Search NASASearch

SEARCH · Search NASA

Results for “Critical infrastructure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Unified 0.25-degree gridded infrastructure-critical extreme weather for the United States from 1979 to 2100

Extreme weather events can severely disrupt critical infrastructure, triggering cascading effects on power, transportation, and essential services. However, standard weather and climate datasets often lack specialized variables necessary for hazard assessments. We present a unified dataset of infrastructure-critical weather and climate variables across the United States at 0.25° resolution, covering daily or sub-daily intervals from 1979 to 2100. The dataset includes temperature, dew point, wind gusts, precipitation partitioned by rain, snow, and freezing rain or ice pellets, lightning, and wildfire metrics. Historical conditions (1979-2023) are synthesized from observations and reanalysis products, while future projections are derived from 14 CMIP6 global climate models (historical, SSP245, and SSP585 experiments). Physically based and data-driven methods are used to estimate variables not directly provided by existing models. By integrating these variables into a single unified dataset, we enable consistent, high-resolution assessments of weather-related infrastructure risks across past and future periods, supporting wide-ranging applications in energy, transportation, water resources, emergency management, and beyond.

Climate and Earth system modelling

Arctic Critical Infrastructure: Assessing and Predicting the Risk to Critical Permafrost Infrastructure from Climate Change: A New Thermomechanical Approach

This study presents the development of a computational framework designed to predict the interaction between permafrost and infrastructure, addressing potential failure modes and mitigation strategies in the context of climate change. The framework, rooted in advanced modeling and simulation (mod/sim) techniques, integrates thermomechanical coupling to account for the complex interplay between heat flow, ice content, and mechanical behavior in permafrost. Existing models fail to fully capture these dynamics, particularly as they relate to the effects of ice saturation on structural integrity. Our innovative Arctic Coastal Erosion (ACE) framework fills this gap by coupling thermal and mechanical models to accurately simulate subsidence and deformation in permafrost environments. We applied the ACE framework to a representative runway, demonstrating its capability to predict settlement due to rising temperatures and subsequent permafrost thaw. This proof-of-concept showcases the potential of the framework to evaluate risks to Arctic infrastructure, which supports over four million people and 70% of existing permafrost-based structures. By simulating various infrastructure types and environmental conditions, our research offers insights into failure mechanisms and evaluates structural solutions to mitigate risk. The anticipated deliverables, including a prototype runway exemplar, position this project as a critical advancement in permafrost infrastructure modeling, with applications in national security and resilience planning.

54 ENVIRONMENTAL SCIENCES

Synergies Between Nuclear Security and Critical Infrastructure: National Legal and Regulatory Frameworks

Nuclear reactors and other nuclear facilities are part of a nation's critical infrastructure assets. Key cross-sector interdependencies, in relation to energy, transportation systems, communications, emergency services, water, information technologies and others, result in inevitable synergies between legal frameworks for the security of nuclear facilities and legal frameworks for the protection of critical infrastructure. The protection of nuclear facilities against sabotage and other malicious acts is paramount in ensuring energy security and thus ensuring uninterrupted energy supply. The protection of other sectors, such as uninterrupted communications, secure water supply, and others, supports a safe and secure operation of nuclear facilities. Some countries rely on broader critical infrastructure frameworks to impose security requirements on nuclear facilities, or to achieve robust cybersecurity systems. This paper will analyze the interdependencies and synergies between the legal and regulatory frameworks for critical infrastructure protection and nuclear facilities' security by comparing various national frameworks. The paper will also propose modalities to leverage the best practices and requirements from each framework towards energy security goals and stronger national nuclear security regimes.

Man, Madalina-Anca

A Data Processing Pipeline To Extract A Knowledge Graph From Heterogeneous Data For Socio-technical Analysis Of Critical Infrastructure Influence

