Search NASA⌕ Search

SEARCH · Search NASA

Results for “security controls”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.

Asmar Awad, Rima [ORNL] (ORCID:0000000233407742)↗

Harnessing the Power of AI: Status and Expansion of Current Domestic Transport Security Through Flexible Embedded Hardware

As applications of Artificial Intelligence (AI) continue to expand, there are increasing opportunities to leverage applied AI methodologies with mobile transportation focused embedded systems. Current applications of AI in transportation focus on a variety of areas, including fuel efficiency, safety, security, and other broad fields of optimization or detection. To leverage these AI workflows and methodologies in the field, teams must utilize complex embedded systems capable of implementing these AI-enabled algorithms in real-time. In this paper, we will investigate how these algorithms can be integrated into existing technologies leveraging vehicle data - such as the Controller Area Network Transport Security Tracking and Reporting Unit (C-STAR). The C-STAR technology is an embedded platform with onboard computation capable of running next generation algorithms in vehicle systems AI, such as preventative maintenance, driver authentication, and transport security. As deployed in the field, the C-STAR has a limited AI functionality –this paper will directly discuss how a device like C-STAR can be utilized and the advantages of integrating these new technologies. We will open with relevant background information and transportation projects that leverage AI, focusing specifically on those around transport security such as vehicle identification, anomaly detection, and deterrence. We will then extend this into potential opportunities and scaling for AI methodologies using platforms like the C-STAR. Finally, we will speak directly to the challenges of deploying AI-powered workflows, such as computing power needs, bandwidth, hallucinations, and other regulatory considerations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Internship Presentation: Reactor System Facility Modification to Detect Compromised Human Machine Interfaces

This study presents a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture aimed at detecting and mitigating compromised Human Machine Interface (HMI) and Instrumentation & Control (I&C) systems within the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). The approach combines network security solutions, hash-based algorithms, and blockchain technologies to verify system integrity and provide an immutable record of network activity. This integrated three-pronged strategy enhances the detection of system compromises, enabling preemptive action before significant damage occurs.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

A full-scope, high-fidelity simulator-based hardware-in-the-loop testbed for comprehensive nuclear power plant cybersecurity research

Nuclear power plant (NPP) cybersecurity research often relies on hardware-in-the-loop (HIL) testbeds that integrate real hardware components into simulated environments. These testbeds allow researchers to identify vulnerabilities, evaluate attack impacts, and test security measures in a controlled setting. Furthermore, previous HIL testbeds lacked fidelity to accurately represent real nuclear systems, limiting the scope of cybersecurity analysis. This study presents the creation of a HIL testbed, devised upon a full-scope, high-fidelity NPP simulator, to facilitate realistic and comprehensive cybersecurity research. To demonstrate its capabilities, the control logic for the steam generator water level was migrated from the simulator to an external programmable logic controller. As a practical application of the developed testbed, supply chain attack scenarios were simulated by injecting malicious code into the controller logic, and the effects of manipulating sensor inputs and control commands were observed. While this HIL testbed provides more detailed simulations, enhanced realism, and wider applicability compared to other options utilizing a less complex simulator, it is also more intricate and costly. For this reason, we include a detailed comparison with some alternative architectures to aid fellow researchers and practitioners in the selection of a suitable HIL architecture based on specific research objectives.

47 OTHER INSTRUMENTATION↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

Study on Application of Distributed Network of Sensors with List Mode for NMAC Literature Review

Nuclear material accounting and control (NMAC) for nuclear security detects, deters, and resolves questions related to unauthorized removal (i.e. theft) or misuse of nuclear material. NMAC also serves as a key insider threat mitigation measure and aids in recovery of nuclear material that is missing. Effective nuclear security depends on NMAC for timely and accurate information about nuclear material types, quantities, and locations. Bulk nuclear material processing facilities, however, present unique challenges for effective NMAC due to the presence of large quantities of material in-process and the accumulation of residual material holdup within process equipment. These holdup accumulations can obscure accurate physical inventory taking and complicate efforts to resolve NMAC irregularities at the facility level. Bulk material monitoring systems often rely on material balance calculations and indirect measurement techniques, which may mask protracted theft of smaller amounts of nuclear material. These monitoring limitations have generated increased interest in continuous monitoring technologies, including distributed non-destructive assay (NDA) sensor networks capable of providing real-time or near-real-time measurement of material movement and accumulation within bulk processing environments. Recent advancements in distributed networks of NDA radiation detectors and sensing technologies provide an opportunity to address these limitations. Although such distributed sensor networks have been implemented in select facilities for IAEA Safeguards applications, their potential for supporting NMAC functions specifically tailored to nuclear security objectives remains largely unexplored. Furthermore, emerging list-mode data acquisition technologies have reached high technology readiness levels, enabling time-correlated detection of nuclear events across multiple temporal scales. These capabilities provide enhanced opportunities for accurate holdup measurement, continuous process monitoring, and improved detection of material theft or misuse over time. The increasing global expansion of civil nuclear power and development of related bulk material processing facilities, including those supporting high-assay low-enriched uranium (HALEU) and other advanced reactor fuel fabrication, further increases the need for advanced measurement and monitoring strategies for NMAC.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

