Search NASASearch

SEARCH · Search NASA

Results for “Operational Technology”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Precursor Analysis Report: Blackmatter Ransomware Attack on New Cooperative 2021

The BlackMatter Ransomware Attack on New Cooperative 2021 Precursor Analysis Report leverages publicly available information about the New Cooperative cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The BlackMatter ransomware was first identified in July 2021 and is reported to have infected more than 50 corporations around the world. , The Iowa-based grain cooperative, New Cooperative, was impacted by the BlackMatter ransomware on or before 18 September 2021. The adversary likely resided on New Cooperative’s networks for 15 days prior to encrypting its network and demanding New Cooperative pay $5.9 million in ransom by 25 September to unlock systems and prevent 1 terabyte (TB) of sensitive data from being publicly released. It is not clear if New Cooperative paid the ransom. The full impact of the ransomware attack is not known; however, according to New Cooperative’s general manager, the attack caused the company’s automated processes to revert back to processes used in the 1970s. , As of 6 October, only 50 percent of New Cooperative’s operations were utilizing automated processes. The company took eight weeks to rebuild the entire network and information technology (IT) systems from the ground up, which puts the date of fully recovery around 13 November. Researchers and analysts identified 20 unique techniques utilized during the attack with a total of 404 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Seventeen of the identified techniques used during the New Cooperative cyber attack were precursors to the triggering event. Analysis identified 360 observables associated with these precursor techniques, 284 of which were assessed to have an increased likelihood of being perceived in the 15 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy

Accelerating technology development to monitor and minimize effects from land‐based wind energy on birds and bats

While wind energy is a key sector of domestic energy production for the United States, operation of wind turbines directly and indirectly adversely affects certain species of birds and bats. The cumulative effect of wind turbine strikes can have both biological and regulatory consequences, and, in some cases, delay permitting and construction or affect ongoing operations. Technology can help quantify and minimize these effects, but the pace of development, acceptance, and adoption of technological solutions is slow. Although adopting cost‐effective technologies may reduce negative effects on wildlife and help achieve both energy production and conservation goals, consensus is lacking among developers, regulators, and the conservation community regarding how to define technology effectiveness and acceptance and how to develop a standardized process for doing so. Removing barriers to technology advancement requires deviating from the status quo. Changes include 1) creating incentives to mitigate impacts, 2) establishing options for research as mitigation, 3) rethinking how research is funded, 4) increasing stakeholder coordination, and 5) increasing the efficiency of research and development. We recommend the creation of a national framework to establish clear criteria and protocols for technology evaluation and adoption.

17 WIND ENERGY

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Security of DERs and Grid Edge Technologies [Slides]

Distributed energy resources (DERs) offer significant value for incorporating diverse generation technologies and improving reliability. They also present a new set of cybersecurity challenges. The move of generation to the grid edge can also mean more distributed control systems and expanded communication networks, resulting in an increase in attack surface. This presentation will discuss definitions and essential terms related to DERs; developments and deployment trends for DERs; recent cyber attacks on operational technology and industrial systems; cyber risk arising from distributed grid resources; and ways in which standards may help mitigate some of these risks.

24 POWER TRANSMISSION AND DISTRIBUTION

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

Integrity Enhancing Protocols: Performance and Recommendations for Nuclear Systems

In today’s communication landscape there are multiple technologies and protocols used for communication between end devices. Within security paradigms for these protocols, integrity management is a common goal of system designers. Communication protocols focused on maintaining message integrity can provide assurance that some received data has not been altered or tampered with. While integrity is often coupled with confidentiality in protocol design, this analysis focuses on an evaluation of only integrity protocols. This report outlines various ways message integrity may be preserved with respect to high performance operational technology (OT) systems. It describes a series of experiments and an evaluation framework used to evaluate the performance of the identified integrity approaches regarding common system design goals. Finally, it addresses the testing environment utilized and closes the report with a summary of experimental results.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Emerging Technologies for Privacy Preservation in Energy Systems

This study explores the intersection of digitalization and privacy within the energy sector, focusing on the emerging challenges and opportunities presented by integrating Distributed Energy Resources (DERs) and advanced metering infrastructure. The need for robust digital privacy measures has become crucial as the energy industry evolves towards a more decentralized, digitalized, and decarbonized future. This study delves into four cutting-edge privacy-preserving technologies—Homomorphic Encryption (HE), Secure Multiparty Computation (SMPC), Differential Privacy (DP), and Federated Learning (FL)—each offering unique solutions to safeguard consumer data by increasing digital connectivity and data exchange. Through a detailed examination of these methods, the study explains how each technology operates, its applications within the energy sector, and the specific privacy challenges it addresses. Homomorphic Encryption allows for secure computations on encrypted data, enabling data analysis without compromising privacy. Secure Multiparty Computation enables collaborative data analysis across different entities while protecting the confidentiality of the inputs. Differential Privacy introduces randomness into the assembled data set, preventing the identification of individual records in statistical databases. Lastly, Federated Learning offers a paradigm shift in data analysis, where machine learning models are trained at the edge, minimizing the centralization of sensitive data. The research underscores the significance of implementing these privacy-enhancing technologies to comply with strict data protection regulations, foster consumer trust, and enhance the security of the energy infrastructure. By providing a comprehensive overview of these methodologies and their practical implications for the energy sector, this study aims to contribute to the ongoing discourse on digital privacy, offering insights into how the energy industry can navigate the complexities of data privacy in the digital age.