The code is written in Python and consists of the following pipeline that is implemented in Apache Airflow. This pipeline intends to understand the companies that are directly or indirectly involved with a type of critical infrastructure system at some point in that system's lifecycle. The pipeline takes a configuration file that specifies a list of initial companies to consider, a geographic region of interest, and a set of SEC form types as well as other data sources (e.g. CrunchBase) from which to extract entities and relations. There are four main components to this pipeline as currently implemented: Entity Extraction, Network Construction, Analysis, and Visualization. First, Entity Extraction, is implemented as the `topear-extract_organizations` Apache Airflow workflow. Given an initial query that specifies a geographic region of interest and a time interval, the software will extract CI facilities of interest and organizations that have a direct influence relationship to those facilities (e.g. ownership). During the course of the LDRD, we focused on Electric Vehicle charging stations and this information is available via the Department of Energy (DOE) database on fueling stations maintained by NREL. Within the context of the DOE CESER project, we have focused on Battery Energy Storage Systems (BESS). Second, the Network Extraction component will iteratively construct a social network graph given the set of organizations and people extracted in the previous step. Organizations (and eventually People if desired) are then fed as a query to the `topgear-construct_social_network` Apache Airflow workflow which given a set of initial companies and data sets (e.g. SEC EDGAR form types, OpenCorporates, Crunchbase). This Airflow workflow will iteratively query such data sources to discover relationships with new organizations and people. For example, this module can iteratively query SEC EDGAR for metadata that documents the number of each type of form for the given set of companies and their location. This forms metadata represents a catalog of data sources from SEC EDGAR for the extracted social network knowledge graph. The pipeline then downloads these forms from the website and saves them in a build directory for further processing. These documents are then parsed for entities and relations. Again, we note that in additional to SEC data sources, this step can also pull in information on organizations via API services such as CrunchBase and OpenCorporates or bulk data sources. At the end of this step, the resultant social network, the Critical Infrastructure network, and the edges that encode relationships between organizations and CI facilities, form the Adversarial Socio-Technical Network (ASTN) that informs the analysis. Third, the Analysis component processes these generated ASTN. Previously, that has included the ability to compare prevalence of different vendors for a given infrastructure component type across different regions as well as identify common public and private investors across those vendors. This was demonstrated for EV Charging Stations across several different metropolitan areas within an IEEE PES GridEdge publication. More recently, we have looked at ways to identify infrastructure owners and operators of BESS with the most nameplate capacity across different states as well as other indictors of risk resulting from changes in ownership over time. Finally, the Visualization component consists of an HTML/CSS/JS framework by which users can interact geospatial, operational, and organizational relationships across a given portfolio of Critical Infrastructure facilities. The objective is to provide a library of UI/UX modules that can be repurposed for stakeholder-specific dashboards. All of the modules are related via a common event model that enables UI actions in one view to percolate across the other views.

Weaver, Gabriel [Idaho National Laboratory (INL),

Provable Security and Resilience in Critical Infrastructure – Next Steps

With the conclusion of the Laboratory Directed Research and Development (LDRD) project on Provable Security and Resilience (PSaR) in Critical Infrastructure, we present forward-looking technical concepts and strategies that build on the project’s outcomes and INL’s long-standing expertise in infrastructure protection. The challenge is to protect critical infrastructure and functions much more efficiently at scale than capable adversaries can attack at scale. After summarizing progress and ongoing work we’ll discuss what are the challenges that remain and what are new/emerging technologies, strategies, and processes to meet those challenges. Finally, we’ll layout concepts that integrate with other protection work in the coming year and beyond. For example, building secure function-specific platforms based on the seL4 microkernel, and considering the successes of Cyber-Informed Engineering as a model for engage, collaboration, and adoption. We look forward to your feedback and collaboration as we refine and expand this vision.

97 - MATHEMATICS AND COMPUTING

CI-MOR Final Report: Analysis and Validation of Critical Infrastructure Models using Model Order Reduction

This report summarizes the research and capabilities developed as part of the project “Analysis and Validation of Critical Infrastructure Models using Model Order Reduction” (CI-MOR) LDRD project. CI-MOR research enables the solution of large, complex optimization models that naturally arise in national security challenges involving critical infrastructures. Specifically, CI-MOR researchers developed methods to (1) rigorously approximate complex, nonlinear optimization formulations, (2) identify alternative near-optimal solutions, (3) accelerate optimization workflows used for complex applications, and (4) rigorously integrate domain knowledge in stochastic-process models. This report provides an overview of the research done in CI-MOR, and we describe application exemplars used to illustrate CI-MOR capabilities. Furthermore, we describe the software developed by CI-MOR that researchers can leverage to analyze new applications.

97 MATHEMATICS AND COMPUTING

Energy Storage Impacts in Resilience Hubs and Other Critical Infrastructure: An Assessment Guide for Developers and Practitioners

Battery energy storage systems (BESS) deployed behind the meter at resilience hubs and other critical infrastructure can provide economic and operational value during normal operations—such as lower and more predictable energy costs—as well as resilience and security benefits during power disruptions by maintaining essential services. However, existing evaluation approaches tend to focus narrowly on engineering performance or rely on broad socio-economic frameworks that are not well suited to behind-the-meter storage. As a result, developers, utilities, and funders often lack consistent methods for defining success, quantifying benefits, and comparing outcomes across projects. This report presents a practitioner-oriented impact assessment framework for evaluating behind-the-meter BESS at resilience hubs and critical infrastructure facilities. The framework is organized into five iterative components—developing an action plan, defining project goals, identifying metrics, collecting data and measuring outcomes, and reporting and using results—and includes a structured metric architecture spanning six impact categories. Designed for real-world constraints such as limited staffing and uneven data availability, the framework was developed, applied, and refined through real projects, and is illustrated with case studies across diverse deployment contexts.