American Made Infrastructure: Evolution of Federal Incentives and Requirements

Foreign Entity of Concern (FEOC) restrictions in the One Big Beautiful Bill Act (OBBB) represent the latest evolution of a multi-year legislative trajectory responding to national security concerns about foreign control – and particularly FEOC control – of energy infrastructure. Beginning with Executive Order 14017 (February 2021), which initiated comprehensive federal review of critical supply chain vulnerabilities in semiconductors, battery energy storage systems, and critical minerals, policymakers have progressively expanded restrictions on foreign participation. The National Defense Authorization Act (NDAA) 2019 established precedent for component-level prohibitions on foreign information and communications technology procurement, while NDAA 2024 extended these restrictions to six major People’s Republic of China (PRC) battery manufacturers. Complementary measures such as the Build America, Buy America (BABA) Act and the Infrastructure Investment and Jobs Act (IIJA) introduced domestic content thresholds and FEOC eligibility criteria for federal funding programs. The Inflation Reduction Act (IRA) 2022 further operationalized FEOC restrictions through electric vehicle tax credit requirements, creating a scalable framework for excluding foreign-controlled components. Recent executive actions and state-level policies have reinforced this trajectory, reflecting sustained alignment across federal and state governments. Collectively, these developments demonstrate a bipartisan policy approach that pairs incentives for advanced energy deployment with safeguards designed to prevent subsidizing adversaries or entities that present foreign-sourcing risk.

99 - GENERAL AND MISCELLANEOUS↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Reactor System Facility Modification to Detect Compromised Human Machine Interfaces

This study focuses on a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture to aid in the discovery and mitigation of compromised Human Machine Interface (HMI)/Instrumentation & Control (I&C) based systems for modifying a prototypical reactor condition test facility called the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). This is achieved through a three-layered combination of network security solutions, hash-based algorithms, and blockchain technologies. Hash algorithms are mathematical functions used to generate a predetermined set of fixed-length values. They are widely used in computer security to verify the integrity of system information and data, both on a local network and the wider internet. Even small amounts of unauthorized system modification will cause the hash algorithm to output a set of characters that deviate significantly from its original value. Assisting secure hash functions, blockchain technology is a secure and distributed technology used to provide an immutable set of records replicated on all devices within a decentralized network. Blockchain offers a cost-effective solution to detect system compromise by providing a traceable breadcrumb trail of all network activity and data modification happening on a system. If both are used in conjunction with network monitoring tools, the integration of this three-pronged approach can become an asset in detecting suspected system compromises before any real damage can occur.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

Employing a Hardware-in-the-Loop Approach to Realize a Fully Homomorphic Controller for a Small Modular Advanced High Temperature Reactor

This paper addresses the cybersecurity challenges of advanced nuclear reactors by integrating fully homomorphic encryption (FHE) into their control systems, enabling encrypted processing of control signals without compromising functionality. Advanced nuclear reactors, including Small Modular Reactors (SMRs) and microreactors, aim to achieve autonomous and remote operations, reducing costs and enhancing competitiveness. However, these advancements expand the attack surface for cyberattacks, particularly in autonomous and remote operation scenarios. Cyberattacks can exploit vulnerabilities to manipulate physical processes, causing shutdowns, asset damage, or public harm. Such attacks begin with passive reconnaissance, where adversaries intercept communications or observe behaviors to gather information, which is then leveraged to execute cyber-physical attacks by injecting malicious commands. Nuclear power must adopt cybersecurity protection measures to secure the integrity and availability of their digital control systems. This paper demonstrates the application of FHE to secure operations by enabling encrypted processing of sensitive signals and parameters -- ensuring privacy without exposing data. FHE supports secure mathematical operations on encrypted data without requiring decryption. Using a hardware-in-the-loop (HIL) approach, this paper implements an FHE-integrated controller on a BeagleBone Black (BBB) controlling a simulation of the Small Modular Advanced High Temperature Reactor (SmAHTR). By doing so, the encrypted controller protects the integrity of critical set points and control signals during transmission and processing. Thus, FHE-integrated controllers enhance secure operations of advanced nuclear reactors while maintaining functionality.

