Search NASA⌕ Search

SEARCH · Search NASA

Results for “IT security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

1. Physical Security Engineering by Design for Nuclear Facilities; 2. Nuclear Power Plant Site Security Management – A Security Strategy; 3. The UAE Women in Nuclear Energy Security

1. Security by design, or SeBD, is a comprehensive approach that integrates the physical protection system of a nuclear plant into every stage of its existence. This includes planning, designing, constructing, commissioning, and operating the facility, using a combination of analytical, physical, technological, and procedural measures. Essentially, SeBD involves intentionally applying and incorporating security into all aspects of design and operation throughout the entire lifecycle of a facility. By implementing this methodology throughout various phases such as program development, process implementation, staff training and procedures management in conjunction with plant equipment, facilities can be optimized to minimize security risks without compromising functional design requirements. This ultimately improves the overall security posture of the site and reduces the need for costly modifications or additional security resources post-design. 2. A site security strategy is a living document that is revised on a periodic or event-driven basis, ensuring that site security operations and corresponding procedures provide long-term, effective protection for the entire nuclear power plant (NPP) site. A site security strategy aims to mitigate threats across the entire NPP site via in-depth defense approaches and mutual support; therefore, if a layer is omitted or altered, then the effect across all layers must be re-evaluated. Therefore, the aim of the site security strategy is to provide an appropriate, scalable security regime that deters, denies, delays, and detects incidents and, equally importantly, reassures legitimate users and the regulator that due diligence and regulatory compliance have been achieved, ensuring that the site is safe and secure. Robust access control for vehicles and pedestrians is at the heart of the strategy. Vehicle and pedestrian searching and screening are seen as the strongest mitigation methods against vehicle- and pedestrian-borne attacks. The security strategy must also be supported through comprehensive staff training and the development of robust processes, procedures, and planning. If all these measures are to be effective, then training must be implemented during each phase of construction, partial operation/commissioning, and full operation. No single element of site security is completely isolated from the influence of other elements. Ideally, consideration of all key elements will result in a security strategy that is integrated and proportional to the threat and that does not over specify individual security solutions through the application of isolated measures but rather applies a holistic, all-encompassing approach. 3. When women enter the labor force, numerous positive outcomes emerge, including increased GDP, educational gains, and decreased maternal mortality. Despite these benefits, women's employment rates and equality vary significantly worldwide as does support for women in the workforce. This paper will explore the multifaceted benefits of women's employment, the factors influencing labor force participation rates, and the urgency to achieve gender equality as outlined in the 2015 United Nations Sustainable Development Goals (SDGs). It will then examine the emerging presence of women in the traditionally male-dominated nuclear field, specifically within the United Arab Emirates (UAE) as a testament to their resilience and determination to break social norms and advance gender equality.

Zineddin, Dr. Z.↗

Multilayered Network Models for Security: Enhancing System Security Engineering with Orchestration

Security engineering approaches can often focus on a particular domain—physical security, cyber security, or personnel security, for example. Yet, security systems engineering consistently faces challenges requiring socio-technical solutions to address evolving and dynamic complexity. While some drivers of this complexity stem from complex risk environments, innovative adversaries, and disruptive technologies, other drivers are endogenous and emerge from the interactions across security engineering approaches. In response, INCOSE's Systems Security Working Group identified the need to better coordinate “disparate security solutions [that] operate independently” as one of eleven key concepts in their IS21 FuSE Security Roadmap. From this perspective, this need for “security orchestration” aligns with the perspective that security is a property that emerges from interactions within complex systems. Current efforts at Sandia National Laboratories are developing a systems security engineering approach that describes high consequence facility (HCF) security as a multidomain set of interacting layers. The result is a multilayered network (MLN)-based approach that captures the interactions between infrastructure, physical components, digital components, and humans in nuclear security systems. This article will summarize the MLN-based approach to HCF security and describe two preliminary results demonstrating potential benefits from incorporating interactions across disparate security solutions. Here, leveraging the logical structure of networks, this MLN model-based approach provides an example of how security orchestration provides enhanced systems security engineering solutions.

42 ENGINEERING↗

Connecting Nuclear Security to International Frameworks on Gender and Security

The international community is slowly beginning to recognize the intersections between the law and policy on international security – particularly arms control, non-proliferation, and disarmament – and the body of human rights law that addresses gender equality. Notably absent from this discussion is the field of nuclear security. Despite its historical underpinnings as an inherently domestic activity, nuclear security is thoroughly grounded in international treaty law. Yet, nuclear security is often overlooked in the international security context and has not been well situated with international instruments that address gender equality. We argue that gender equality in nuclear security should be understood as an important component of broader efforts to achieve equal opportunities for women in work and critical to ensuring women are included in conflict prevention efforts. Linking nuclear security to broader international efforts to increase gender equality in security and conflict prevention will provide a clearer structure and framework for gender equality initiatives in the nuclear security field. This is critically important given that estimates indicate that women comprise only twenty percent of the nuclear security workforce. Moreover, situating nuclear security in a broader international legal framework will simultaneously help states meet their gender equality commitments emanating from other instruments. This paper will first analyze the relationship between nuclear security and broader international security efforts, in particular arms control treaties and non-proliferation regimes. It will then survey the relevant international and regional frameworks for gender equality, particularly those that have applicability in the security context. This paper will next explore the relationship between nuclear security and these frameworks on gender. We find that some instruments provide support for gender equality initiatives in nuclear security because of their mandate to states to provide structural gender equality, and others are particularly relevant where they call for women's participation in conflict prevention. This paper concludes with recommendations to states that are concerned about the underrepresentation of women in nuclear security.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Towards Fully Secure 5G Ultra-Low Latency Communications: A Cost-Security Functions Analysis

