Search NASASearch

SEARCH · Search NASA

Results for “OT Environment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks

Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology

97 - MATHEMATICS AND COMPUTING

I Can't Patch My OT Systems! A Look at CISA's KEVC Workarounds & Mitigations for OT

We examine the state of publicly available information about known exploitable vulnerabilities applicable to operational technology (OT) environments. Specifically, we analyze the Known Exploitable Vulnerabilities Catalog (KEVC) maintained by the US Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) to assess whether currently available data is sufficient for effective and reliable remediation in OT settings. Our team analyzed all KEVC entries through July 2025 to determine the extent to which OT environments can rely on existing remediation recommendations. We found that although most entries in the KEVC could affect OT environments, only 13% include vendor workarounds or mitigations as alternatives to patching. This paper also examines the feasibility of developing such alternatives based on vulnerability and exploit characteristics, and we present early evidence of success with this approach.

97 MATHEMATICS AND COMPUTING

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie

5G integrated edge computing platform for efficient component monitoring in coal-fired power plants

This project developed a cutting-edge 5G-integrated edge computing framework to enhance operational efficiency and reliability in coal-fired power plants through real-time component monitoring and anomaly detection. The initiative focused on leveraging distributed machine learning, federated learning, and 5G-based dynamic network slicing to support scalable, fault-tolerant monitoring environments to meet the operational requirements in industrial control systems. With a Distributed Edge Computing Service (DECS) orchestration, this project enabled federated learning at edge for condition monitoring and introduced adaptive client selection strategies to minimize communication overhead. Scalable distributed training was achieved using the Horovod framework, thus enhancing performance across edge nodes. In the realm of 5G networking, the project designed and deployed reconfigurable, QoS-aware network slicing tailored for operational technology (OT) environments, integrating software-defined networks to bolster cyber-resilience and enabling dynamic slicing for federated learning workloads. A significant milestone was the development of a virtualized ICS environment with 5G core integration—which allowed elastic and fault tolerant distributed training on real-world datasets such as NASA Bearings, Hydraulic Systems, and TEP. To broaden the impact of the project, a TRL-3 virtualized ICS testbed for research and education was designed. This project engaged several graduate and undergraduate students to conduct research on the cutting-edge technology, and it resulted in one PhD dissertation, one MS thesis, and over 14 peer-reviewed publications. With the support of this project students also participated in national cybersecurity competitions to improve their professional development skills.

20 FOSSIL-FUELED POWER PLANTS

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G

Equipment Self-Assessment Guide Checklist

This Equipment Self-Assessment Checklist is designed for asset owners and operators (AOOs) responsible for the deployment, operation, maintenance, or cybersecurity oversight of grid systems and digital energy technologies. It provides a structured inspection checklist for evaluating the security, integrity, and operational trustworthiness of equipment across substations, generation sites, distributed energy resources (DERs), and control environments.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA

Clean Energy Cybersecurity Accelerator: Cohort 2 - Asimily Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator (TM) (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION

Scan2Sim: Software to Convert Network Scans to Emulations

Within operational technology (OT) systems design, the construction of testing environments for simulation is often a tedious, manual process that slows down safety and security evaluations. This document details the design and functionality of Scan2Sim, a program designed to construct high-fidelity topological schematics for OT systems without significant manual human input. Scan2Sim may take as input a detailed network scan of a system, and produces an instruction set to re-create the original scanned network within a virtualized simulation network. This construction is achieved via heuristic methods of machine template selection, which allows for a fast, performant approach to automated environment construction. The current tool is designed to produce topology schematics compatible with the Minimega, a tool designed by Sandia National Laboratories for repeatable experimentation management.

97 MATHEMATICS AND COMPUTING

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION

Module Testing Procedures and Results for the CMS Phase-2 Outer Tracker Upgrade at Fermilab

The High-Luminosity LHC (HL-LHC) will operate at significantly increased luminosities and is expected to deliver about 3000 $fb^{-1}$ of proton-proton collision data at $\sqrt{s}=14$ TeV over a decade of operation. To maintain efficient tracking and triggering performance under high pileup and radiation conditions, the CMS experiment is upgrading its tracking detector for Phase-2 operations. The upgraded Outer Tracker (OT) will consist of Pixel-Strip (PS) and Strip-Strip (2S) silicon modules capable of providing tracking information to the Level-1 trigger at 40 MHz. Production and qualification of OT modules have been ongoing for about one year across several assembly and testing centers in the US, Europe, India, and Pakistan, requiring extensive testing to ensure stable operation in the HL-LHC environment. Fermilab is responsible for the production and testing of a significant fraction of the OT modules. The testing activities include IV characterization of silicon sensors, noise and pedestal measurements, verification of communication between module components, and burn-in studies using cold-box systems operated under controlled thermal conditions. Results from module testing and qualification studies performed during production will be presented.

Baradia, Sweta [UC, Davis (main)]

Design and construction of the CMS Outer Tracker for the phase-2 upgrade

The High-Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000–4000 fb −1 over 10 years of operation with the peak instantaneous luminosity reaching about 5–7.5 × 1 0 34 cm −2 s −1 . During Long Shutdown 3, several components of the CMS detector will undergo major improvements, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have increased radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger for the first time at a hadron collider, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely-spaced silicon sensors read out by front-end ASICs that can correlate hits in the two sensors to create short track segments, used in the Level-1 track finder. The modules come in two flavors: strip-strip and pixel-strip, containing different sensor configurations and multiple ASICs. This contribution presents the Phase-2 OT, the finalization of the OT module design, and the quality assurance and control procedures used to ensure that the modules fulfill both the specifications from the assembly steps as well as the proper communication among the ASICs.

