Search NASA⌕ Search

SEARCH · Search NASA

Results for “OT”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Living-off-the-land Techniques Unlikely to Supplant Energy Sector-Focused OT-Specific Malware

Despite increased reports of energy sector-focused threat actors using living-off-the-land (LOTL) techniques, it is unlikely LOTL techniques will wholly supplant malware in energy sector operational technology (OT)-focused cyber operations. Threat actors leverage LOTL techniques to access energy sector networks, abstracting process information and maintaining persistence. Although threat actors using LOTL techniques have successfully interrupted energy sector industrial control environments, designed features of OT-specific malware likely increase the cyber-physical impact of an attack and delay recovery of critical functions and services. Malicious actors will very likely continue to use LOTL techniques for stealth, while designing malware to bolster final impacts on cyber-physical systems in energy sector OT environments.

99 GENERAL AND MISCELLANEOUS↗

Traffic Shaping to Traffic Engineering in Time-Sensitive OT Network

Modern industrial automation systems increasingly depend on network infrastructures for time-critical communication, driving the need for solutions that guarantee timely and reliable data delivery. IEEE 802.1 Time-Sensitive Networking (TSN) holds significant promise for converging Information Technology (IT) and Operational Technology (OT) networks, enabling interoperability and supporting the coexistence of mixed-critical traffic crucial for Industry 4.0 and IIoT. To achieve deterministic communication, TSN employs various traffic shapers such as the Time-Aware Shaper (TAS), Asynchronous Traffic Shaper (ATS), and Credit-Based Shaper (CBS). However, the effective deployment of TSN in industrial automation faces several challenges. These include the non-trivial mapping of diverse industrial traffic types to specific shapers, the complexity of optimizing shaper configurations. We present a model for effective traffic engineering within TSN enabled OT Network. Our experiments also demonstrate how shaping of certain traffic types get affected in absence of precise time synchronization and propose possible solutions based on experiment results. Based on our experimental results we provide recommendations on how traffic type assignments should be done and which traffic shaping mechanisms should be used for a particular traffic type.

Sarker, Taposh Kumer [University of Texas at El Pa↗

Multiwavelength study of OT 081: broadband modelling of a transitional blazar

ABSTRACT OT 081 is a well-known, luminous blazar that is remarkably variable in many energy bands. We present the first broadband study of the source, which includes very high energy (VHE, $E\gt $ 100 GeV) $\gamma$-ray data taken by the MAGIC (Major Atmospheric Gamma-ray Imaging Cherenkov telescopes) and H.E.S.S. (High Energy Stereoscopic System) imaging Cherenkov telescopes. The discovery of VHE $\gamma$-ray emission happened during a high state of $\gamma$-ray activity in July 2016, observed by many instruments from radio to VHE $\gamma$-rays. We identify four states of activity of the source, one of which includes VHE $\gamma$-ray emission. Variability in the VHE domain is found on daily time-scales. The intrinsic VHE spectrum can be described by a power law with index $3.27\pm 0.44_{\rm stat}\pm 0.15_{\rm sys}$ (MAGIC) and $3.39\pm 0.58_{\rm stat}\pm 0.64_{\rm sys}$ (H.E.S.S.) in the energy range of 55–300 and 120–500 GeV, respectively. The broadband emission cannot be successfully reproduced by a simple one-zone synchrotron self-Compton model. Instead, an additional external Compton component is required. We test a lepto-hadronic model that reproduces the data set well and a proton-synchrotron-dominated model that requires an extreme proton luminosity. Emission models that are able to successfully represent the data place the emitting region well outside of the broad-line region to a location at which the radiative environment is dominated by the infrared thermal radiation field of the dusty torus. In the scenario described by this flaring activity, the source appears to be a flat spectrum radio quasar (FSRQ), in contrast with past categorizations. This suggests that the source can be considered to be a transitional blazar, intermediate between BL Lac and FSRQ objects.

