Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity Risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Linking Threat Agents to Targeted Organizations: A Pipeline for Enhanced Cybersecurity Risk Metrics

In this study, we present a methodology leveraging Large Language Models (LLMs) to transform Cybersecurity Threat Intelligence (CTI) narratives into actionable insights for individual organizations. Our approach automates the extraction of machine-readable adversary SKRAM (Skills, Knowledge, Resources, Authorities, and Motivation) attributes from open-source reports, extending LLM utility beyond typical interactions. This innovation enables precise, automated assessments of cybersecurity risks posed by various adversaries. Using a chain-of-thought and multi-shot prompting strategy, our methodology advances the automation of cybersecurity feature extraction for new machine-learning models that predict the risk of adversary targeting. This approach is refined using a substantial dataset of over 150 analyst-validated threat reports and synthetic organizational data from 900 companies. Here, by bootstrapping the training data with a rule-based heuristic over synthetic data, we have developed a high-accuracy machine-learning model that allows entities to dynamically prioritize threats and defensive actions.

Cyber Threat Intelligence↗

Quantifying Cybersecurity Risk for NASA Missions

An end-to-end cyber risk assessment process is presented that is based on the combination of guidelines from the National Institute of Standards & Technology (NIST), the standard 5x5 risk matrix, and quantitative methods for generating loss exceedance curves. The NIST guidelines provide a framework for cyber risk assessment, and the standard 5x5 matrix is widely used across the industry for the representation of risk across multiple disciplines. Loss exceedance curves are a means of quantitatively assessing the loss that occurs due to a given risk profile. Combining these different techniques enables us to follow the guidelines, adhere to standard 5x5 risk management practices and develop quantitative metrics simultaneously. Our quantification process is based on the consideration of the NASA and JPL Cost Risk assessment modeling techniques as we define the cost associated with the cybersecurity risk profile of a mission as a function of the mission cost.

Miller, Robert L.↗

Hydropower Cybersecurity Risk Management and Valuation

Advancements to DOE WPTO funded Hydropower Cybersecurity Value-at-Risk Framework application allows stakeholder to translate risk-based assessments to quantitative scores allowing to better decision making for cybersecurity investments.

13 HYDRO ENERGY↗

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Integrating Cybersecurity Risk Assessment with Process Safety in Chemical Process Industries

This dissertation bridges the gap between industrial cybersecurity and traditional process safety by introducing an integrated Cyber-LOPA framework that combines the Purdue Enterprise Reference Architecture, Cyber Kill Chain, and CVSS v4.0 metrics. Demonstrated on a High-Density Polyethylene slurry process, the work illustrates how cyber threats targeting automation systems can bypass physical protection layers, proving the necessity of unified risk assessments to prevent cyber-induced physical incidents in chemical manufacturing plants.

Cyber-LOPA (CLOPA)↗

Cyber100 Compass: Quantification of Cybersecurity Risks for Systems Transitioning to High Levels of Renewables (Final Report)

The shift to high levels of renewable deployment will entail a significant re-engineering of the grid. As investors, utilities, customers, and others prepare for clean energy transitions, there is need to understand how restructuring the grid to accommodate renewables will change the attack surface of the grid and accompanying cyber risk. However, today the cyber-physical risks associated with electric grids incorporating high levels of renewable deployment remain largely unknown. The Cyber100 Compass proof-of-concept application attempts to quantify future cyber-physical security risks by combining risk data gathered from subject matter experts (SMEs) with input from system planners about conditions they expect to be true about their electric systems in the future. Users provide data about their organization’s tolerance for risk; the value they place on avoiding the consequences of different cyber events; and conditions that they expect to be true on their systems at some point in the future. The SMEs provide baseline probabilities for different cyber events; the probability that an event will be low-, moderate-, or high-impact; and the amount by which user-identified conditions on their systems will change the likelihood of the cyber events. The application takes both the user and SME input and performs a series of Monte Carlo simulations to arrive at a quantification of risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Cybersecurity Value-at-Risk Framework: Informing Cybersecurity Decisions

The Cybersecurity Value-at-Risk Framework is a tool that can be used by hydropower plant manager to make more educated cybersecurity investments. Users can take a self guided assessment allowing the tools to generate risk, impact and cybersecurity scores and be given risk-based recommendations to enhance decision-making.

CVF↗

Gateway Implementation of Cybersecurity Requirements

Cybersecurity threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is a critical discipline that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfil and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Cybersecurity↗

Gateway Implementation of Cybersecurity Requirements

Cyber threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is one of the critical subsystems that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfill and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Svetlana Hanson↗

Dynamic probabilistic risk assessment and game theory for cyber security risk analysis in nuclear power plants

Nuclear Power Plants and energy systems have become more prone to cyber-attacks with their digitalization and the increased use of smart equipment. Hence, it is important to quantify the risk associated with cyber-attacks in such systems. Dynamic Probabilistic Risk Assessment which involves studying the evolution of a system due to random events and operator and attacker actions during a cyber-attack by employing a physics-based model of the system is a suitable framework to quantify cybersecurity risk in nuclear power plants. In addition to the plant dynamics, it is also important to model the strategies of the attackers and plant operators for an effective cybersecurity risk assessment. Game theory provides a set of necessary tools to model such strategic interactions. In this research, a framework that integrates dynamic probabilistic risk assessment with game theory for cybersecurity risk analysis in nuclear power plants is presented. The mathematical formulation is derived based on the theory of continuous event trees. We propose a game theory based action model, that utilizes physics-based rewards to define the strategies of attackers and operators at every decision epoch. As a case study, the risk associated with cyber-attacks on the digital components in the secondary side of a pressurized water reactor is studied using a reduced order model. A set of attacker actions and a set of operator actions are defined for the system. The operator and attacker interactions were modelled using simultaneous game, their action policies were computed using the concept of mixed strategy Nash equilibrium and the evolution of the system was studied.

