Search NASA⌕ Search

SEARCH · Search NASA

Results for “cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

International Space Agency CIO Forum Industrial Control System (ICS) and Cyber

This briefing covers Industrial Control System (ICS) best practices for enhancing cyber protection. The briefing provides a very high-level overview of best practices currently being pursued by NASA as well as by other US government agencies such as NIST and DHS ICS-CERT. All information presented in this slide deck is publicly available and no sensitive information is provided in these slides. These slides will be used to generate discussion around best practices within the international community in the area of ICS cyber protections.

Powell, Robert↗

Cyber Physical Security (CPS) Extension to Air Traffic Management (ATM) Testbed

The Air Traffic Management (ATM) Testbed is being developed at NASA to enable benefit, impact, safety and cost assessments for accelerating the deployment of Concept and Technologies (C&T) in the National Airspace System (NAS). Today, C&T introduction into the NAS takes decades. The primary reason for this is an inability to assess the operational impact of the interaction between the proposed C&T and operationally deployed systems (Realistic Technologies) in terms of NAS-wide safety, traffic flow efficiency, roles and workload of controllers and traffic managers, and impact on airline fleet operations. Transition of C&T to operations requires mathematical modeling and simulation, Human-in-the-Loop (HITL) testing and shadow-mode evaluation driven by operational data. Whereas interaction with the operational system during testing and stages of deployment is not permissible due to safety concerns, it is certainly possible to create a simulation environment that closely mimics the NAS using the same operational systems/hardware for enabling such assessments. This presentation focuses on a proposed Cyber Physical Security extension to the ATM Testbed for creating a modeling and simulation architecture to study how well the Air Traffic Management system will perform and analyze effectiveness of mitigating security measures against particular cyber-attack scenarios.

Datta, Koushik↗

Mission-centric cyber security assessment of critical systems

We present a novel model-based, mission-centric approach to perform cyber security assessments for evaluating the impact of low-level cyber events on high-level mission objectives.We demonstrate the benefits of our approach using a system model and attack trees specific to the command-and-control system of a spacecraft. Specifically, we demonstrate how our approach enables a decision-maker to assess the security posture of the system, identify necessary mitigations and prioritize their deployment.

Tan, Kymie↗

Role of Cyber-Physical Testing in Developing Resilient Extraterrestrial Habitats

Extraterrestrial long-term habitat systems (henceforth referred to as habitat systems) require groundbreaking technological advances to overcome the extreme demands introduced by isolation and challenging environments. A habitat system must operate as intended under continuous disruptive conditions. Designing for the demands that challenging environments will place on habitat systems (e.g., wild temperature fluctuations, galactic cosmic rays, destructive dust, meteoroid impacts, vibrations, and solar particle events) represents one of the greatest challenges in this endeavor. This engineering problem necessitates that we design and manage habitat systems to be resilient. System resilience requires a comprehensive approach that accounts for disruptions through the design process and adapts to them in operation. As the habitat system evolves—growing in physical size, complexity, population, and connectivity—and diversifies in operations, it must continue to be safe and resilient. In this endeavor, we should take advantage of lessons learned in developing civil infrastructure responsive to catastrophic natural hazards, autonomous robotics platforms, smart buildings, cyber-physical testing, complex systems, and diagnostics and prognostics for intelligent health management. This study highlights the importance of system resilience and cyber-physical testing to address the grand challenge of developing habitat systems.

Public health and safety↗

Thermal Actuator Identification and Control for Thermomechanical Real-Time Cyber–Physical Testing

Thermomechanical cyber–physical testing enables two-way thermal coupling between a numerical and an experimental subsystem. The interactions between the numerical model and the physical specimen occur through transfer systems, which enforce interface conditions. Thus, efficient control methodologies are necessary to achieve the desired interface interaction through thermal actuators with minimal error. This study introduces a novel thermal transfer system that imposes distributed cooling (or heating) thermal loads on a physical subsystem. First, the thermal actuator is identified considering switching-mode continuous dynamics for heating and cooling conditions. A switching-mode estimation algorithm is adopted to estimate the operating thermal cycle of the actuator in real-time. A control system is developed to experimentally impose the desired temperature and reduce tracking error (i.e., the error between the desired and actual temperature) under different thermal cycles. The identification and control of the thermal transfer system are then validated through a set of experiments considering different temperature rates of change. The developed control system is found to effectively minimize tracking errors in real-time cyber–physical experiments.

