identify program-relevant mitigations. Results indicate that V2H can provide measurable resilience value, but outcomes are strongly context dependent on outage patterns and the share of events that are “V2H-applicable.” Typical transfer-to-backup behavior clustered on the order of minutes, but rare long-delay edge cases were observed (including an event approaching 30 minutes) and should be treated as a reliability risk. High-power testing showed that peak-rated output is not necessarily continuously deliverable; stable operation may require operation below nameplate ratings and attention to thermal and installation constraints. The cybersecurity assessment highlights a broad attack surface spanning commissioning, home networks, embedded services, and cloud/OTA pathways, motivating minimum controls for secure onboarding, signed updates, patch cadence, and coordinated vulnerability response for any scaled deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Roadmap for Solar Photovoltaic (PV) Cybersecurity: A vision for improving cyber maturity of distributed and utility-scale solar energy installations

As the solar energy sector continues to expand, its integration into the broader energy infrastructure presents both unprecedented opportunities and new risks. The increasing reliance on digital technologies and interconnected systems in solar energy creates an expanded attack surface for motivated cyber adversaries. Cyberattacks have the potential to cause disruptions in energy production, damage to equipment, financial losses, and compromises in national security. Therefore, ensuring robust cybersecurity measures is paramount to protect the integrity, availability, confidentiality, and access control of solar energy systems. However, there are still key gaps and challenges to be addressed in industry and research, which stakeholders must race to address as they combat a growing number of real-world cyber incidents that affect solar energy systems and a growing number of vulnerabilities discovered and disclosed in key types of equipment. This roadmap explore the current state of solar PV cybersecurity and the gaps and challenges still to be addressed.

14 - SOLAR ENERGY↗

Responsible Artificial Intelligence for Insider Threat Mitigation

This report examines the application of artificial intelligence (AI) technologies for insider threat mitigation (ITM) programs in nuclear security facilities. Insider threat detection presents unique challenges due to the subtle and adaptive nature of these threats, the complex signatures involved, and the scarcity of available data for analysis. Traditional human-centered approaches, while essential, face limitations in processing large amounts of data continuously and detecting subtle patterns across multiple systems. AI technologies can potentially address these limitations by providing 24/7 monitoring capabilities, identifying complex patterns that might escape human observation, and offering consistent application of security criteria. However, the deployment of AI in nuclear security contexts introduces significant new risks, including workflow disruption, expanded attack surfaces, potential for misuse, and ethical concerns regarding privacy, fairness, transparency, safety, and security. The high-consequence nature of nuclear security decisions demands careful consideration of these risks and systematic approaches to their mitigation.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Building Nuclear-Specific Cybersecurity Expertise in Higher Education

The rapid digitalization of nuclear power plants (NPPs) and the deployment of advanced and small modular reactors (A/SMRs) have expanded the cybersecurity attack surface within the nuclear sector. This evolution introduces unique challenges beyond those faced in general information technology (IT), operational technology (OT) and industrial control system (ICS) security, due to nuclear power’s regulatory rigor, safety-critical nature, and operational needs. A pressing workforce gap persists; cybersecurity graduates typically lack nuclear-specific context and retraining them for industry readiness requires 12–18 months, creating a significant burden. This paper addresses this gap by defining the domains of knowledge that nuclear cybersecurity specialists must master, spanning cybersecurity, nuclear engineering, OT/ICS security, and regulatory governance. We propose a curricular framework integrating technical, regulatory, and applied learning components to accelerate workforce readiness. Our approach builds on existing findings that current curricula inadequately integrate nuclear engineering and cybersecurity, shifting the discourse from why specialization is needed to what knowledge must be taught. The recommendations have implications for workforce development and long-term resilience of the nuclear energy sector.

99 - GENERAL AND MISCELLANEOUS↗

Design definition study of a lift/cruise fan technology V/STOL aircraft. Volume 1: Navy operational aircraft

Aircraft were designed and sized to meet Navy mission requirements. Five missions were established for evaluation: anti-submarine warfare (ASW), surface attack (SA), combat search and rescue (CSAR), surveillance (SURV), and vertical on-board delivery (VOD). All missions were performed with a short takeoff and a vertical landing. The aircraft were defined using existing J97-GE gas generators or reasonable growth derivatives in conjunction with turbotip fans reflecting LF460 type technology. The multipurpose aircraft configuration established for U.S. Navy missions utilizes the turbotip driven lift/cruise fan concept for V/STOL aircraft.

