Search NASA⌕ Search

SEARCH · Search NASA

Results for “Defense In Depth”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

1. Physical Security Engineering by Design for Nuclear Facilities; 2. Nuclear Power Plant Site Security Management – A Security Strategy; 3. The UAE Women in Nuclear Energy Security

1. Security by design, or SeBD, is a comprehensive approach that integrates the physical protection system of a nuclear plant into every stage of its existence. This includes planning, designing, constructing, commissioning, and operating the facility, using a combination of analytical, physical, technological, and procedural measures. Essentially, SeBD involves intentionally applying and incorporating security into all aspects of design and operation throughout the entire lifecycle of a facility. By implementing this methodology throughout various phases such as program development, process implementation, staff training and procedures management in conjunction with plant equipment, facilities can be optimized to minimize security risks without compromising functional design requirements. This ultimately improves the overall security posture of the site and reduces the need for costly modifications or additional security resources post-design. 2. A site security strategy is a living document that is revised on a periodic or event-driven basis, ensuring that site security operations and corresponding procedures provide long-term, effective protection for the entire nuclear power plant (NPP) site. A site security strategy aims to mitigate threats across the entire NPP site via in-depth defense approaches and mutual support; therefore, if a layer is omitted or altered, then the effect across all layers must be re-evaluated. Therefore, the aim of the site security strategy is to provide an appropriate, scalable security regime that deters, denies, delays, and detects incidents and, equally importantly, reassures legitimate users and the regulator that due diligence and regulatory compliance have been achieved, ensuring that the site is safe and secure. Robust access control for vehicles and pedestrians is at the heart of the strategy. Vehicle and pedestrian searching and screening are seen as the strongest mitigation methods against vehicle- and pedestrian-borne attacks. The security strategy must also be supported through comprehensive staff training and the development of robust processes, procedures, and planning. If all these measures are to be effective, then training must be implemented during each phase of construction, partial operation/commissioning, and full operation. No single element of site security is completely isolated from the influence of other elements. Ideally, consideration of all key elements will result in a security strategy that is integrated and proportional to the threat and that does not over specify individual security solutions through the application of isolated measures but rather applies a holistic, all-encompassing approach. 3. When women enter the labor force, numerous positive outcomes emerge, including increased GDP, educational gains, and decreased maternal mortality. Despite these benefits, women's employment rates and equality vary significantly worldwide as does support for women in the workforce. This paper will explore the multifaceted benefits of women's employment, the factors influencing labor force participation rates, and the urgency to achieve gender equality as outlined in the 2015 United Nations Sustainable Development Goals (SDGs). It will then examine the emerging presence of women in the traditionally male-dominated nuclear field, specifically within the United Arab Emirates (UAE) as a testament to their resilience and determination to break social norms and advance gender equality.

Zineddin, Dr. Z.↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

Robust Restoration From Cyber-Physical Attacks in Active Distribution Grids With Grid-Edge IBRs

The inverter-based resources (IBRs) have enabled the integration of renewable energy at the grid edge with enhanced control capabilities to support the reliable operation of power grids. Different control frameworks, such as hierarchical or distributed architecture, have been proposed with the expansion of cyber networks for real-time monitoring and control. This evolution of critical infrastructure into cyber-physical systems also brings more vulnerabilities for the broadened attack surfaces, and significantly increases the possibility of physical system failures or outages caused by cyberattacks. Among tremendous efforts in the defense-in-depth approach, it remains challenging to provide prompt detection and accurate location of attack entry points or paths. Therefore, the prevailing restoration framework may struggle to fully consider the cyber-physical interdependence, successfully isolate the compromised cyber and physical components, and safely recover the systems without the potential risks leading to secondary outages. This paper is motivated to develop a cyber-physical restoration framework for distribution grids to recover from cyber attacks by harnessing grid-edge IBRs. The framework is first built on the operational guidelines of IBRs considering the compromised cyber layer. Then, an ambiguity set is established to represent the uncertainty of attack scenarios and their possibility levels. Next, a distributionally robust optimization model is developed to provide the optimal load restoration strategy across all scenarios. The effectiveness of the proposed model is demonstrated through various use cases on the modified IEEE 13-node and 123-node test systems. Finally, simulation results demonstrate the effectiveness and advancement of developed post-attack restoration strategies.

