Search NASA⌕ Search

SEARCH · Search NASA

Results for “Security Information and Event Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Mapping SIEM Vulnerabilities in STIG

SIEM (Security Information and Event Management) tools monitor network traffic and allow users to quickly detect problems in their networks. Because of the valuable information processed by SIEM tools, it is important to understand their vulnerabilities. STIG (Structured Threat Intelligence Graph) is an application created at INL used to visualize data related to cyber threats. Using STIG can allow users to understand vulnerabilities related to their SIEM products and how to protect their systems.

99 GENERAL AND MISCELLANEOUS↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Human Supervision of Autonomous Vehicle Fleet Operations and Associated Passenger Communications: Preprint

Advances in automated vehicle (AV) technology and expanded operations are rapidly emerging with Automated Mobility District (AMD) deployments in global cities. NLR's AMD research addresses critical elements of human supervision of AV fleet operations and associated passenger communications for vehicles in which no driver or safety attendant is present. Although sufficiently advanced AVs no longer have direct oversight by a driver, fleet management remains staffed with operations personnel at the operations command and control (OCC) facility. This paper examines the functionality of the OCC, drawing comparisons of how automated train control and automated people mover OCCs operate. Within an AMD, the OCC manages various vehicle types, sizes, and operational modes, including on-demand and fixed route service, to facilitate a 'network of networks' for transport within a metropolitan area. The OCC serves as oversight for multiple AV fleets assisting AVs via remote operation of vehicles, communication, and dispatching personnel to resolve problems. The OCC also coordinates system operation, geographically staging vehicles, and managing weather, police, and emergency events. Informed by traffic management center (TMC) strategies using highly integrated software and communications, OCCs facilitate seamless information flows. OCC personnel remotely assist passengers and oversee multi-party operation to ensure safety and security. Although social norms mitigate large-capacity unattended vehicle operations, social interaction in multi-party automated small vehicles has little precedent. This poses a new frontier for society and requires research to effectively understand and manage. Future research will monitor OCC implementations, passenger interfaces, and deployment scaling of initial AMD systems.

33 ADVANCED PROPULSION SYSTEMS↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗

Supply Chain Management in Cyber Grid Guard Framework

Grid modernization has impeded innovative power grid applications and energy resources that are increasingly distributed. Blockchain/distributed ledger technology (DLT) has the potential to enhance the resilience of the electric infrastructure, particularly in a decentralized and distributed environment. The benefits of blockchain are to ensure asset information and lifecycle events are secure and traceable and identify potential malicious modification of data. Oak Ridge National Laboratory (ORNL) has developed a framework, Cyber Grid Guard (CGG), incorporating blockchain. The system implements a low-energy, fast, and robust enhancement to system trustworthiness within and across electric grid systems, including substations, control centers, and metering infrastructures. Currently, one of the major concerns is supply chain attacks. There have been several recent attacks that have significantly impacted critical infrastructures and organizations around the world. This document focuses on how CGG can be used to address the supply chain issue.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Dose Coefficient Calculation for Use in Dosimetry Assessment of a Fission-Based Weapon

In the event of a fission-based weapon or improvised nuclear device (IND) detonation, dose coefficients can be harnessed to provide dose assessments for defense, emergency preparedness, and consequence management, as well as to prospectively inform the assessment of radiation biomarkers and development of medical prophylaxis countermeasures for defense and homeland security stakeholders and decision-makers. Although dose coefficients have previously been calculated for this group, they would apply specifically to the studied population, the 1945 Japanese cohort, after which their anthropomorphic computational phantoms were modeled. For this reason, applications to other populations may be limited, and instead, an assessment of a more standardized population is desired. We employed a series of computational human phantoms representing international reference individuals: UF/NCI voxel phantom series containing newborn, 1-, 5-, 10-, 15-, and 35-year-old males and females. Irradiation of the phantoms was simulated using the Monte Carlo N-Particle transport code to determine organ dose coefficients under four idealized irradiation geometries at three distances from the detonation hypocenter at Hiroshima and Nagasaki using DS02 free-in-air prompt neutron and photon fluence spectra. Through these simulations, age-specific dose coefficients were determined for individual organs. Various articulated PIMAL stylized phantoms were simulated as well to estimate the effect of body posture on dose coefficients and determine the effect of posture on dosimetric estimation and reconstruction. Results additionally demonstrate that 137 Cs and the Watt fission spectra are not ideal general surrogate sources for fission weapons, which may be considered for experimental testing of medical countermeasures. Supplementary data provided tabulates the compilation of organ dose-rate coefficients in this study.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Development of a Framework for Data Integration, Assimilation, and Learning for Geological Carbon Sequestration (DIAL-GCS) (Final Report)