control systems↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗

Methods of Securing Chemical and Pharmaceutical Knowledge and Recommendations for International Institutions to Enhance Research Integrity

Here, this paper examines strategies for securing chemical and pharmaceutical expertise in a globalized research environment, focusing on safeguarding intellectual property and preventing the misuse of sensitive and potentially dual-use information. The product of collective efforts between Pacific Northwest National Laboratory, Carol Davila University of Medicine and Pharmacy, and New Bulgarian University, highlights the challenges and opportunities posed by cross-border research collaborations, particularly in the context of differing regulatory frameworks and research cultures. It explores current mechanisms to prevent data loss and unauthorized access to sensitive information while assessing the effectiveness of existing security measures, frameworks, and international export control regimes. The approach examines the differing methodologies for promoting transparency, trust-building, and mutual accountability in joint research projects to cultivate secure data-sharing practices and intellectual property. It provides recommendations for international institutions to implement security guidelines in framing research priorities, encourages continual training and education programs, and the integration of processes for monitoring research compliance. This partnership aims to advance scientific innovation while maintaining global stability, ensuring compliance with international norms, and safeguarding valuable intellectual property as measures in chemical and pharmaceutical research security practices continue to expand due to international collaboration and knowledge exchange.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Security of Mobile Radiological Sources: Overview of Industry Applied Technologies

Small radiological sources used in industrial settings recurrently require transit between job sites. Securing these sources, while stationary, can be addressed with standard security approaches and equipment. Transport of these sources increases the risk and complexity of managing and maintaining control of these sources. Implementing methodologies to securely monitor and locate sources improves response and resolution of anomalous events during transit. The Mobile Source Transit Security (MSTS) system was developed to improve security and provide situational awareness of these mobile sources throughout their job cycle. The MSTS development effort focused on creating a set of systems that could be successfully implemented in industrial radiography and well-logging applications. The MSTS team worked to address source presence and location through use and storage. The MSTS system monitors radiological sources as they move from the base of operations to the job site and back. The system provides near-real-time monitoring of the mobile source location and status and early notification of source loss or theft by transmitting operational status and alerting anomalous conditions over telematic links worldwide. The MSTS system can trigger an armed response or initiation of search and recovery operations and will automatically alert management and responsible staff if a radioactive source is lost or stolen whether it is on-site, in transport, or in storage.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Angular-spectral filtering of recoil protons for optimization of fast neutron imaging employing proton converters

Fast neutron imaging is an important capability for diverse applications such as inertial confinement fusion diagnostics, cargo security, nuclear nonproliferation and arms control, and industrial inspection. Traditional phosphor image plates can be enhanced for fast neutron imaging using hydrogenous plastic converters which allow fast neutrons to scatter off hydrogen nuclei to produce energetic protons that can be recorded by the image plate. However, protons emitted by image plates are not constrained in their emission angle, which contributes to the blur of the resulting image. Here, we investigate two methods that can alter the spatial extent of converted protons that deposit energy in the image plate: reducing the converter thickness, and introducing a proton filter between the plastic converter and image plate to reduce the contribution of lower-energy, off-axis protons to the image. Here we determine the optimal plastic converter thickness for maximizing the signal intensity to be 2–3 mm through Monte Carlo simulations, and we benchmark this result against experimental measurements with a deuterium-tritium (DT) neutron generator. Next, we evaluate the image smearing and signal loss for various converters to show that solely reducing the converter thickness has the expected effect of reducing the blur from proton image smearing of the sharpness of an edge recorded on the image plate at the cost of reducing the signal intensity. The use of a proton filter is shown to achieve a similar improvement of edge sharpness as reducing the converter thickness while also sacrificing the signal intensity. We conclude that the use of proton energy filtering can improve the sharpness of fast neutron images in situations where the converter thickness cannot be reduced below some practical minimum. For more intense neutron sources, the signal intensity is of less concern, and optimizing the resolution of the image plate and therefore of the imaging system could have greater value. In these applications, proton filters may allow for improved fast neutron imaging measurements.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