Cybersecurity↗

Nuclear Safety [Vol. 35, No. 2, July-December 1994]

Nuclear Safety is a journal that covers significant issues in the field of nuclear safety. Its primary scope is safety in the design, construction, operation, and decommissioning of nuclear power reactors worldwide and the research and analysis activities that promote this goal, but it also encompasses the safety aspects of the entire nuclear fuel cycle, including fuel fabrication, spent-fuel processing and handling, and nuclear waste disposal, the handling of fissionable materials and radioisotopes, and the environmental effects of all these activities. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 179 Consideration of Postaccident Consequences in the Determination of Safety Objectives for Future Nuclear Power Plants in France, D. Queniart, A. Sugier, and J. Lochard; ACCIDENT ANALYSIS: 187 Nuclear Safety Research: The Phebus FP Severe Accident Experimental Program, P. von der Hardt, A. V. Jones, C. Lecomte, and A. Tattegrain; 205 Containment Performance Analysis of the Advanced Neutron Source Reactor at the Oak Ridge National Laboratory, S. H. Kim, R. P. Taleyarkhan, and V. Georgevich; 213 Assessment of Fission Product Deposits in the Reactor Coolant System: The DEVAP Program, G. Le Marois and M. Megnin; 222 Erratum to “A Review of the Available Information on the Triggering Stage of a Steam Explosion," Vol. 35, No. 1, CONTROL AND INSTRUMENTATION: 223 Effects of Normal Aging on Calibration and Response Time of Nuclear Plant Resistance Temperature Detectors and Pressure Sensors, H. M. Hashemian; DESIGN FEATURES: 235 Defense in Depth Against the Hydrogen Risk—A European Research Program, F. Fineschi; ENVIRONMENTAL EFFECTS: 246 Technical Note: A Preliminary Analysis of the Risks to Hong Kong Resulting from Potential Accidents of Daya Bay Nuclear Power Plant, Z. Shi and X. Wei; OPERATING EXPERIENCES: 253 Reactor Shutdown Experience, Compiled by J. W. Cletcher; SPECIAL SECTION ON TMI-2 VESSEL INVESTIGATION PROJECT: 256 Three Mile Island—New Findings 15 Years After the Accident A. M. Rubin and E. Beckjord; 269 Relocation of Molten Material to the TMI-2 Lower Head, J. R. Wolf, D. W. Akers, and L. A. Neimark; 280 Insight Into the TMI-2 Core Material Relocation Through Examination of Instrument Tube Nozzles, L. A. Neimark; 288 Physical and Radiochemical Examinations of Debris from the TMI-2 Lower Head, D. W. Akers and B. K. Schuetz; 301 Results of Metallographic Examinations and Mechanical Tests of Pressure Vessel Samples from the TMI-2 Lower Head, D. R. Diercks and G. E. Korth; 313 Margin-to-Failure Calculations for the TMI-2 Vessel, J. Rempe, L. Stickler, S. Chavez, G. Thinnes, R. Witt, and M. Corradini; U.S. NUCLEAR REGULATORY COMMISSION INFORMATION AND ANALYSES: 328 1993 Accident Sequence Precursor (ASP) Program Results, L. N. Vanden Heuvel, J. W. Cletcher, D. A. Copinger, J. W. Minarick, B. W. Dolan, and P. D. O’Reilley; RECENT DEVELOPMENTS: 339 Reports, Standards, and Safety Guides, D. S. Queener; 345 Proposed Rule Changes as of June 30, 1994; ANNOUNCEMENTS: 234 Thirty-First Annual Meeting of the National Council on Radiation Protection and Measurements; 356 1995 International Incineration Conference; 358 Fifth International Controls and Instrumentation Conference; 359 ANS International Topical Meeting on Safety of Operating Reactors; 359 Fifth International Conference on Nuclear Criticality Safety; 360 International Conference on Probabilistic Safety Assessment Methodology and Applications; 351 The Authors; 357 Reviewers of Nuclear Safety, Vol. 35.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Multilevel Cybersecurity for Photovoltaic Systems

The motivation behind this project is to protect critical infrastructure in electric power generation pertaining to solar photovoltaic (PV) systems. This growing renewable energy resource is becoming a more vital part of the nation’s energy portfolio, particularly since it has achieved grid-parity to existing generation methods in terms of cost. It is thus vital that steps be taken to ensure the cybersecurity of these assets. The project goal was to devise a multilevel cybersecurity solution to address PV security gaps at the inverter and system levels, and field test the solution under the supervision and review of a US-based solar inverter manufacturer and PV installer/operator. A two-level cyberattack defense approach was formulated whereby the first level, the solar inverter level, hardens individual devices and achieves a deeply cyber-secure inverter. The inverter level security involves a multi-layer defense-in-depth approach for securing the inverter while also providing data for the system level algorithms. The second level, the system level, addresses intrusion detection and restoration involving an ensemble of inverters and relevant systems.