This project aimed to develop and demonstrate a Data Integration, Assimilation, and Learning framework for geologic carbon sequestration projects (DIAL-GCS). DIAL-GCS is an intelligence monitoring system (IMS) for automating GCS closed-loop management by leveraging recent developments in machine learning technologies, complex event processing (CEP), and reduced-order modeling. The safe and efficient operation of GCS repositories requires integrated monitoring to track the injected CO¬2 as it moves within a storage reservoir. GCS projects are data intensive, as a result of proliferation of digital instrumentation and smart-sensing technologies. GCS projects are also resource intensive, often requiring multidisciplinary teams performing different monitoring, verification, accounting (MVA) tasks throughout the lifecycle of a project to ensure secure containment of injected CO2. The success of GCS thus depends in a large part on our ability to access, assimilate, and analyze heterogeneous data and information sources in a timely manner. This project included a number of meaningful and necessary tasks to transform the human domain knowledge into machine-interpretable rules for automating knowledge extraction and discovery in GCS. The specific technical objectives of the proposed DIAL-GCS project were to develop an ontology-driven GCS data management module for storing, querying, and exchanging GCS data (both historic and live sensor data) from multiple sources and in heterogeneous formats. Incorporate a CEP engine for detecting abnormal situations by seamlessly combining expert knowledge, rule-based reasoning, and machine learning. Enable uncertainty quantification and predictive analytics using a combination of coupled-process modeling, AI/ML methods, and reduced-order modeling, and integrate and demonstrate the system’s capabilities with both real and simulated data. As far as we know, this is one of the first projects aimed to develop intelligent monitoring systems (IMS) targeting the GCS. Under this project, the team had developed a large number of web applications and scientific algorithms that contribute the main theme of intelligent monitoring. The team has published more than a dozen peer reviewed papers and disseminated the research results at multiple technical meetings.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilient Information Architecture Platform for Smart Grid (RIAPS)

A number of emerging trends will substantially alter the operation and control of the electric grid over the next several decades. These trends include ensuring resiliency under severe weather events, increasing integration of renewable electricity generation, supporting changing electricity demand patterns, and the improving cost effectiveness of distributed energy resources. To address these challenges, the future “Smart Grid” management will need to transition from centralized to coordinated distributed control paradigm. Reliable operation of the Smart Grid depends on distributed intelligence realized through software applications that run on distributed computing devices attached to the power system to collect data and collaboratively manage resources. However, much of the existing software for Smart Grid-enabled devices is either proprietary or developed with custom solutions, which limits interoperability among the heterogeneous devices and hinders the ability to manage system-level reliability, security, and resiliency requirements. Additionally, this approach makes Smart Grid applications hard to maintain, evolve, verify, and replace; resulting in high development and deployment costs. Further development of the Smart Grid requires a reusable software base-layer to move from hard-coded functionality to a plug-and-play architecture capable of managing system-level objectives and constraints in addition to providing consistent common services across heterogeneous devices and applications. Vanderbilt University, in collaboration with North Carolina State University and Washington State University has developed a foundation ‘software platform’ for developing and deploying robust, reliable, effective and secure software applications for the Smart Grid. The Resilient Information Architecture Platform for the Smart Grid (RIAPS) provides core services for building effective and powerful smart grid applications. It offers unique services for real-time data dissemination, fault tolerance, and coordination across apps distributed over the network.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Best Practices for Grid Communications