Abe, H.↗

IT vs. OT: Trends and Incidents

This presentation discusses the differences between information systems (IT) and operational systems (OT) and why that difference is important in the context of cybersecurity for the energy sector.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

On the Life Expectancy Ot High-power CW Magnetrons for Superconducting Accelrators

Modern CW or pulse Superconducting RF (SRF) accelerators require efficient RF sources controllable in phase and power with a reduced cost. Therefore, utilization of the high-power CW magnetrons as RF sources in SRF accelerator projects was proposed in a number of works, e.g., [1, 2]. But typically, the CW magnetrons are designed as RF sources for industrial heating, and the lifetime of the tubes is not the first priority as it is required for high-energy accelerators. The high-power industrial CW magnetrons use the cathodes made of pure tungsten. The emission properties of the tungsten cathodes are not deteriorated much by electron and ion bombardments, but the latter causes sputtering of the cathode in the magnetron crossed fields. The sputtered cathode material covers the magnetron interior. This leads to sparks and discharges that limit the life of the magnetrons. We considered an analysis of magnetron failure modes vs. output power [3]. We developed a model of ionization of the residual gas in the magnetrons interaction space and simulated the spattering of the cathode in 100 kW CW magnetrons to estimate the life expectancy. Basing on results we proposed ways to increase the CW magnetrons longevity for SRF accelerators.

43 PARTICLE ACCELERATORS↗

Cyber-Informed Engineering (CIE) Guidance to Defeat Systematic OT Weaknesses

This research summary outlines the University of Illinois Information Trust Institute (ITI) team's evaluation of whether applying the 12 Cyber-Informed Engineering (CIE) Principles could reduce or eliminate weaknesses identified by the SEI-ETF in engineered systems. ITI's findings suggest that applying CIE principles to weaknesses in MITRE CWE View 1358 can potentially mitigate or eliminate those vulnerabilities.

42 ENGINEERING↗

OT Defender Presentation - Hacker Mindset

Presentation on hacker mindset and what utilities may be up against from lone hackers or professional groups, with ideas on how to improve defensive posture.

99 - GENERAL AND MISCELLANEOUS↗

Center of Excellence for Operational Technology

The Center of Excellence for Operational Technology Traditional Presentation Abstract 2025 National Laboratories Information Technology Summit | Denver, CO Traditional Presentation Session Managing cybersecurity risk in Operational Technology (OT) presents a significant challenge across the Department, and critically, at many of the national laboratories. This includes IT-OT convergence, aging OT systems, cost of updating OT systems, and increased Advanced Persistent Threat efforts against OT including the 16 critical infrastructure sectors as listed in Presidential Policy Directive 21. DoE’s Office of Science and NNSA’s Office of the Chief Information Officer are taking the lead in addressing this challenge to include critical systems, by establishing the Center of Excellence (CoE) for Operational Technology. Championed by NNSA Deputy Chief Information Officer Steven McAndrews and the Office of Science Chief Information Officer Shila Cooch, the CoE for OT was chartered in February 2025 to address the challenges of OT cybersecurity and compliance. The CoE for OT will create partnerships and leverage expertise from across the NNSA National Security Enterprise and DOE Labs, Plants and Sites. The CoE will also collaborate with colleagues in other government agencies, industry partners and academia. The CoE for OT discussion at the National Laboratories Information Technology Summit ’25 will include the genesis of the CoE, stated goals, organizational structure, and the effort to attract OT subject matter experts to join the CoE effort to share knowledge and expertise. The discussion will include opportunities to get involved and contribute to this important effort. This session will be led by CoE for OT Co-Chairs Matt Kwiatkowski, Fermi National Laboratory Chief Information Security Officer, and Steven Weldon, Savannah River National Laboratory Cyber Program Director at the Georgia Cyber Center. The session will be of particular interest to CIOs, CTOs, CISOs, as well as IT and OT practitioners.