14 SOLAR ENERGY↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Advancement and Application

This report documents activities performed by Idaho National Laboratory (INL) during fiscal year (FY) 2024 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, Digital Instrumentation and Control (DI&C) Risk Assessment project. The goal of the RISA Pathway is to optimize safety margins and minimize uncertainties to achieve economic efficiencies while maintaining high levels of safety. This is accomplished by providing scientific basis to better represent safety margins and factors that contribute to cost and safety, and by developing new technologies that reduce operating costs. The research efforts for FY 2024 encompass methodology refinement and exploration. The efforts include: (1) The implementation of a natural language processing tool to expedite key aspects of the reliability analysis methods developed by INL; (2) advances to support intersystem CCF analysis by providing guidance for and identification of coupling mechanisms that may contribute to CCF; (3) the investigation of how generative artificial intelligence tools can aid in hazard analysis and diversity and defense in depth (i.e., D3) assessments; (4) Industry collaboration, allowing the demonstration of and INL's risk assessment tools to support risk assessment of DI&C systems at early and late stages of development; (4) a roadmap for the development of a software for each of INL's risk assessment tools; (5) The development of a theory and methodology manual for a risk quantification methodology; (6) the development of a reliability analysis for machine learning (ML)-integrated control systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Implications of Safety and Operational Features of Small, Advanced Reactors for the Evaluation of Important Human Actions

The design and operational characteristics of non-light water reactors are likely to change the role of human actions in safety function management and the types of human actions that are deemed important. The objectives of this report are to: • Identify the implications of small, advanced reactor design characteristics on human performance and the changing role of human actions in the management of safety functions. • Identify the methods that may be used to identify important human actions. • Identify how HFE safety reviewers can help ensure that the methods adequately model human actions to identify those that are important to safety. We identified the implications of small, advanced reactor characteristics on the role of personnel in safety function management. Then we addressed how designers can identify which human actions are important to safety using both probabilistic risk assessment (PRA) and deterministic analyses. PRA identifies important human actions using risk-importance criteria. Deterministically identified important human actions include those identified by analyses of situations such as transients and accidents and defense in depth. In all cases, the acceptability of the analyses is dependent on the modeling, quantification, and criterion selection to determine which human actions are important. How well the designers address these processes determines the acceptability of their methodology.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Security Licensing Basis Framework Development

This report summarizes a technology-inclusive and performance-based method to determine the physical security licensing basis for a commercial nuclear reactor under the proposed 10 CFR 73.100 for Part 53 licensees. The method focuses on the identification of security functions, the contributing security systems and programs to meet those functions, the identification of security events that will provide the foundation for the security licensing basis and includes a risk-informed performance-based defense in depth adequacy method. The method can also be employed to justify performance-based alternative measures to traditional security requirements found in 10 CFR 73.55.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Programmable Digital Devices used in Advanced Reactors

This paper introduces the concepts of common cause failure, diversity, and defense-in-depth used by the nuclear industry to analyze resilience in reactors. A survey of publicly traded and private companies building advanced reactors and their licensing status is presented. Safety and non-safety systems found in the NuScale Power design are summarized and the likely hardware and software categories used by those systems are enumerated. The importance of industry partners is highlighted. This paper also identifies an alternate path forward without industry partners to advance the knowledge needed to use artificial intelligence to analyze HBOMs and SBOMs to better understand reactor resiliency.

cybersecurity↗

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗

Implementation of Programmatic Quality and the Impact on Safety

The purpose of this paper is to discuss the implementation of a programmatic quality assurance discipline within the International Space Station Program and the resulting impact on safety. NASA culture has continued to stress safety at the expense of quality when both are extremely important and both can equally influence the success or failure of a Program or Mission. Although safety was heavily criticized in the media after Col~imbiaa, strong case can be made that it was the failure of quality processes and quality assurance in all processes that eventually led to the Columbia accident. Consequently, it is possible to have good quality processes without safety, but it is impossible to have good safety processes without quality. The ISS Program quality assurance function was analyzed as representative of the long-term manned missions that are consistent with the President s Vision for Space Exploration. Background topics are as follows: The quality assurance organizational structure within the ISS Program and the interrelationships between various internal and external organizations. ISS Program quality roles and responsibilities with respect to internal Program Offices and other external organizations such as the Shuttle Program, JSC Directorates, NASA Headquarters, NASA Contractors, other NASA Centers, and International Partner/participants will be addressed. A detailed analysis of implemented quality assurance responsibilities and functions with respect to NASA Headquarters, the JSC S&MA Directorate, and the ISS Program will be presented. Discussions topics are as follows: A comparison of quality and safety resources in terms of staffing, training, experience, and certifications. A benchmark assessment of the lessons learned from the Columbia Accident Investigation (CAB) Report (and follow-up reports and assessments), NASA Benchmarking, and traditional quality assurance activities against ISS quality procedures and practices. The lack of a coherent operational and sustaining quality assurance strategy for long-term manned space flight. An analysis of the ISS waiver processes and the Problem Reporting and Corrective Action (PRACA) process implemented as quality functions. Impact of current ISS Program procedures and practices with regards to operational safety and risk A discussion regarding a "defense-in-depth" approach to quality functions will be provided to address the issue of "integration vs independence" with respect to the roles of Programs, NASA Centers, and NASA Headquarters. Generic recommendations are offered to address the inadequacies identified in the implementation of ISS quality assurance. A reassessment by the NASA community regarding the importance of a "quality culture" as a component within a larger "safety culture" will generate a more effective and value-added functionality that will ultimately enhance safety.