Source record↗

Design definition study of NASA/Navy lift/cruise fan V/STOL aircraft. Volume 1: Summary report of Navy multimission aircraft

This report presents results of a study by the Rockwell International Corporation for the NASA Ames Research Center and the Naval Air Systems Command of promising Navy lift-cruise fan V/STOL aircraft for the 1980-1985 time period. The purpose of the study was to identify the likely technical and operating characteristics and technology requirements for the ultimate development of this type aircraft. The study focused on identifying aircraft individually optimized to perform the anti-submarine warfare, carrier onboard delivery, combat search and rescue, surveillance and surface attack missions, and a multi-purpose aircraft concept capable of performing all five missions at minimum total program cost. The configuration features the use of two 1.3 fan pressure ratio, single stage lift-cruise fans and three current design J97 gas generators with a high mounted high aspect ratio wing with winglets. The design missions can be performed at takeoff weights ranging from approximately 32,000 to 39,000 pounds. Top speed is 0.80 Mach number at sea level and 0.885 at altitude, Advanced composite structural technology and advanced subsystem concepts are employed. One basic fuselage design, with alternate bolt-in floor structures, meets all the mission requirements.

Robert L Cavage↗

Type 'A' V/STOL - One aircraft for all support missions

An investigation is conducted regarding the feasibility of developing a single support aircraft type for the Navy, taking into account the current naval inventory of utility aircraft types. Support mission characteristics are examined, giving attention to antisubmarine warfare, airborne early warning, marine assault, carrier on board delivery/vertical on board delivery, the aerial tanker mission, long-range rescue, surface attack, and aspects of combat, search, and rescue. With the aid of a sample design for a V/STOL aircraft with a medium disc loading lift system it is demonstrated that it is now possible to design an aircraft which, with minor modifications, can meet the wide variety of support missions.

Adelt, W. H.↗

A supercritical airfoil experiment

The purpose of this investigation is to provide a comprehensive data base for the validation of numerical simulations. The initial results of the study (single angle of attack) were presented in ref. 1, where the effects of various parameters and the adequacies of selected turbulence models were discussed. The objective of the present paper is to provide a tabulation of the experimental data. The data were obtained in the two-dimensional, transonic flowfield surrounding a supercritical airfoil. A variety of flows were studied in which the boundary layer at the trailing edge of the model was either attached or separated. Unsteady flows were avoided by controlling the Mach number and angle of attack. Surface pressures were measured on both the model and wind tunnel walls, and the flowfield surrounding the model was documented using a laser Doppler velocimeter (LDV). Although wall interference could not be completely eliminated, its effect was minimized by employing the following techniques. Sidewall boundary layers were reduced by aspiration, and upper and lower walls were contoured to accommodate the flow around the model and the boundary-layer growth on the tunnel walls. A data base with minimal interference from a tunnel with solid walls provides an ideal basis for evaluating the development of codes for the transonic speed range because the codes can include the wall boundary conditions more precisely than interference corrections can be made to the data sets.

Mateer, George G.↗

A supercritical airfoil experiment

The purpose of this investigation is to provide a comprehensive data base for the validation of numerical simulations. The objective of the present paper is to provide a tabulation of the experimental data. The data were obtained in the two-dimensional, transonic flowfield surrounding a supercritical airfoil. A variety of flows were studied in which the boundary layer at the trailing edge of the model was either attached or separated. Unsteady flows were avoided by controlling the Mach number and angle of attack. Surface pressures were measured on both the model and wind tunnel walls, and the flowfield surrounding the model was documented using a laser Doppler velocimeter (LDV). Although wall interference could not be completely eliminated, its effect was minimized by employing the following techniques. Sidewall boundary layers were reduced by aspiration, and upper and lower walls were contoured to accommodate the flow around the model and the boundary-layer growth on the tunnel walls. A data base with minimal interference from a tunnel with solid walls provides an ideal basis for evaluating the development of codes for the transonic speed range because the codes can include the wall boundary conditions more precisely than interference connections can be made to the data sets.

Mateer, G. G.↗

Rhenium/Oxygen Interactions at Elevated Temperatures

The oxidation of pure rhenium is examined from 600-1400 C in oxygen/argon mixtures. Linear weight loss kinetics are observed. Gas pressures, flow rates, and temperatures are methodically varied to determine the rate controlling steps. The reaction at 600 and 800 C appears to be controlled by a chemical reaction step at the surface; whereas the higher temperature reactions appear to be controlled by gas phase diffusion of oxygen to the rhenium surface. Attack of the rhenium appears to be along grain boundaries and crystallographic planes.