Herta Montoya↗

NUMERICAL MODELING OF A SOLID OXIDE FUEL CELL FOR USE IN REAL-TIME SIMULATION AND CYBER-PHYSICAL SYSTEMS

Cyber-physical systems provide a mechanism with which to investigate the physical phenomena and behavior of traditionally cost-prohibitive or otherwise fragile equipment. For the National Energy Technology Laboratory (NETL), this approach resulted in the Hybrid Performance (Hyper) facility which features a gas turbine-SOFC hybrid cycle utilizing real turbomachinery and a simulated SOFC stack. This allows for the investigation of combined cycle performance and control strategies, in an exhaustive manner, both without fear of destroying delicate state-of-the-art fuel cells, and with the full accuracy of real-world turbomachinery. Issues arose between the transient response of the SOFC model being limited to a sample time of 80 milliseconds, due to the calculation time of the SOFC model taking on average 40 milliseconds to calculate for a given timestep with spikes in calculation time reaching the 80 millisecond threshold. In order to be able to match the speed of transients from the turbomachinery and likewise better discern transient behavior, it was determined that the SOFC model must be optimized to operate at a sample time of 5 milliseconds. Therefore, it is necessary to optimize the SOFC model in order to decrease the calculation time from around 40 milliseconds, down to at the most 5 milliseconds. To do this, both the electrochemical algorithm and the thermal algorithm used to simulate the physical behavior of the SOFC are investigated to determine where improvements can be made. To this end the rootfinding numerical recipes of the electrochemical algorithm are investigated as the complex electrochemistry requires a highly iterative nested dual convergence loop to resolve the voltage-current relationship, and likewise the temporal discretization of the thermal algorithm is modified for the sake of higher accuracy and stability. Ultimately the new electrochemical algorithm featuring higher order rootfinding schemes proves to be efficient enough to reach the sub 5 millisecond target, signifying an order of magnitude reduction in calculation time, and when coupled with the new temporal discretization similar calculation time characteristics show that a fully implicit, higher order temporal discretization can also successfully be used if desired. Ultimately this result means that the cyber-physical simulation system can operate at higher sample rates, and resolve transient events at significantly higher resolution and fidelity.

Arias, Jesus↗

Are Satellites Cyber Physical Systems?

Abstract— Cyber-physical systems (CPS) are a key part of modern infrastructure. However, satellites are often excluded from discussions of CPS, despite their evident cyber-physical attributes, such as the ability to respond to information from its surroundings and adjust accordingly. Through a brief examination of relevant literature, we prove that satellites are CPSs, specifically through payload-bus interactions that occur on a satellite. By establishing satellites as a form of CPS, we hope to encourage its inclusion in discussions for bettering the security of such systems.

Jones, Rachel C.↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Engineering Out Industry 4.0 Cyber Risk

The increasing complexity and business requirements of operational technology (OT) devices is beginning to break the normal segmentation between information technology (IT) and OT networks. The introduction of industry 4.0 devices such as industrial internet of things (IIoT) and other intelligent industrial devices (IID), virtualized OT systems, OT cloud integration, and artificial intelligence (AI)-driven industrial control systems (ICS) has challenged traditional IT/OT cybersecurity strategies. Industry 4.0 devices are analyzed through the lens of well-regarded models such as the PERA model and confidentiality, integrity, and availability (CIA) security objectives, showing the division between what is needed and traditional cybersecurity countermeasures. In this paper, the practice of Cyber-Informed Engineering (CIE) is proposed to bridge the gap between IT/OT security, enhance the practice of cybersecurity in this modern age, and reduce the impacts of consequential events in OT.

42 - ENGINEERING↗

Adaptive anomaly detection for identifying attacks in cyber-physical systems: A systematic literature review

Modern cyberattacks in cyber-physical systems (CPS) rapidly evolve and cannot be deterred effectively with most current methods, which focus on characterizing past threats. Adaptive anomaly detection (AAD) is among the most promising techniques to detect evolving cyberattacks, with an emphasis on fast data processing and model adaptation. AAD has been researched extensively; however, to the best of our knowledge, our work is the first systematic literature review (SLR) on current research in this field. We present a comprehensive SLR, gathering 397 relevant papers and systematically analyzing 65 of them (47 research and 18 survey papers) on AAD in CPS from 2013 to November 2023. We introduce a novel taxonomy considering attack types, CPS application, learning paradigm, data management, and algorithms. Our findings show that most studies addressed either model adaptation or data processing, but rarely both simultaneously. This indicates a research gap in fully adaptive solutions. We also categorize algorithms, datasets, and attack characteristics, and summarize strengths and weaknesses across the literature. Our review provides a structured and accessible reference for researchers and practitioners, offering insights into key trends and highlighting limitations in current approaches. Finally, we outline several future research directions, including the need for integrated real-time processing and adaptive learning, explainability, and uncertainty quantification in AAD for CPS.

Adaptation↗

Cyber-Informed Engineering Workbook: CIE Hands-On Training

This workbook presents a case study of a hypothetical project to support discussion and application of the principles for Cyber-Informed Engineering as a part of a facilitated workshop. Though this scenario draws from a selection of real-world case studies, it is fictional. Workshop participants are encouraged to use the workbook to capture insights and lessons learned.

42 ENGINEERING↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Workbook: Substations

This workbook contains a case study based on a hypothetical substation project, intended to aid in the conversation and utilization of principles related to Cyber-Informed Engineering.

42 ENGINEERING↗

Cyber-Informed Engineering Workbook: ADMS

This workbook presents a hypothetical project designed to facilitate discussion and the practical application of cyber-informed engineering principles.

42 ENGINEERING↗