Search NASASearch

SEARCH · Search NASA

Results for “Critical infrastructure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Unified 0.25-degree gridded infrastructure-critical extreme weather for the United States from 1979 to 2100

Extreme weather events can severely disrupt critical infrastructure, triggering cascading effects on power, transportation, and essential services. However, standard weather and climate datasets often lack specialized variables necessary for hazard assessments. We present a unified dataset of infrastructure-critical weather and climate variables across the United States at 0.25° resolution, covering daily or sub-daily intervals from 1979 to 2100. The dataset includes temperature, dew point, wind gusts, precipitation partitioned by rain, snow, and freezing rain or ice pellets, lightning, and wildfire metrics. Historical conditions (1979-2023) are synthesized from observations and reanalysis products, while future projections are derived from 14 CMIP6 global climate models (historical, SSP245, and SSP585 experiments). Physically based and data-driven methods are used to estimate variables not directly provided by existing models. By integrating these variables into a single unified dataset, we enable consistent, high-resolution assessments of weather-related infrastructure risks across past and future periods, supporting wide-ranging applications in energy, transportation, water resources, emergency management, and beyond.

Climate and Earth system modelling

A Data Processing Pipeline To Extract A Knowledge Graph From Heterogeneous Data For Socio-technical Analysis Of Critical Infrastructure Influence

The code is written in Python and consists of the following pipeline that is implemented in Apache Airflow. This pipeline intends to understand the companies that are directly or indirectly involved with a type of critical infrastructure system at some point in that system's lifecycle. The pipeline takes a configuration file that specifies a list of initial companies to consider, a geographic region of interest, and a set of SEC form types as well as other data sources (e.g. CrunchBase) from which to extract entities and relations. There are four main components to this pipeline as currently implemented: Entity Extraction, Network Construction, Analysis, and Visualization. First, Entity Extraction, is implemented as the `topear-extract_organizations` Apache Airflow workflow. Given an initial query that specifies a geographic region of interest and a time interval, the software will extract CI facilities of interest and organizations that have a direct influence relationship to those facilities (e.g. ownership). During the course of the LDRD, we focused on Electric Vehicle charging stations and this information is available via the Department of Energy (DOE) database on fueling stations maintained by NREL. Within the context of the DOE CESER project, we have focused on Battery Energy Storage Systems (BESS). Second, the Network Extraction component will iteratively construct a social network graph given the set of organizations and people extracted in the previous step. Organizations (and eventually People if desired) are then fed as a query to the `topgear-construct_social_network` Apache Airflow workflow which given a set of initial companies and data sets (e.g. SEC EDGAR form types, OpenCorporates, Crunchbase). This Airflow workflow will iteratively query such data sources to discover relationships with new organizations and people. For example, this module can iteratively query SEC EDGAR for metadata that documents the number of each type of form for the given set of companies and their location. This forms metadata represents a catalog of data sources from SEC EDGAR for the extracted social network knowledge graph. The pipeline then downloads these forms from the website and saves them in a build directory for further processing. These documents are then parsed for entities and relations. Again, we note that in additional to SEC data sources, this step can also pull in information on organizations via API services such as CrunchBase and OpenCorporates or bulk data sources. At the end of this step, the resultant social network, the Critical Infrastructure network, and the edges that encode relationships between organizations and CI facilities, form the Adversarial Socio-Technical Network (ASTN) that informs the analysis. Third, the Analysis component processes these generated ASTN. Previously, that has included the ability to compare prevalence of different vendors for a given infrastructure component type across different regions as well as identify common public and private investors across those vendors. This was demonstrated for EV Charging Stations across several different metropolitan areas within an IEEE PES GridEdge publication. More recently, we have looked at ways to identify infrastructure owners and operators of BESS with the most nameplate capacity across different states as well as other indictors of risk resulting from changes in ownership over time. Finally, the Visualization component consists of an HTML/CSS/JS framework by which users can interact geospatial, operational, and organizational relationships across a given portfolio of Critical Infrastructure facilities. The objective is to provide a library of UI/UX modules that can be repurposed for stakeholder-specific dashboards. All of the modules are related via a common event model that enables UI actions in one view to percolate across the other views.

Weaver, Gabriel [Idaho National Laboratory (INL),

Provable Security and Resilience in Critical Infrastructure – Next Steps

With the conclusion of the Laboratory Directed Research and Development (LDRD) project on Provable Security and Resilience (PSaR) in Critical Infrastructure, we present forward-looking technical concepts and strategies that build on the project’s outcomes and INL’s long-standing expertise in infrastructure protection. The challenge is to protect critical infrastructure and functions much more efficiently at scale than capable adversaries can attack at scale. After summarizing progress and ongoing work we’ll discuss what are the challenges that remain and what are new/emerging technologies, strategies, and processes to meet those challenges. Finally, we’ll layout concepts that integrate with other protection work in the coming year and beyond. For example, building secure function-specific platforms based on the seL4 microkernel, and considering the successes of Cyber-Informed Engineering as a model for engage, collaboration, and adoption. We look forward to your feedback and collaboration as we refine and expand this vision.

97 - MATHEMATICS AND COMPUTING

Energy Storage Impacts in Resilience Hubs and Other Critical Infrastructure: An Assessment Guide for Developers and Practitioners

Battery energy storage systems (BESS) deployed behind the meter at resilience hubs and other critical infrastructure can provide economic and operational value during normal operations—such as lower and more predictable energy costs—as well as resilience and security benefits during power disruptions by maintaining essential services. However, existing evaluation approaches tend to focus narrowly on engineering performance or rely on broad socio-economic frameworks that are not well suited to behind-the-meter storage. As a result, developers, utilities, and funders often lack consistent methods for defining success, quantifying benefits, and comparing outcomes across projects. This report presents a practitioner-oriented impact assessment framework for evaluating behind-the-meter BESS at resilience hubs and critical infrastructure facilities. The framework is organized into five iterative components—developing an action plan, defining project goals, identifying metrics, collecting data and measuring outcomes, and reporting and using results—and includes a structured metric architecture spanning six impact categories. Designed for real-world constraints such as limited staffing and uneven data availability, the framework was developed, applied, and refined through real projects, and is illustrated with case studies across diverse deployment contexts.

Impact Assessment

Applications of UAVs for Remote Sensing of Critical Infrastructure

The surveillance of critical facilities and national infrastructure such as waterways, roadways, pipelines and utilities requires advanced technological tools to provide timely, up to date information on structure status and integrity. Unmanned Aerial Vehicles (UAVs) are uniquely suited for these tasks, having large payload and long duration capabilities. UAVs also have the capability to fly dangerous and dull missions, orbiting for 24 hours over a particular area or facility providing around the clock surveillance with no personnel onboard. New UAV platforms and systems are becoming available for commercial use. High altitude platforms are being tested for use in communications, remote sensing, agriculture, forestry and disaster management. New payloads are being built and demonstrated onboard the UAVs in support of these applications. Smaller, lighter, lower power consumption imaging systems are currently being tested over coffee fields to determine yield and over fires to detect fire fronts and hotspots. Communication systems that relay video, meteorological and chemical data via satellite to users on the ground in real-time have also been demonstrated. Interest in this technology for infrastructure characterization and mapping has increased dramatically in the past year. Many of the UAV technological developments required for resource and disaster monitoring are being used for the infrastructure and facility mapping activity. This paper documents the unique contributions from NASA;s Environmental Research Aircraft and Sensor Technology (ERAST) program to these applications. ERAST is a UAV technology development effort by a consortium of private aeronautical companies and NASA. Details of demonstrations of UAV capabilities currently underway are also presented.

Wegener, Steve

Augmenting LLM-Based Agents for Improved Performance in Pentesting and Commissioning Operational Technology in Critical Infrastructure

Artificial intelligence (AI), and more specifically large language models (LLMs) have the potential for use in penetration testing (“pentesting”) against devices, networks, and computer systems in information technology (IT). We explore the possibility of extending pentesting from IT systems to operational technology (OT) systems, which are more obscure than IT systems in their protocols and design. A challenge therefore exists when applying pretrained LLMs to OT systems as corpora are likely to underrepresent OT systems in comparison to other more prevalent systems. We evaluate augmentations of LLMs with various methods, especially retrieval augmented generation (RAG), to improve performance of the LLMs in the OT domain. In addition to pentesting, some of the testing of these OT devices may include commissioning to ensure that the newly installed devices work correctly. Our framework may also be applied in such cases.