Cali, Umit

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE

Influence of Ordered Mesoporous Oxides in Plasma-Assisted Ammonia Synthesis

Widespread implementation of dielectric barrier discharge (DBD)-assisted NH 3 synthesis, a nascent technology operating under sustainable, ambient conditions, is hindered by low energy yields due to, in part, poor fundamental understanding. Porous oxides used to support metal nanoparticle catalysts have shown significant energy yield contributions for DBD-assisted NH 3 synthesis even without metal. Using an AC-powered, coaxial, single-stage reactor at 16 kV with equimolar (N 2 /H 2 ) feed, we measured NH 3 synthesis rates in the presence of different nonordered oxides, ordered SiO 2 structures (SBA-15 and MCM-41), and ordered Al-incorporated analogues (γ-Al 2 O 3 -coated with varying Al-loadings and Al-substitution, respectively: Al 2 O 3 -SBA-15 and Al-MCM-41). We systematically quantified NH 3 energy yield dependence on pore structures and material identities (i.e., ordered pores and Al incorporation) known to facilitate higher DBD-assisted NH 3 synthesis rates. SBA-15 displayed a higher steady-state energy yield than MCM-41, indicating that framework type is a crucial factor, with both ordered porous systems outperforming fumed SiO 2 . 10 wt % Al maximized in situ NH 3 uptake among the various Al loadings, exhibiting a higher steady-state energy yield and similar power to SBA-15. However, Al-MCM-41 had a similar steady-state energy yield and lower power than MCM-41, likely due to the extended γ-Al 2 O 3 surface that has a dielectric constant higher than that of SiO 2 . Both Al-incorporated analogues benefit from surface acid sites that can adsorb NH 3 in situ, resulting in higher overall NH 3 energy yields than that of their parent ordered SiO 2 . Al 2 O 3 -SBA-15 shielded more NH 3 than Al-MCM-41, likely due to a higher acid site density than the acid site identity. Furthermore, Al incorporation via γ-Al 2 O 3 coating more successfully improves the NH 3 energy yield; together with the high-performing ordered framework, these analogues are potential metal catalyst supports with promising energy yields for DBD-assisted synthesis of NH 3 and other chemicals.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH

High-Temperature Observation of Intralayer, Interlayer, and Rydberg Excitons in Bulk Van Der Waals Alloy Single Crystals

Transition metal dichalcogenides exhibit remarkable optical properties due to the diverse number of strongly bound excitons, which can be fine-tuned by alloying. Despite a flurry of research activity in characterizing these excitons, a comprehensive and profound understanding of their behavior with temperature is lacking. Here, we report the rich spectrum of excitonic features within bulk van der Waals alloy Mo0.5 W0.5 S2 and Mo0.5 W0.5 Se2 single crystals through temperature-dependent reflectance spectroscopy and first-principles calculations. We observed Rydberg excitons and interlayer excitons in both the single crystals. Notably, we provide the first experimental evidence of highly energetic A' and B' excitons in Mo0.5 W0.5 S2 at room temperature. The strong carrier-phonon scattering significantly broadens the A', B', and interlayer excitons at room temperature in bulk Mo0.5 W0.5 S2 single crystal compared to its selenide. Our findings, supported by density functional theory and Bethe-Salpeter equation calculations, signify the crucial role of carrier-phonon interactions. These results open pathways for next-generation optoelectronic devices and quantum technologies operating at high temperature.

excitons

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN

Cyote Insights

CyOTE Insights leverages React, Vite, Typescript, Tailwind, and Daisy UI for the Graphical User Interface. It was designed in a particular style with a dark mode and a light mode. All code is broken down into components and reusable wrapper components for efficiency. All data is stored in Deep Lynx as a central data repository using an ontology based schema. The application serves as a main endpoint for the data in the COREII and CyOTE programs. The main purpose of the application is to display historical attack data in the Operational Technology space. At the time of this writing, it supports 27 historical attack reports compiled from OSINT sources. All of the data is publicly available, but what this application offers is the ability to see many years worth of publications in a detailed dashboard. It will also support future reports that are written using the other applications in the COREII program.

Pluth, AdamJ [Idaho National Laboratory (INL), Ida

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Virtual Environment Platform for OT/IT Training Enhancement

TRADITIONAL TECHNIQUES OT/IT Concepts Operational Technology (OT) and Information Technology (IT) concepts can often be difficult to visualize Teaching Methods Traditional teaching methods lack the intuitive & immersive aspects of hands-on activities Caveat: Unless taught by Team B! Physical Limitations Digital Twins require existing systems/hardware to mirror UPDATED TECHNIQUES Virtual Environment By making use of a virtual environment, we can represent abstract concepts in a more approachable and digestible way Increased Engagement Students are more engaged with the activities and are more likely to retain the information they are given. New/Emerging Technologies As the system is currently growing and developing, the technologies in use, as well as those represented by the system, stay up-to-date.

Deroller, Nicholas F.

Cybersecurity Considerations for the Liquified Natural Gas Sector

Due to the highly volatile nature of Liquified Natural Gas (LNG) and the systems required for generation and safe containment, it is likely a targeted cyber-attack on LNG control and safety systems will have a significant economic impact on energy supplies and prices. Moreover, if the interconnected operational technology (OT) devices within LNG systems are exploited to malfunction, the repair and recertification process will almost certainly be longer than for natural gas (NG) systems.

03 NATURAL GAS

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION

Secure NTP Implementation for Power System Synchronization

Network Time Protocol (NTP), originally developed in the 1980s, remains one of the most widely adopted protocols for synchronizing clocks over Internet Protocol (IP)-based networks. It distributes time with millisecond-level accuracy across Ethernet-based systems and continues to be a standard in both enterprise and operational technology environments.

97 MATHEMATICS AND COMPUTING