Impact Assessment

EQSIM: Exascale Predictions of Earthquake Effects on Critical Infrastructure

The great “San Francisco” earthquake of 1906 is one of the most recognized, and sobering, demonstrations of the havoc that can be caused by the sudden and violent movement of Earth’s tectonic plates. The estimated 7.9-magnitude quake and subsequent fires decimated the major metropolis and surrounding areas: buildings turned to ruins, hundreds of thousands of people left homeless, and a death toll exceeding 3,000. Today, as evidenced by the catastrophic 7.8-magnitude earthquake that struck Turkey in February 2023, these events still present a significant danger to life and economic security. To mitigate the potential devastation of future earthquakes and better prepare for these inevitable events, researchers are turning to high-performance computers to simulate the underlying geophysical processes and accurately quantify associated risks to critical infrastructure.

42 ENGINEERING

Augmenting LLM-Based Agents for Improved Performance in Pentesting and Commissioning Operational Technology in Critical Infrastructure

Artificial intelligence (AI), and more specifically large language models (LLMs) have the potential for use in penetration testing (“pentesting”) against devices, networks, and computer systems in information technology (IT). We explore the possibility of extending pentesting from IT systems to operational technology (OT) systems, which are more obscure than IT systems in their protocols and design. A challenge therefore exists when applying pretrained LLMs to OT systems as corpora are likely to underrepresent OT systems in comparison to other more prevalent systems. We evaluate augmentations of LLMs with various methods, especially retrieval augmented generation (RAG), to improve performance of the LLMs in the OT domain. In addition to pentesting, some of the testing of these OT devices may include commissioning to ensure that the newly installed devices work correctly. Our framework may also be applied in such cases.

97 MATHEMATICS AND COMPUTING

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing

Data Analytics and Visualization of Energy Systems for Critical Infrastructure Insights

Modernization of energy systems including transportation facilities provides opportunities for increased efficiency, expansion of commerce and meeting industry and federal goals. A significant increase in electrical demand is projected to meet these needs, which concentrates at facilities such as airports. For example, Xcel Energy working with two airports in their service area recently published information projecting an up to fivefold increase in electricity demand in the next 25 years [1]. Concurrently, the US Government Accountability Office (GAO) recently surveyed 30 commercial service airports identifying more than 300 outages of more than 5 minutes between 2015 and 2022 [2]. Power, reliability, and resilience planning becomes more important to safely maintain operations and the flow of commerce with fewer energy carriers providing necessary energy to safely move passengers and goods. NREL proposes to develop methodologies to allow owners, utilities, and federal agencies to dynamically analyze, forecast, and manage energy loads at airports, focused upon maintaining the flow of commerce in an efficient, sustainable, and resilient way. To address these energy challenges, a suite of technologies and methodologies can be leveraged to validate concepts, inform design, de-risk solutions and optimize energy management during deployment. These technologies include digitalization of energy systems, microgrid methodologies, and related energy technologies for building and vehicle loads. [1] Electrifying Airport Ecosystems - https://www.enterprisemobility.com/content/dam/enterpriseholdings/marketing/innovation-in-mobility/vehicle-innovation/airport-electrification-study-full-report-2024.pdf [2] Airport Infrastructure: Selected Airport's Efforts to Enhance Electrical Resilience https://www.gao.gov/products/gao-23-105203.

critcal infrastructure

Hardware Aware Mitigation of Timing Side-Channel Vulnerabilities in Critical Infrastructure Software

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime sidechannel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. We propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzAR in terms of execution time overhead (up to −46%), code size overhead (up to −10%), and correctness (no failures) on five different embedded/edge devices.

Suha, Tasneem [University of Maine]

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS

Addressing Consequence within Operational Risk (O.T. Gagnon III) 9-18-2024

Addressing Consequence within Operational Risk: Why threats and security are just not that important! When dealing with cyber or physical risk within any critical infrastructure (CI) environment, don’t concern yourself with vulnerabilities and threats, at least not at first! Also, don’t be overly fixated on “securing the systems” within the organization. The endeavor of tackling operational risk focused on consequences in any critical infrastructure environment to include the complex Aviation ecosystem is challenging even for the most resourced entity but can be advanced though a simplified approach: identifying, binning, and prioritizing the infrastructure environment. While no two entities within a single element of the 16 critical infrastructure sectors are exactly alike when it comes to risk, there is a basic process to move toward a greater understanding of operational risk through becoming more informed about the infrastructure environment in which the entity exists. The process starts with bringing internal and external stakeholders and subject matter experts together to analyze key areas such as Information Technology (IT) and Operational Technology (OT) components and points of convergence, analyzing internal and external cyber and physical dependencies, accounting for explosive growth in devices and wireless technology, and leveraging the contributions of people inside and outside the operational environment. Attaining a common understanding of the infrastructure environment as part of addressing consequences within operational risk is not easy to do or resource light, but the process outlined provides the framework to further any entity’s efforts in this space. When it comes to cyber risks, before an organization can consider vulnerabilities within and threats to its operations, it must first have a solid understanding of the consequences existing inside its infrastructure environment. Idaho National Lab’s Consequence-Driven, Cyber-Informed Engineering is offered as an example of this approach to effective and efficient cyber risk mitigation.

99 GENERAL AND MISCELLANEOUS

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY