Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cyber Research”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

An Old Guys Perspective of Cyber - Journey Through INL Cyber Research

An overview of the history of cybersecurity at INL and how it has evolved with today's Critical Infrastructure, including the advancement of Electric Vehicles (EVs) and the EV charging infrastructure. Recent and future research efforts are included to demonstrate the current state of the art and where this technology might progress. With maybe a little Fear, Uncertainty, and Doubt (FUD) mixed in...

99 GENERAL AND MISCELLANEOUS↗

Ultrasound Interim cyber-physical research evaluation

Recent events have presented Medical Practitioners with concerns about safety and privacy implications associated with GE’s VScan MIot Ultrasound Device. Concerns relate to the devices potential risk to broadcast location data that can pose serious risks to device users and patients. This report was commission in collaboration with Augusta University to determine if device concerns pose real threat to operators and patients. In effort to ensure all potential threat vectors are targeted, the initial step was to analyze the supply chain. Here the devices are CT scanned to look for any hardware anomalies that could present threat vectors to users of these devices. (See SRNL-STI-2024-00225 for detailed analysis). No anomalies were found associated with the hardware utilized within the GE VScan Air.

42 ENGINEERING↗

Cyber Halo Innovation Research Program (CHIRP) Handbook: CHIRP Program Document 2026

The Cyber Halo Innovation Research Program (CHIRP) handbook outlines a comprehensive framework designed to advance space cybersecurity education, workforce development, recruitment efforts for United States Space Force (USSF) Space Systems Command (SSC) and the Department of the Airforce, and foster students’ professional growth. It provides an overview of CHIRP's objectives and strategic focus, establishing the foundation for participant engagement through a network of collaborations with academic institutions, contracted industry partners, training and certification organizations, federal agencies, and community organizations. It states a clear participation strategy for SSC and Pacific Northwest National Laboratory (PNNL) for program execution and successful support for student transition to a career in space cybersecurity.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Halo Innovation Research Program (CHIRP) Student Research Report: Program Analysis

The Cybersecurity and Space Systems Research Program (CHIRP) conducted multi-year, mission-focused research addressing emerging cybersecurity challenges affecting space and ground systems. Students from California State University San Bernardino (CSUSB), University of Texas El Paso (UTEP), and California State University Dominguez Hills (CSUDH) conducted structured research, developed proof-of-concept demonstrations, participated in applied cybersecurity training, and collaborated with Space Systems Command (SSC), academic, and industry partners. This report documents the research questions, methodologies, findings, demonstrations, and student contributions associated with each cohort. It also summarizes the program’s workforce-development outcomes, including applied cybersecurity training, professional certifications, technical credentials, and partnerships with organizations such as CT Cubed, Inc. and ISC2. Collectively, CHIRP strengthened the space-cybersecurity workforce pipeline and produced research and prototype efforts that may inform future cybersecurity assessments, test and evaluation activities, cyber-range development, acquisition planning, operational training, and mission-assurance initiatives.

McKenzie, Penny L.↗

Situational Awareness of Grid Anomalies (SAGA)

The modern power industry becomes more vulnerable to cyber events due to the growing interconnectivity, interdependence, and complexity of the electric power grid. High-fidelity modeling and simulation tools that support the preventative risk analysis on potential cyber-relevant events is essential for ensuring the situational awareness of the system operator as it provides an inexpensive and risk-free environment to test the system responses under various cyber-relevant events and hereby can support research on cyber anomaly detection, optimal protective resource allocation, and mitigation measures. In this webinar, we will share NREL's cybersecurity research capabilities by highlighting the development of a scalable cyber-physical event test bed and demonstration with real hardware in the loop. The developed cyber-physical event test bed is backboned by an integrated transmission, distribution, and communication dynamic co-simulation framework and a plug-and-play cyber event generation module. It is designed to be modular and compatible with parallel computing, and thereby supports large-scale system simulations at an affordable computation cost. The test bed can capture millisecond-to-minutes dynamic frequency and voltage responses under cyber events from the bulk transmission system to the active distribution systems and distributed energy resources at the grid edge.

co-simulation↗

Advanced Research on Integrated Energy Systems Cyber Range

As digital technologies expand to meet the needs of a more autonomous, interconnected, and advanced power system, new cybersecurity complexities and vulnerabilities arise. The ARIES Cyber Range enables the energy sector to evaluate these evolutions and validate cybersecurity solutions without impacting live systems. Combining power grid-scale hardware with emulation and simulation approaches, the ARIES Cyber Range can faithfully replicate modern energy systems - from grid physics to communication networks, and everything in between - with real-world fidelity. At NLR, researchers and partners are answering complex power system cybersecurity questions, examining emerging threats to the electric sector, and de risking new security technologies, all at a mission-relevant speed that keeps pace with rapidly evolving systems and hazards.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

The NREL Cyber Range

With the National Renewable Energy Laboratory's (NREL's) cyber range, researchers can replicate cybersecurity scenarios as they would occur on real, complex energy systems. With supercomputing and advanced emulation capabilities, the cyber range allows users to build digital twins of real systems and connect the emulated environment to actual physical devices throughout NREL's laboratories. The space offers unlimited potential to test the frontier of energy systems security.

cyber range↗

A High-Fidelity Cyber-Physical Testbed-Based Benchmarking Dataset For Testing Operational Technology Specific Intrusion Detection Systems

Quality datasets serve a critical purpose in cyber security research. Data is needed to understand system behavior and develop security controls to protect critical systems. However, for critical infrastructure operational environments there is a lack of available datasets to study because of the high cost and specialized capabilities necessary to generate them. This paper documents the development of a dataset of high fidelity hardware in the loop laboratory simulated models of electric and natural gas distribution systems with real cyber attack test cases. A deep dive discussion for the experimental setup and controls for generating the data is provided along with observations from using the data in evaluating intrusion detection approaches.

Ashok, Aditya↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Wintap

Wintap is an extensible, general purpose agent framework for the Windows operating system. It provides an easy-to-use plugin architecture, an integrated streaming analytics engine, and real-time event subscriptions for host-based data. Wintap can support a wide variety of applications across production operations, cyber security operations, and cyber security research.

Frye, DavidJ↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

STRATOS: A cyber-energy SAAS platform to manage real-time experiment configuration and deployment [SWR-23-16]

STRATOS is a novel management SAAS platform for achieving multi-environment, multi-tenant real-time cyber-energy experimentation. The platform empowers users to configure a wide variety of experiment environments by automating the initialization process and providing a framework for building system configurations. During run-time the platform ensures resources are allocated appropriately and the environment remains stable until the required cyber-energy events have occurred. This capability to manage this complex process in a single user-focused application significantly reduces difficulty and setup time for performing high-impact cyber-energy research.

Van Natta, Joshua↗