Search NASA⌕ Search

SEARCH · Search NASA

Results for “Industrial Control Systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Self-Supervised and Interpretable Anomaly Detection Using Network Transformers

Machine learning and deep neural networks (DNNs) have been proposed as a tool to identify anomalies in computer network communications. However, due the obfuscated nature of off-the-shelf machine learning models, their output often does not provide enough information to isolate the source of the anomaly to take corrective measures. In this article, we introduce the network transformer (NeT), a DNN model for anomaly detection that incorporates the graph structure of the communication network in order to improve interpretability. Further, the presented approach has the following advantages: first, enhanced interpretability by incorporating the graph structure of computer networks; second, provides a hierarchical set of features that enables analysis at different levels of granularity; second, self-supervised training that does not require labeled data. The NeT model was evaluated on a set of anomalous scenarios executed in a real industrial control system. The presented approach successfully identified the anomalies, the devices affected, and the specific connections causing the anomalies, providing a data-driven hierarchical approach to analyze the behavior of a cyber network.

97 MATHEMATICS AND COMPUTING↗

MARIAH PCAP data for Validation Demonstration

This dataset holds simulated PCAP (packet capture) data from the SCEPTRE validation demonstration model as a set of pairwise communications between devices via specific protocols. All connections should be assumed to be symmetric, as this data is an aggregation of the true PCAP. A mapping is also provided associating each IP address with its true device type.

cyber-physical system↗

Cytrics Repository Of Analysis Tools And Engineering Resources

Cybersecurity Testing for Resilient Industrial Control Systems (CyTRICS) is a DOE-funded project that works with vendors to evaluate the cybersecurity of equipment used in US critical infrastructure. In the process of testing systems, CyTRICS researchers often develop custom tools. The tools in this repository were developed during multiple CyTRICS tests to assist with the testing process. They help solve problems encountered by CyTRICS researchers and address uncommon testing subjects for which limited tooling is available. They are useful to other researchers working on similar systems and architectures.

Laird, SutterE↗

AdCyDER Attack Simulator

SF-25-117 A framework for simulating various cyber attacks on industrial control systems and SCADA environments.

Blakely, Benjamin↗

Cyote-attack Chain Estimator

Attack Chain Estimator (ACE) Application Overview The Attack Chain Estimator (ACE) Application is a sophisticated tool designed for the ingestion, classification, sequencing, and enrichment of cybersecurity threat reports. This application leverages advanced machine learning models and extensive historical data to provide comprehensive insights into cyber threats, specifically targeting Industrial Control Systems (ICS). Purpose The primary functions of the ACE Application include: Ingestion of Cybersecurity Threat Reporting: Capable of ingesting text-based threat reports in markdown or text file format. Supports ingestion of structured data from other sources in STIX/JSON format. Classification of Report’s Text-Based Events: Utilizes a DeBERTa classifier, specifically trained on cybersecurity data, to map the events to MITRE ATT&CK for ICS Tactics and Techniques. Classification is performed using multiple Jupyter notebooks and machine learning workflows hosted as FastAPI microservices: regex_data deberta_base_35_train_hft_classifier_mlflow.ipynb hft_regex_classifier_mlflow.ipynb param_train_hft_classifier_mlflow.ipynb regex_tactic_tech.ipynb Ordering of Tactics, Techniques, and Observable Events: Sequences the identified tactics, techniques, and events to form a coherent attack chain. Enrichment with Historical Attack Chain Details: Enhances the attack chain with details from historical attacks using a Markov model developed from CyOTE Precursor Analysis Report data. The Markov model is available as a FastAPI endpoint for seamless integration. Enrichment with Adversary Emulation Capabilities Data: Integrates adversary emulation capabilities data using MITRE Caldera for OT adversary abilities UUIDs. Export of Output Files: Provides options to export the enriched attack chain in JSON or CSV formats. Routing of Output to Other Applications: Facilitates routing of output to various platforms and applications, including: Threat Intelligence Platforms COREII Scout for Threat Intelligence Analysis COREII Modeling and Simulation for Adversary Emulation Technical Description The ACE Application is an advanced cybersecurity tool designed to provide detailed threat analysis and sequence generation. It is built on a robust architecture that integrates natural language processing, machine learning, and historical data modeling. Key Components: Data Ingestion Module: Handles the input of threat reports and data from various formats, ensuring flexibility in data sources. Classification Engine: Employs DeBERTa-based classifiers hosted as FastAPI microservices to analyze and classify threat report events in accordance with the MITRE ATT&CK framework for ICS. Sequence Generator: Orders the classified events into a logical attack chain, providing clear insight into the sequence of tactics and techniques used in the threat. Enrichment Engine: Integrates historical data and adversary emulation capabilities to enhance the attack chain with valuable context and additional details. The historical data enrichment is powered by a Markov model, which is available as a FastAPI endpoint. Export and Routing Module: Facilitates the export of the enriched attack chain in multiple formats and routes the output to designated applications for further analysis or emulation.