Future components to enhance the basic, native security of 5G networks are either complex mechanisms whose impact in the requiring 5G communications are not considered, or lightweight solutions adapted to ultra-reliable low-latency communications (URLLC) but whose security properties remain under discussion. Although different 5G network slices may have different requirements, in general, both visions seem to fall short at provisioning secure URLLC in the future. In this work we address this challenge, by introducing cost-security functions as a method to evaluate the performance and adequacy of most developed and employed non-native enhanced security mechanisms in 5G networks. We categorize those new security components into different groups according to their purpose and deployment scope. We propose to analyze them in the context of existing 5G architectures using two different approaches. First, using model checking techniques, we will evaluate the probability of an attacker to be successful against each security solution. Second, using analytical models, we will analyze the impact of these security mechanisms in terms of delay, throughput consumption, and reliability. Finally, we will combine both approaches using stochastic cost-security functions and the PRISM model checker to create a global picture. Our results are first evidence of how a 5G network that covers and strengthened all security areas through enhanced, dedicated non-native mechanisms could only guarantee secure URLLC with a probability of ~55%.

5G networks↗

Workshop on Establishing and Operating a National Nuclear Security Support Centre Hypothetical Scenario: “Centralia Nuclear Security Support Centre Strategy Implementation Plan”

[This is part of a hypothetical scenario-based exercise for workshop participants, based on the fictitious country "Centralia."] In prior years, as a part of efforts to strengthen and better sustain nuclear security within the State, Centralia requested through the Integrated Nuclear Security Support Plan (INSSP) framework that the International Atomic Energy Agency (IAEA) conduct an expert mission on establishing and operating a national nuclear security support centre (NSSC). After the IAEA conducted the NSSC expert mission, members of the Centralia Committee on Nuclear Security (CNS) agreed to initiate the feasibility determination phase of establishing an NSSC, in line with the systematic process recommended by the IAEA. Centralia Nuclear Regulatory Authority (CNRA), as the designated lead organization for coordinating the feasibility determination process, prepared a Feasibility Report in collaboration with members of the CNS and based on input gathered among relevant national stakeholders. The report was presented to the National Security Advisor (NSA), who reviewed and approved the proposal for Centralia to proceed with establishing an NSSC. After Centralia moved into the planning phase for the Centralia Nuclear Security Support Centre (CNSSC), per REF, the primary stakeholders of the centre jointly developed this strategy implementation plan, which provides an outline of the organizational structure, needs analysis, programme objectives, financial and project management, risk management, and other key aspects of the centre. This document will be reviewed and updated as necessary on a semi-annual basis during the project implementation period of establishing CNSSC.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Artificial Intelligence for (AI) Nuclear Security: Expert Perspectives on AI Priorities for the Office of International Nuclear Security

Artificial intelligence (AI) has the potential to transform nuclear security operations, offering opportunities to enhance effectiveness while simultaneously introducing new challenges. As AI technologies rapidly evolve, agencies across the United States Government (USG) are researching, implementing, and evaluating various AI models and systems. Given the broad capabilities and applications of these technologies, it is essential for each agency to identify and articulate those areas where it can make meaningful contributions aligned with its mission and expertise. To address this need for strategic focus, in late Fiscal Year 2025 (FY2025), the Office of International Nuclear Security (INS) established an AI Task Force (AITF) to gather input from subject matter experts (SMEs) regarding the most appropriate role INS could serve in researching, evaluating, or implementing AI for nuclear security. The AITF engaged 15 experts from national laboratories with backgrounds in cyber security, physical security, transport security, insider threat mitigation, nuclear engineering, human-systems engineering, and AI/ML development. This white paper summarizes the insights gathered from these SMEs and presents a potential roadmap for INS engagement with AI technologies. The recommendations outlined here are intended to inform INS leadership as they make strategic decisions about resource allocation and program direction in this rapidly evolving technological domain.

