Search NASA⌕ Search

SEARCH · Search NASA

Results for “ICS”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

123 records · Page 7

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Capabilities for Water Sector Infrastructure Resilience - Prioritizing RD&D in a Target Rich, Resource Poor Sector

WSTB & Water Sector Security Program Expansion Objective: Incubate and shepherd a public-private consortium of joint seal US government sponsors and industry stakeholders to build out industrial control system (ICS) and operational technology (OT) architecture of the Idaho National Laboratory (INL) Water Security Test Bed (WSTB) asset to enable research, testing, and cyber workforce training related to evolving cyber-physical and physical vulnerabilities and threats in the water sector.

99 - GENERAL AND MISCELLANEOUS↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Determining the Solubility Behavior of Kogarkoite in Simulated Nuclear Waste

Kogarkoite (Na 3 FSO 4 ) is a sparingly soluble fluoride–sulfate double salt that has been identified in high level nuclear waste sludge at the Hanford Site and, more recently, in sludge batch compilation samples at the Savannah River Site (SRS). Due to its complex dissolution behavior, which exhibits an inverse dependence on sodium ion activity, the presence of this mineral poses significant challenges to waste retrieval and processing. Incomplete dissolution during sludge washing can lead to the retention of fluoride and sulfate in the high-level waste feed, potentially causing the formation of corrosive, immiscible molten salt layers, known as "glass gall,” in vitrification melters. Current efforts to optimize flowsheet parameters and wash-water volumes are hindered by the absence of a commercially available, certified reference material, which prevents the accurate calibration of analytical methods and the verification of dissolution kinetics. To address this critical gap, this research focuses on the laboratory synthesis of pure Kogarkoite to serve as a standard for comprehensive solubility and washing performance testing. A coupled synthesis and simulant campaign was executed using an evaporative crystallization protocol designed to replicate the dynamic concentration effects observed in tank farm operations. Thirteen simulant matrices were prepared by dissolving systematically varied ratios of sodium fluoride (NaF) and sodium sulfate (Na 2 SO 4 ) in deionized water under three distinct caustic regimes: 0.0 g (control), 4.0 g (~1 M), and 12.0 g (~3 M) sodium hydroxide (NaOH). While thermodynamic equilibrium models suggest that high-caustic environments should favor the stability of the double salt7, results from this evaporative study at 25 0 C revealed a distinct kinetic divergence. Simulants with high hydroxide loading predominantly yielded large, blocky crystals of sodium sulfate decahydrate (Na 2 SO 4 .10H 2 O). Successful synthesis of pure Kogarkoite was achieved exclusively in specific NaOH-free compositional windows, where the precipitate manifested as fine, opaque granular aggregates. Ion chromatography (IC) analysis confirmed phase purity through the simultaneous stoichiometric depletion of both fluoride and sulfate from the supernatant. This successful synthesis establishes a reproducible route to generate bulk Kogarkoite, enabling the subsequent phase of quantitative dissolution testing using inhibited water to optimize sludge-batch assembly.

Sarker, Md Sharif [Florida International Univ. (FI↗

Experimental Investigation of the Effect of Air-Handling and DME-Propane Blends on the Performance and Emissions of a 4-Cylinder CI Engine

Dimethyl ether (DME) is considered an excellent alternative to diesel because of its higher cetane number and lower carbon content. Additionally, DME can be blended with abundantly available propane with minimal modifications to the propane infrastructure. This paper focuses on an experimental investigation of the effect of air-handling i.e., boost pressure and exhaust gas recirculation (EGR), and DME-propane blends on the combustion and emissions performance of a light-duty, four-cylinder, compression ignition (CI) engine. Here, the boost pressure and EGR sweeps were carried out and showed that higher boost pressures resulted in increased brake thermal efficiencies (BTE) at the expense of higher NOx emissions which could be reduced by an increase in EGR. The fuel sweeps were carried out at 0, 15 and 25% propane (neat, 85% and 75% DME) with 0% and 25% EGR. The fuel sweeps indicated that the ignition delay (ID) increased and burn duration (BD) decreased monotonically when the blend increased to 25% propane/75% DME. The results suggest optimum engine performance with neat DME at 105 kPa boost pressure and 25% EGR with propane addition improving the BTE with negligible increase in emissions. Higher contents of Propane, up to 25%, did not affect the variability of combustion, with standard deviations of burn duration and peak cylinder pressures below 1% for all test cases.