97 MATHEMATICS AND COMPUTING↗

Cyber100 Compass [SWR 23-64]

Cyber100 Compass ("Compass") is a unique risk assessment framework that will enable grid system planners to understand and mitigate cybersecurity risk for grids transitioning to high levels of renewable generation, including 100%. The idea for Compass was developed by NREL based on past work on high-renewable grids and a series of discussions with DOE. Compass is part of Cyber100, a portfolio of proposed research activities that would greatly expand understanding of cybersecurity for high-renewable grids. Compass is a desktop application designed with a user-friendly interface. The tool gathers information from users, conducts probabilistic backend calculations, and outputs a series of visualizations to help users understand and analyze their cybersecurity risks based on the unique features of their future grid. Compass will take as inputs the values for different conditions and produce a risk score of the resulting grid. By trying different configurations, system planners can compare the resultant risks against their own risk tolerance and decide which system-of-system controls to implement as they transition toward a 100% renewable grid.

Martin, Maurice↗

Cybersecurity Standards, Certification, and Best Practices for DERs

Distributed energy resources (DERs) are becoming increasingly important to the electric grid, including solar energy systems. However, DERs also introduce new cybersecurity risks, including those posed by cloud computing. Standards harmonization is essential for ensuring that DERs are secure and can be safely integrated into the grid. This panel will discuss cyber standards harmonization for solar security. The panel will feature experts from the S2G Program, National Labs and Industry who will discuss the following topics: the cybersecurity risks and future benefits posed by ubiquitous solar energy systems, the development and implementation of cloud-based security solutions for DERs, including solar energy systems, the challenges and opportunities for harmonizing DER cybersecurity standards, and Cyber Informed Engineering and the solar security implementations The panel will also discuss the following specific initiatives: the S2G Program's DER Cybersecurity Framework, UL's DER Cybersecurity Certification Program, and IEEE 1547 Updates. The panel will conclude with a discussion of the future of standards harmonization for DER cybersecurity.

14 SOLAR ENERGY↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems may become more widely deployed throughout the country, and so it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity of the facility, and the company that owns the facility. The two main ways bad actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when companies conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks associated with a generic hydrogen storage system by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Large-Scale Hydrogen Storage Cyber Risk Assessment

Hydrogen storage systems are becoming more widely deployed throughout the country, and as their presence continues to grow, it is possible that individual and interconnected systems will be exposed to cyber-attacks. These events can cause physical and financial harm to employees, people in the vicinity, and to the company that owns the facility. The two main mechanisms malicious actors may access information or control from a hydrogen storage facility are through information technology and operations technology devices, the former of which refers to data and information from networked devices and the latter of which refers to onsite controls for the physical system. Both types of entryways into the system should be considered when facility managers conduct cyber risk assessments and when regulators develop or revise relevant codes and standards. This report analyzes cybersecurity risks applicable to a wide variety of hydrogen storage systems by outlining the system's purpose and the importance of its cybersecurity. The hydrogen storage system architecture and communication protocols are provided to understand potential cyber vulnerabilities. Later, an event tree analysis is performed on hydrogen operation to identify system weaknesses by outlining potential attack scenarios. This report also identifies critical cyber assets related to different hydrogen operations followed by an examination of potential threats, and the impact of cyber assets on those operational assets.

08 HYDROGEN↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

ByzSec — A Multi-layered Byzantine Resilient Architecture for Bulk Power System Protective Relays

Reliability, selectivity, and sensitivity are the fundamental attributes of any protection system, acting as the main drivers in the selection of schemes, and equipment. In high-voltage systems, microprocessor-based relays represent the industry’s preferred solution, providing engineers with a vast array of benefits. However, they remain vulnerable to cybersecurity events that may compromise their functionality. To help mitigate against potential cybersecurity risks, this paper presents a fault-tolerant, Byzantine Resilient (BR) architecture that significantly increases the cybersecurity attributes of a protection system while minimizing the amount of performance impacts and integration overheads introduced. The solution relies on an array of independent relays that utilize robust consensus methods (based on Spire [1], [2]) to ensure correct system behavior is achieved even when a relay has been compromised. Furthermore, the solution has been complemented with a custom-built Situational Awareness engine that can be used to detect and identify potential threats. The implemented solution has been developed in consultation with three hardware vendors and has been tested to comply with the performance requirements of a 345kV differential protection scheme (87T). The results indicate that the proposed architecture is a comprehensive solution that: supports the strict correctness and performance requirements of the bulk power grid while providing a cost-effective alternative that offers a seamless, long-term solution.

byzantine security, Fault Tolerant Application Sof↗