97 MATHEMATICS AND COMPUTING

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY

Center for Alternate Synchronization and Timing (CAST) PTP Network Monitoring Report

The Oak Ridge National Laboratory Center for Alternative Synchronization and Timing (CAST) performs research, development, testing, and evaluation of alternative terrestrial-based timing and synchronization infrastructure for the US power grid and other critical infrastructures. Alternative timing options reduce reliance on GPS and enhance the overall resilience of critical infrastructures. CAST infrastructure uses Precision Time Protocol (PTP) as the primary conduit for delivery of synchronization packets. CAST deploys PTP over long terrestrial links to synchronize a multitude of remote boundary clocks and downstream power grid components with the authoritative grand master clocks. Network traffic issues can severely degrade PTP accuracy. This report focuses on examining network traffic anomalies and their effects on PTP operation as well as the potential implications to CAST’s high-precision remote synchronization operations.

24 POWER TRANSMISSION AND DISTRIBUTION

Alaska Transportation & Infrastructure - Identifying Permafrost Subsidence Using NASA Earth Observations to Pinpoint Road & Infrastructure Vulnerability in Fairbanks, Alaska

A rapidly warming Arctic has compromised the structural integrity of critical infrastructure through accelerated permafrost thaw and thermokarst development underlying these areas. Infrastructure, including roads, bridges, and airports across the state of Alaska are particularly at risk, as permafrost underlies ~85% of the state. However, monitoring the impacts of permafrost thaw on infrastructure is largely limited to in situ observations and frequently identified after the damage is evident. In order to assist transportation and infrastructure decision-makers in Alaska, this project identified and quantified areas of surface subsidence near critical infrastructure. Seasonal interferograms were created using Sentinel-1 C-band Synthetic Aperture Radar (SAR) and L-band Uninhabited Aerial Vehicle SAR (UAVSAR) data to identify areas experiencing surface deformation. Additionally, Light Detection and Ranging (LiDAR) datasets were used to validate select interferograms created between 2017 and 2019. Validation of subsidence detection across platforms was performed over a 7x8 sq. kilometer field site for 2017. UAVSAR and Sentinel-1 seasonal deformation returns produced consistent spatial deformation patterns with residual root mean squared errors of 13 and 21 millimeters, respectively. These results suggest that both UAVSAR and Sentinel-1 platforms are capable of detecting surface subsidence. The higher resolution of UAVSAR is better able to resolve localized subsidence features of less than 80 meters, but is limited by temporal resolution.In conjunction, UAVSAR and Sentinel-1 can provide complementary spatial and temporal resolutions for subsidence analysis in the absence of in situ data.

Patrick Saylor

Alaska Transportation & Infrastructure Identifying Permafrost Subsidence Using NASA Earth Observations to Pinpoint Road and Infrastructure Vulnerability in Fairbanks, Alaska

A rapidly warming Arctic has compromised the structural integrity of critical infrastructure through accelerated permafrost thaw and thermokarst development underlying these areas. Infrastructure, including roads, bridges, and airports across the state of Alaska are particularly at risk, as permafrost underlies ~85% of the state. However, monitoring the impacts of permafrost thaw on infrastructure is largely limited to in situ observations and frequently identified after the damage is evident. In order to assist transportation and infrastructure decision-makers in Alaska, this project identified and quantified areas of surface subsidence near critical infrastructure. Seasonal interferograms were created using Sentinel-1 C-band Synthetic Aperture Radar (SAR) and L-band Uninhabited Aerial Vehicle SAR (UAVSAR) data to identify areas experiencing surface deformation. Additionally, Light Detection and Ranging (LiDAR) datasets were used to validate select interferograms created between 2017 and 2019. Validation of subsidence detection across platforms was performed over a 7x8 sq. kilometer field site for 2017. The strongest relationship in spatial deformation is observed between Sentinel-1 and UAVSAR with a residual root mean square error of 20 mm. These results suggest that both UAVSAR and Sentinel-1 platforms are capable of detecting surface subsidence. The higher resolution of UAVSAR is better able to resolve localized subsidence features of less than 80 meters, but is limited by temporal resolution. In conjunction, UAVSAR and Sentinel-1 can provide complementary spatial and temporal resolutions for subsidence analysis in the absence of in situ data.

DEVELOP Tech Paper