Paul, Tony [Idaho National Laboratory (INL), Idaho↗

5G integrated edge computing platform for efficient component monitoring in coal-fired power plants

This project developed a cutting-edge 5G-integrated edge computing framework to enhance operational efficiency and reliability in coal-fired power plants through real-time component monitoring and anomaly detection. The initiative focused on leveraging distributed machine learning, federated learning, and 5G-based dynamic network slicing to support scalable, fault-tolerant monitoring environments to meet the operational requirements in industrial control systems. With a Distributed Edge Computing Service (DECS) orchestration, this project enabled federated learning at edge for condition monitoring and introduced adaptive client selection strategies to minimize communication overhead. Scalable distributed training was achieved using the Horovod framework, thus enhancing performance across edge nodes. In the realm of 5G networking, the project designed and deployed reconfigurable, QoS-aware network slicing tailored for operational technology (OT) environments, integrating software-defined networks to bolster cyber-resilience and enabling dynamic slicing for federated learning workloads. A significant milestone was the development of a virtualized ICS environment with 5G core integration—which allowed elastic and fault tolerant distributed training on real-world datasets such as NASA Bearings, Hydraulic Systems, and TEP. To broaden the impact of the project, a TRL-3 virtualized ICS testbed for research and education was designed. This project engaged several graduate and undergraduate students to conduct research on the cutting-edge technology, and it resulted in one PhD dissertation, one MS thesis, and over 14 peer-reviewed publications. With the support of this project students also participated in national cybersecurity competitions to improve their professional development skills.

20 FOSSIL-FUELED POWER PLANTS↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Mixed Reality Training and Workspace Integration

Mixed reality technology is being used across Idaho National Laboratory (INL) to enhance training and workforce development. Projects involving mixed reality such as lockout/tagout , the Industrial Control System Laboratory , and a Department of Defense microreactor demonstration have benefited from these innovative approaches. Several key concerns exist with integrating this new technology, including ease of use, ease of setup, and maintenance through the lifecycle. These aspects need to be properly addressed to ensure that this technology remains attractive and useful to operations teams as well as engineers and researchers at INL. Primarily, this requires buy-in from information technology management, designing software/hardware-agnostic tools, and reducing friction with technology integration. To be successful, regular operational use of this new and unfamiliar technology will require straightforward user interfaces, simple setup processes, and feature-rich experiences that reduce the time needed to benefit from the technology. INL is improving its toolset to allow for a streamlined deployment and use of mixed reality technologies that are directly available to researchers and engineers.

99 GENERAL AND MISCELLANEOUS↗

Capabilities for Water Sector Infrastructure Resilience - Prioritizing RD&D in a Target Rich, Resource Poor Sector

WSTB & Water Sector Security Program Expansion Objective: Incubate and shepherd a public-private consortium of joint seal US government sponsors and industry stakeholders to build out industrial control system (ICS) and operational technology (OT) architecture of the Idaho National Laboratory (INL) Water Security Test Bed (WSTB) asset to enable research, testing, and cyber workforce training related to evolving cyber-physical and physical vulnerabilities and threats in the water sector.

99 - GENERAL AND MISCELLANEOUS↗

From natural language to control signals: a conceptual framework for semantic channel finding in complex experimental infrastructure