Jacobson, Nathan↗

Addressing Software Security

Historically security within organizations was thought of as an IT function (web sites/servers, email, workstation patching, etc.) Threat landscape has evolved (Script Kiddies, Hackers, Advanced Persistent Threat (APT), Nation States, etc.) Attack surface has expanded -Networks interconnected!! Some security posture factors Network Layer (Routers, Firewalls, etc.) Computer Network Defense (IPS/IDS, Sensors, Continuous Monitoring, etc.) Industrial Control Systems (ICS) Software Security (COTS, FOSS, Custom, etc.)

software↗

NASA Blue Team: Determining Operational Security Posture of Critical Systems and Networks

Emergence of Cybersecurity has increased the focus on security risks to Information Technology (IT) assets going beyond traditional Information Assurance (IA) concerns: More sophisticated threats have emerged from increasing sources as advanced hacker tools and techniques have emerged and proliferated to broaden the attack surface available across globally interconnected networks.

cybersecurity↗

Empowering Critical Infrastructure Communication with Secure 5G Private Networks

With the transformational New Radio- Unlicensed (NR-U), 5G network can be operated with unlicensed and shared spectrum. Private 5G networks without any licensed bands, which are both highly expensive and usually available to only large commercial wireless providers, can now be used for a whole range of new applications including smart factories, warehouses, connected cars and drones. 5G’s support of a) massive machine type communication (mMTC) for a large number of connected devices with b) ultra-reliable low latency communication (URLLC) capability when needed, and c) up to 20 times higher data rate with enhanced mobile broadband (eMBB) than previously available, enables new and powerful capabilities in a wireless network. While these capabilities are transformational, necessary security and reliability requirements have to be satisfied when used in critical infrastructure such as factories, power plants, water systems, ports, and other industrial facilities. 5G standards have introduced significant security improvement over 4G/LTE as well as mitigations for new attack surfaces created by changes in the 5G network. This talk will discuss these security improvements and whether they meet the security properties required for mission critical communication over wireless.

5G↗

Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The future of the grid will be powered by AI—or undermined by it. Artificial intelligence is rapidly reshaping grid operations, improving fault detection, forecasting accuracy, and real-time optimization. As AI systems move closer to operational decision loops, however, they introduce new consequence pathways: expanded attack surfaces, model integrity risks, regulatory exposure, and human-automation challenges. This talk presents a consequence-driven framework for deploying AI responsibly in the electric grid. Attendees will gain practical strategies to strengthen resilience, boost reliability, and deploy AI securely — ensuring the grid of the future is not only smarter but safer.

25 - ENERGY STORAGE↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Modeling Cyber Supply Chain Incidents with Multilayered Graph Motifs

As noted within the literature, supply chain includes people and organizations---manufacturers, integrators, and third-party vendors---that are involved in one or more stages of a product lifecycle. Since supply chains, by definition, include organizations and people, supply chain risk management activities must consider dependencies between an organization's business processes and third-party resources. Just as adversarial tactics can be implemented via techniques implemented via networked computer systems, so can such tactics be expressed via legal business relationships. A cyber incident may have an exponential impact downstream, for example, by leveraging a product's distribution channel (e.g. malicious updates in SolarWinds, buggy updates in CrowdStrike). Similarly, legitimate and legal business relationships also affect the attack surface exposure of systems, enabling long-term persistence and/or unknown impacts to product quality that are hard to detect. This paper catalogs several recent digital supply chain incidents and applies a multilayered network formalism to develop structural indicators (graph motifs) that reflect potentially-adversarial behavior. Finally, we compare and contrast the characteristics of adversarial tactics (e.g. Loss of Availability, Data Collection) that leverage cyber-physical dependencies to those that leverage legal organizational relationships.

97 - MATHEMATICS AND COMPUTING↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Normal- and oblique-shock flow parameters in equilibrium air including attached-shock solutions for surfaces at angles of attack, sweep, and dihedral

Normal- and oblique-shock flow parameters for air in thermochemical equilibrium are tabulated as a function of shock angle for altitudes ranging from 15.24 km to 91.44 km in increments of 7.62 km at selected hypersonic speeds. Post-shock parameters tabulated include flow-deflection angle, velocity, Mach number, compressibility factor, isentropic exponent, viscosity, Reynolds number, entropy difference, and static pressure, temperature, density, and enthalpy ratios across the shock. A procedure is presented for obtaining oblique-shock flow properties in equilibrium air on surfaces at various angles of attack, sweep, and dihedral by use of the two-dimensional tabulations. Plots of the flow parameters against flow-deflection angle are presented at altitudes of 30.48, 60.96, and 91.44 km for various stream velocities.

Hunt, J. L.↗