air-handling↗

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Considerations for the Liquified Natural Gas Sector

Due to the highly volatile nature of Liquified Natural Gas (LNG) and the systems required for generation and safe containment, it is likely a targeted cyber-attack on LNG control and safety systems will have a significant economic impact on energy supplies and prices. Moreover, if the interconnected operational technology (OT) devices within LNG systems are exploited to malfunction, the repair and recertification process will almost certainly be longer than for natural gas (NG) systems.

03 NATURAL GAS↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

Malcolm Deployment Guide for Solar Power Generation Plants

This guide provides detailed instructions for deploying Malcolm in Solar Power Generation systems. It covers the deployment process, from understanding the network architecture of these systems to configuring network switches and Switched Port Analyzer (SPAN) ports or mirror ports or TAPs. The guide also includes best practices for deploying Hedgehog sensors, another critical component in these systems. Following this guide, users can enhance network visibility, improve their system’s security, and effectively troubleshoot common issues.

14 SOLAR ENERGY↗

StructuredFuzzer: Fuzzing Structured Text-Based Control Logic Applications

Rigorous testing methods are essential for ensuring the security and reliability of industrial controller software. Fuzzing, a technique that automatically discovers software bugs, has also proven effective in finding software vulnerabilities. Unsurprisingly, fuzzing has been applied to a wide range of platforms, including programmable logic controllers (PLCs). However, current approaches, such as coverage-guided evolutionary fuzzing implemented in the popular fuzzer American Fuzzy Lop Plus Plus (AFL++), are often inadequate for finding logical errors and bugs in PLC control logic applications. They primarily target generic programming languages like C/C++, Java, and Python, and do not consider the unique characteristics and behaviors of PLCs, which are often programmed using specialized programming languages like Structured Text (ST). Furthermore, these fuzzers are ill suited to deal with complex input structures encapsulated in ST, as they are not specifically designed to generate appropriate input sequences. This renders the application of traditional fuzzing techniques less efficient on these platforms. To address this issue, this paper presents a fuzzing framework designed explicitly for PLC software to discover logic bugs in applications written in ST specified by the IEC 61131-3 standard. The proposed framework incorporates a custom-tailored PLC runtime and a fuzzer designed for the purpose. We demonstrate its effectiveness by fuzzing a collection of ST programs that were crafted for evaluation purposes. We compare the performance against a popular fuzzer, namely, AFL++. The proposed fuzzing framework demonstrated its capabilities in our experiments, successfully detecting logic bugs in the tested PLC control logic applications written in ST. On average, it was at least 83 times faster than AFL++, and in certain cases, for example, it was more than 23,000 times faster.

47 OTHER INSTRUMENTATION↗

Laser Based Ultrasound for Verification of Circuit Card Assemblies

This IR is a follow-up conference Paper to the IR approved abstract; PNNL-SA-194096. --- Verification that equipment is authentic and not changed; even at the circuit card assembly (CCA) level will likely be an important component of future arms control treaties. This effort was an initial evaluation of the potential for laser-based ultrasound (LBU) as an inspection tool for Unique Identification (UID) of Circuit Card Assembly (CCA) boards and CCA components. The LBU system used a laser pulse for ultrasound generation and an Optical Microphone for ultrasound detection to image subsurface structures without physical contact and in a dry state. This paper described the selected CCA surrogate, CCA components that were examined, the LBU system, LBU images of the CCA components, and the initial development of UID algorithms. Receiver operating characteristics (ROC) curves indicated good performance for two algorithms as a potential means for UID of CCA boards and CCA components.

Laser Ultrasound, Equipment Verification, Arms Con↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