Modern experimental platforms such as particle accelerators, fusion devices, telescopes, and industrial process control systems expose tens to hundreds of thousands of control and diagnostic channels, accumulated over decades of hardware evolution. Operators and AI systems alike depend on informal expert knowledge, inconsistent naming conventions, and scattered documentation to locate the signals required for monitoring, troubleshooting, and automated control, creating a persistent bottleneck for reliability, scalability, and emerging language-model-driven interfaces. We formalize semantic channel finding, the task of mapping natural-language intent to concrete control-system signals, as a general problem in complex experimental infrastructure, and introduce a four-paradigm conceptual framework to guide architecture selection based on facility-specific data regimes. The paradigms span (i) direct in-context lookup over small, curated channel dictionaries, (ii) constrained hierarchical navigation through structured trees, (iii) interactive agent exploration using iterative reasoning and tool-based database queries, and (iv) ontology-grounded semantic search that decouples channel meaning from facility-specific naming conventions. We demonstrate the practical feasibility of each paradigm through proof-of-concept implementations at four operational facilities spanning two orders of magnitude in scale: from compact free-electron lasers to large synchrotron light sources, operating under diverse control-system architectures ranging from clean hierarchical naming schemes to legacy environments with decades of heterogeneous conventions. Where evaluated against expert-curated operational queries, these instantiations achieve 90%–97% accuracy, validating the framework’s applicability across real-world deployment scenarios. To accelerate adoption across the broader scientific and industrial control-system community, we release open-source, plug-and-play implementations of all three interactive paradigms-direct lookup, hierarchical navigation, and middle-layer exploration-within the Osprey framework, together with tools for channel database generation, interactive testing, and minimal-configuration deployment. This work establishes semantic channel finding as a foundational capability for human-centric and agentic AI interfaces at large-scale facilities, providing both a systematic framework for architecture design and practical resources to enable adoption without building custom infrastructure from scratch.

channel finding↗

Bridging the Gap Between Modern UX Design and Particle Accelerator Control Room Interfaces

Accelerator control systems often represent relatively complex and safety-sensitive human-machine interfaces within process control industries. These systems are technically robust and reflect the cumulative integration of solutions built and adapted across decades. One of the regular, unfortunate casualties of provisional accelerator control system updates is their human-system interfaces (HSIs) which often lag behind modern usability and design standards. An additional challenge is that although there is a multitude of established human factors (HF), and user experience (UX) principles for everyday digital applications, there are very few (if any) established principles for complex and safety-critical applications for an accelerator. This paper argues for the importance of established HF and UX principles (herein referred to as human-centered design principles) into the development of accelerator HSIs, emphasizing the need for clarity, consistency, responsiveness, and cognitive accessibility. Drawing from HF/UX best practices and human-centered design, this paper discusses how these approaches can enhance operator performance, reduce human error, and improve accelerator personnel collaboration. Case studies from Accelerator Control Operations Research Network (ACORN) at Fermilab are explored to demonstrate how interfaces built with human-centered design principles can scale with system complexity while remaining intuitive and efficient for diverse user roles including operators, machine experts, and engineers. By bridging the gap between traditional control system design and modern human-centered design methods, this paper provides a roadmap for evolving accelerator HSIs into more usable, maintainable, and effective tools.

Hill, Rachael [Idaho Natl. Lab.]↗

Transformer Neural Networks with Spatiotemporal Attention for Predictive Control and Optimization of Industrial Processes

In the context of real-time optimization and model predictive control of industrial systems, machine learning, and neural networks represent cutting-edge tools that hold promise for enhancing dynamic modeling. This work presents a novel transformer neural network architecture for real-time optimization and model predictive control. This network design includes a modified attention mechanism inspired by positional embedding attention from vision transformers and task-specific modifications to the input-output structure of the transformer’s decoder stack. Experiments were conducted using data from a 450 MW coal-fired power plant to evaluate this approach's effectiveness. The transformer neural network was compared with conventional recurrent models, including GRU and LSTM. The transformer exhibited a 6% increase in the R-squared (R2) value of predictions and an 83% reduction in mean squared error (MSE). Computation time was also reduced by 84% compared to conventional recurrent models.

Gallup, Ethan R.↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

Cyber-Informed Engineering (CIE) Guidance to Defeat Systematic OT Weaknesses

This research summary outlines the University of Illinois Information Trust Institute (ITI) team's evaluation of whether applying the 12 Cyber-Informed Engineering (CIE) Principles could reduce or eliminate weaknesses identified by the SEI-ETF in engineered systems. ITI's findings suggest that applying CIE principles to weaknesses in MITRE CWE View 1358 can potentially mitigate or eliminate those vulnerabilities.

42 ENGINEERING↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

Cyber-Informed Engineering Validation Methods and Guidance

Validation is an important step in any systems engineering process to ensure the correct system was made to fulfill stakeholders’ needs, goals, and expectations. In the context of Cyber-Informed Engineering (CIE), validation ensures cyber impact is reduced through implemented design choices and CIE requirements. This document details a process in validating CIE-based design choices relative to their effectiveness at mitigating high consequence events. The document includes a case study to illustrate the CIE validation process. The case study explores the implementation of CIE validation within the engineering lifecycle of a chemical mixing plant.

42 ENGINEERING↗