Zoi, Irene [Fermilab] (ORCID:0000000257389446)

Design and Construction of the CMS Outer Tracker for the Phase-2 Upgrade

The High Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000-4000~fb$^{-1}$ after 10 years of operation with peak instantaneous luminosity reaching about 5-7.5$\times10^{34}$cm$^{-2}$s$^{-1}$. During Long Shutdown 3, several components of the CMS detector will undergo major changes, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have high radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger, for the first time at hadron colliders, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely spaced silicon sensors read out by front-end ASICs, which can correlate hits in the two sensors creating short track segments (stubs), used for tracking in the L1 track finder. The modules come in two flavors: strip-strip (2S) and pixel-strip (PS), containing different sensor configurations and multiple ASICs. This contribution will present the design of the Phase-2 OT, the first results with pre-production devices, and the quality assurance procedures used to ensure the functionality of the modules: from fulfilling the precision specification of the module assembly procedure to ensuring the proper communication among the module's ASICs.

43 PARTICLE ACCELERATORS

Design and construction of the CMS Outer Tracker for the Phase-2 Upgrade

he High Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of $3000-4000$~fb$^{-1}$ after 10 years of operation with peak instantaneous luminosity reaching about $5-7.5\times10^{34}$cm$^{-2}$s$^{-1}$. During Long Shutdown 3, several components of the CMS detector will undergo major changes, called Phase-2 upgrade, to be able to operate in the challenging environment of the HL-LHC. The current CMS silicon strip tracker has to be replaced with a new detector. The Phase-2 Outer Tracker (OT) will have higher radiation tolerance, higher granularity, and the capability to handle higher data rates compared to the current system. Another key feature of the OT will be to provide tracking information to the Level-1 (L1) trigger, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made out of modules with two closely spaced sensors read out by front-end ASICs, which can correlate hits in the two sensors creating short track segments called stubs. The stubs will be used for tracking in the L1 track finder. The modules come in two flavors: strip-strip (2S) and pixel-strip (PS), which contain different sensor configurations and multiple ASICs. In this contribution, the design of the CMS Phase-2 OT, the technological choices, and the quality assurance (QA) procedures used to ensure the functionality of the modules will be reported. The contribution will cover the first results with pre-production devices and the different aspects taken into account during the QA: from fulfilling the precision specification of the module assembly procedure to ensuring the proper communication between the different ASICs on the module. The module noise performance is also checked and the full module functionality is verified at different temperatures.

Zoi, Irene

Network Slicing for Federated Learning in Operational Technology Environment

Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments are essential to modern infrastructure, facing challenges in ensuring low-latency, high-throughput communication while mitigating cyber threats. This paper presents a framework integrating Federated Learning (FL) and network slicing with Quality of Service (QoS) to enable real-time monitoring without disrupting OT operations. Leveraging digital twin technology and Network Function Virtualization (NFV), the architecture supports predictive analytics and Industry 4.0 requirements. FL facilitates decentralized model training, preserving data privacy and scalability, though it introduces potential throughput constraints. Network slicing addresses this by creating dedicated virtualized segments optimized for performance and security. Advanced fault tolerance at the container and instance levels enhances system reliability. The proposed architecture ensures high throughput, low latency, and secure orchestration for real-time anomaly detection in OT networks. Performance evaluations validate its efficiency in throughput, deployment, and learning accuracy, providing a robust foundation for future ICS automation and data-driven decision-making.

Delgado, Brian G. Rodiles [University of Texas at

Multiwavelength study of OT 081: broadband modelling of a transitional blazar

ABSTRACT OT 081 is a well-known, luminous blazar that is remarkably variable in many energy bands. We present the first broadband study of the source, which includes very high energy (VHE, $E\gt $ 100 GeV) $\gamma$-ray data taken by the MAGIC (Major Atmospheric Gamma-ray Imaging Cherenkov telescopes) and H.E.S.S. (High Energy Stereoscopic System) imaging Cherenkov telescopes. The discovery of VHE $\gamma$-ray emission happened during a high state of $\gamma$-ray activity in July 2016, observed by many instruments from radio to VHE $\gamma$-rays. We identify four states of activity of the source, one of which includes VHE $\gamma$-ray emission. Variability in the VHE domain is found on daily time-scales. The intrinsic VHE spectrum can be described by a power law with index $3.27\pm 0.44_{\rm stat}\pm 0.15_{\rm sys}$ (MAGIC) and $3.39\pm 0.58_{\rm stat}\pm 0.64_{\rm sys}$ (H.E.S.S.) in the energy range of 55–300 and 120–500 GeV, respectively. The broadband emission cannot be successfully reproduced by a simple one-zone synchrotron self-Compton model. Instead, an additional external Compton component is required. We test a lepto-hadronic model that reproduces the data set well and a proton-synchrotron-dominated model that requires an extreme proton luminosity. Emission models that are able to successfully represent the data place the emitting region well outside of the broad-line region to a location at which the radiative environment is dominated by the infrared thermal radiation field of the dusty torus. In the scenario described by this flaring activity, the source appears to be a flat spectrum radio quasar (FSRQ), in contrast with past categorizations. This suggests that the source can be considered to be a transitional blazar, intermediate between BL Lac and FSRQ objects.

Abe, H.