Kwiatkowski, Matt [Fermilab]↗

Open Source Software Prevalence Ingest Tool

The OSSP Ingest Tool accepts user-input organizational information, ingests IT/OT asset lists in Excel format, and ingests the associated CycloneDX SBOM's. It then performs analytics demonstrating the ability to answer the follow research questions: o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability to differentiate running from not-running OSS components. o RQ1c: Ability to differentiate based on the originator of the component, because a supplier may have modified it after retrieval from the upstream software source. o RQ2. Ability to correlate the identity of a single OSS component across multiple OT devices, mitigating common name variations such as differences in capitalization, '-' vs '_', and so on. o RQ3. Ability to perform subset analysis of OSS components across multiple OT devices o RQ3a: Ability to perform subset analysis across OSS libraries, generating density & distribution graphs to identify commonly-used libraries and outliers. o RQ3b: Ability to perform subset analysis of a single OSS library, generating density & distribution by CI sector, by device type, by device make/model, and/or by firmware version. o RQ3c: Ability to perform subset analysis by grouping OSS libraries according to programming language, then overlay with RQ4b. o RQ3d: Ability to perform subset analysis by OSS upstream source, providing insight into degree of modifications performed by suppliers. o RQ4. Ability to identify dependencies (transitive and direct) of each differentiated OSS library within each OT device, and enable RQ1,2,3 iteratively for dependencies. o RQ1. Ability to identify all OSS services running on, and all OSS components present within, an OT device o RQ1a: Ability to differentiate multiple versions of the same OSS component within each OT device. o RQ1b: Ability Page

Kapadia, Shayna [Lawrence Livermore National Labor↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Accelerating template generation in resonant anomaly detection searches with optimal transport

We introduce Resonant Anomaly Detection with Optimal Transport (RAD-OT), a method for generating signal templates in resonant anomaly detection searches. RAD-OT leverages the fact that the samples from the conditional probability density of the target features vary approximately linearly along the optimal transport path connecting the resonant feature. This does not assume that the conditional density itself is linear with the resonant feature, allowing RAD-OT to efficiently capture multimodal relationships, changes in resolution, etc. By solving the optimal transport problem, RAD-OT can quickly build a template by interpolating between the background distributions in two sideband regions. We demonstrate the performance of RAD-OT using the LHC Olympics R&D dataset, where we find comparable sensitivity and improved stability with respect to deep learning-based approaches.

Automation↗

Nitrogen: A promising doping strategy for high-performance ovonic threshold switching selectors

The Ovonic Threshold Switching (OTS) selector serves as an essential component in the development of three-dimensional high-density memory integration technology. Nevertheless, the state-of-the-art high-performance OTS materials usually contain toxic elements such as arsenic (As), posing significant risks to both environmental and human health. Nitrogen (N), which belongs to the same group as arsenic (As), has emerged as a highly promising alternative for As doping. However, the underlying mechanisms that govern N-based OTS materials have not yet been extensively investigated. In this study, we delve into the effects of N doping on the structural, bonding, and electronic properties of amorphous GeSe (a-GeNSe) by ab initio molecular dynamics simulations to bridge the knowledge gap. Our findings indicate that upon N doping in a-GeSe, the formation of robust Ge-N bonds, along with N-centered tetrahedral and triangular structures, resulting in the sluggish atomic movement that enhances the thermal stability and endurance of a-GeNSe. The OTS characteristics are significantly influenced by the material’s electronic band structure, and thus the relatively slow performance drift can be attributed to the stabilization of mid-gap states, a result of N doping which effectively slows down the aging process of chalcogenide glass. Moreover, the increased mobility gap in a-GeNSe raises the threshold voltage (V th ), making it more compatible with commercially available phase-change memory materials. Furthermore, our findings reveal the extensive impact of the N element on a typical OTS material and offer valuable perspectives for alternative doping strategies that could potentially supplant As practices.

36 MATERIALS SCIENCE↗

Design and construction of the CMS Outer Tracker for the phase-2 upgrade

The High-Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000–4000 fb −1 over 10 years of operation with the peak instantaneous luminosity reaching about 5–7.5 × 1 0 34 cm −2 s −1 . During Long Shutdown 3, several components of the CMS detector will undergo major improvements, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have increased radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger for the first time at a hadron collider, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely-spaced silicon sensors read out by front-end ASICs that can correlate hits in the two sensors to create short track segments, used in the Level-1 track finder. The modules come in two flavors: strip-strip and pixel-strip, containing different sensor configurations and multiple ASICs. This contribution presents the Phase-2 OT, the finalization of the OT module design, and the quality assurance and control procedures used to ensure that the modules fulfill both the specifications from the assembly steps as well as the proper communication among the ASICs.

Zoi, Irene [Fermilab] (ORCID:0000000257389446)↗