97 MATHEMATICS AND COMPUTING↗

Fusing Edge Computing with Transport Security by Leveraging the Controller Area Network Transport Security Tracking and Reporting (C-STAR) Unit

Rapid advances in embedded system complexity and capability provides exciting opportunities for transportation security deployment. Manufacturers and developers of these embedded systems continue to provide lower cost and more powerful solutions that can be leveraged by researchers and engineers. Furthermore, deploying these devices at the “edge” of the Internet-of-Things (IoT) infrastructure provides opportunities for highly capable applications in transport security. In an edge computation architecture, the device is co-located at the source of the data in the larger IoT structure – this provides computational capability at the location directly where the data is collected. For shipment transport security, this provides a direct compute node for digestion of data and mitigation actions in real-time. In our application, the vehicle provides a significant amount of this data that can be processed in real-time via the Controller Area Network Transport Security Tracking and Reporting (C-STAR) edge device. Utilization of a computational node located on the vehicle, such as the C-STAR, capitalizes on previously discussed opportunities of edge architectures. In this paper, we will discuss this security solution’s usability, current deployments, and scalability to further applications in transport security. First, we will cover the supported vehicle platforms that can leverage the C-STAR technology. This will be particularly relevant to medium- and heavy-duty vehicles transporting high-risk shipments. Second, we will speak to current deployments of the C-STAR that are ongoing. Finally, we will discuss additional areas for expansion such as maturing the onboard algorithms through continuing collaborations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

Workshop on Establishing and Operating a National Nuclear Security Support Centre Hypothetical Scenario: "Republic of Centralia Nuclear Security Support Centre Feasibility Report"

[This is part of a hypothetical, scenario-based exercise for workshop participants, based on the fictitious country "Centralia."] This report serves as official record of the coordinated process completed by competent authorities and other organizations with nuclear security responsibilities in the Republic of Centralia to determine the feasibility of establishing and operating a national nuclear security support centre (NSSC). The report summarizes all sustainability needs and available resources identified during the feasibility determination process, including consideration of possible NSSC institutional models, in line with the systematic approach recommended by the International Atomic Energy Agency (IAEA). Centralia Nuclear Regulatory Authority (CNRA), as the designated lead organization for coordinating the feasibility determination process, has prepared this report in collaboration with members of the Committee on Nuclear Security (CNS) and based on input gathered among relevant national stakeholders. The report has been presented to the National Security Advisor (NSA), for final review and decision-making as to whether Centralia should proceed with establishing an NSSC.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cybersecurity and Infrastructure Security Agency (CISA) Infrastructure Security Division (ISD) Assessment Prioritization Project

The Cybersecurity and Infrastructure Security Agency’s Infrastructure Security Division (CISA ISD) manages a diverse portfolio of assessments across the nation’s critical infrastructure sectors. These assessments—ranging in type, scope, and complexity—are essential for identifying vulnerabilities and strengthening national security. However, the wide variation in assessment offerings and the increasing demand for limited resources have highlighted the need for a transparent, structured approach to prioritizing assessment activities. To address this challenge, CISA ISD partnered with Lawrence Livermore National Laboratory (LLNL) to review current assessment methodologies, analyze existing prioritization practices, and develop a comprehensive, national-security-focused prioritization framework. This report summarizes the project’s approach, key findings, and actionable recommendations for enhancing ISD’s assessment program.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS): A Probabilistic Approach

In this project, we employ a layered protection strategy incorporating advanced optimization and detection techniques using a probabilistic approach. The probabilistic approach is not only applied when detecting cyber attacks, but also incorporated in control strategies, which greatly increases the attacking difficulties. Hackers need to understand both probabilistic detection algorithms and uncertainty modeling methods in control in order to execute any effective attacks. The end-to-end solutions enable us to provide Building Intelligence with Layered Defense using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS).

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Water Security: Trends, Capabilities, and Research Directions to Secure Water Infrastructure

Water and wastewater sector is target rich and resource poor ~153k water utilities, serve 80% of US population ~16k publicly-owned wastewater systems in the US serve 75% of the population Need scalable solutions to fit small and medium to large systems Federal attention to critical infrastructure continues to grow – particularly in the water sector Increase in water sector incidents and threats for large scale disruption – particularly by nation-state actors and their proxies EPA is the SRMA DHS CISA focuses on critical infrastructure protection across sectors They must work together to secure WWW systems Research capabilities to enable secure water systems Current and future threats Resilience – natural disasters, accidents, cyber-physical attacks

99 - GENERAL AND MISCELLANEOUS↗

Security Analysis of a Class of Secured Spread Spectrum Systems

Abstract—A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain the estimates of relevant entropy values which will be then used to quantify the rate of information recovery as more data are being transmitted. It turns out that such information recovery requires adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.

97 - MATHEMATICS AND COMPUTING↗

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

CYDRES: CYber Defense and REsilient System for securing grid-interactive efficient buildings

Smart buildings, especially Grid-interactive Efficient Buildings (GEBs), suffer from cyber-attacks and physical faults due to the integration of a large number of sensors and controls, connected devices, and associated communication networks. This study demonstrated a real-time advanced building resilient platform, called CYber Defense and REsilient System (CYDRES), which is deployable for existing and emerging Building Automation Systems (BASs). CYDRES aims to empower GEBs with cyber-attack-immune capabilities through multi-layer prevention and adaptation mechanisms to monitor, detect, and respond to cyber-attacks and physical operational faults. CYDRES is demonstrated through real-time experiments in a Hardware-in-the-Loop (HIL) testbed.

Building automation system, Cyber-attacks, Physica↗