Huls, Dale Thomas↗

A Proven Methodology for Developing Secure Software and Applying It to Ground Systems

Part Two expands upon Part One in an attempt to translate the methodology for ground system personnel. The goal is to build upon the methodology presented in Part One by showing examples and details on how to implement the methodology. Section 1: Ground Systems Overview; Section 2: Secure Software Development; Section 3: Defense in Depth for Ground Systems; Section 4: What Now?

security↗

Internship Presentation: Integrating Safety and Cybersecurity: Security-by-Design with SOWT Analysis for Reactor Testing

This study covers leveraging reactor testing facilities that are primarily designed with a focus on safety to enhance cybersecurity testing. By incorporating reactor security-by-design with reactor safety-by-design principles and adopting defense-in-depth strategies that emphasize both safety and security, the research evaluates applicable cyber tools, models, and solutions. This includes simulating specific cyber-attack scenarios using reactor simulators and performing SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis to improve the cybersecurity of reactor systems.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Malcolm Deployment Guide for Solar Power Generation Plants

This guide provides detailed instructions for deploying Malcolm in Solar Power Generation systems. It covers the deployment process, from understanding the network architecture of these systems to configuring network switches and Switched Port Analyzer (SPAN) ports or mirror ports or TAPs. The guide also includes best practices for deploying Hedgehog sensors, another critical component in these systems. Following this guide, users can enhance network visibility, improve their system’s security, and effectively troubleshoot common issues.

14 SOLAR ENERGY↗

Seasonal Snow Extent and Snow Volume in South America Using SSM/I Passive Microwave Data

Seasonal snow cover in South America was examined in this study using passive microwave satellite data from the Special Sensor Microwave Imagers (SSM/I) on board Defense Meteorological Satellite Program (DMSP) satellites. For the period from 1992-1998, both snow cover extent and snow depth (snow mass) were investigated during the winter months (May-August) in the Patagonia region of Argentina. Since above normal temperatures in this region are typically above freezing, the coldest winter month was found to be not only the month having the most extensive snow cover but also the month having the deepest snows. For the seven-year period of this study, the average snow cover extent (May-August) was about 0.46 million sq km and the average monthly snow mass was about 1.18 x 10(exp 13) kg. July 1992 was the month having the greatest snow extent (nearly 0.8 million sq km) and snow mass (approximately 2.6 x 10(exp 13) kg).

Foster, James L.↗

Seasonal Snow Extent and Snow Mass in South America Using SMMR and SSM/I Passive Microwave Data (1979-2003)

Seasonal snow cover in South America was examined in this study using passive microwave satellite data from the Scanning Multichannel Microwave Radiometer (SMMR) on board the Nimbus-satellite and the Special Sensor Microwave Imagers (SSM/I) on board Defense Meteorological Satellite Program (DMSP) satellites. For the period from 1979-2003, both snow cover extent and snow depth (snow mass) were investigated during coldest months (May-September), primarily in the Patagonia area of Argentina and in Chile. Most of the seasonal snow in South America is in the Patagonia region of Argentina. Since winter temperatures in this region are often above freezing, the coldest winter month was found to be the month having the most extensive snow cover and also usually the month having the deepest snow cover as well. Sharp year-to-year differences were recorded using the passive microwave observations. The average snow cover extent for July, the month with the greatest average snow extent during the 25-year period of record, is 320,700 km(exp 2). In July of 1984, the average monthly snow cover was 701,250 km(exp 2) - the most extensive coverage observed between 1979 and 2003. However, in July of 1989, snow cover extent was only 120 km(exp 2). The 25-year period of record shows a sinusoidal like pattern, though there appears to be no obvious trend in either increasing or decreasing snow extent or snow mass between 1979 and 2003.

Foster, J. L.↗