As the grid evolves, the communications architecture will need to evolve with it. That architecture affords a structured means by which the evolving complexities of the modern electric grid can be managed. This document provides best practices that can be implemented in the grid of today and evolve towards the grid and grid architecture of the future. The evolving grid and its control communications increasingly rely on commercial communications providers and a variety of technologies, from wireless (e.g., 5G, microwave, Wi-Fi) to wireline (fiber, copper) to radio communications (P25, other repeater-based systems), and all these communications systems rely on electric power. A reliable and resilient grid must account for this complex set of interdependencies in its planning activities, especially those involving restoration and recovery. The participation of all relevant parties in both planning and exercising of plans can prevent unexpected conditions that impede the reliable operation and recovery of the grid. Best practices for grid communications include using a Network Management System to document the operational state, define and monitor baselines, detect changes, and accelerate response to abnormalities. If transitioning from SONET to IP/packet-based systems, translating grid requirements into communications requirements for latency, bandwidth and throughput, IP packet delay variation, packet loss, and availability should inform and drive technology planning and selection as well as that communication system’s Quality of Service (QoS) policies and Service Level Agreements (SLAs). Secure and reliable timing is another key component of a reliable and resilient grid that can operate through adverse events. A trusted internal NTP configuration, an integrated and diverse timing delivery system, optimizing the timing architecture based on the transport technologies of the communications system, and using established standards can deliver the level of timing accuracy required by a range of time-sensitive power system applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

LandScan Mosaic Rapid Population Update: Jamaica After Hurricane Melissa (V1)

During a natural disaster such as Hurricane Melissa, understanding where people are located is critical for situational awareness, operational planning and humanitarian support and consequence assessment. Traditional population datasets focus on mapping populations based on residential, or "business-as-usual" scenarios. However, natural disasters can create disruptions in daily routines of population in addition to the magnitude of the population displacement, depending on the type, duration, context, and location of the event. The Geospatial Science and Human Security Division at Oak Ridge National Laboratory (ORNL) produced this latest LandScan Mosaic Rapid Population Update for Jamaica following Hurricane Melissa, a category 5 hurricane that made landfall on Jamaica on October 28 2025. This Rapid Population Update captures the immediate population displacement following the hurricane using a combination of open-source building damage assessment data from Microsoft, flood exposure data from the Global Flood Monitoring service, reported population displacement information, and humanitarian shelter locations from the Jamaican Office of Disaster Preparedness and Emergency Management and the underlying LandScan Mosaic Jamaica as a base population.

97 MATHEMATICS AND COMPUTING↗

Fracture Network Prediction Using Physics-based Machine Learning Algorithms

In recent years, systematic CO2 injection into geological reservoirs across the U.S. has gained traction as a strategy to mitigate greenhouse gas emissions. This approach necessitates precise monitoring to ensure secure containment, minimize risks, and optimize storage management. Our study leverages machine learning (ML) techniques to advance the understanding of CO2 injection processes, focusing on the Illinois Basin. Over a three-year injection period, we analyzed microseismic data, identifying 19 temporal intervals with significant bottom-hole pressure changes. By partitioning microseismic events into these intervals and estimating b-values, we revealed over 100 clusters of events related to fracture initiation or reactivation. Advanced spatial analysis highlighted horizontally-oriented fractures along the NNW-SSE axis. This quantification of fracture networks informs dynamic injection scheduling, work-over strategies, and risk assessments, enhancing carbon capture, utilization, and storage (CCUS) operations. Additionally, our methodology offers valuable insights for oil and gas operations and geothermal development, supporting fracture-based monitoring and risk mitigation.

Kumar, Abhash↗

Pacific Northwest National Laboratory Annual Site Environmental Report for Calendar Year 2022 (Final Report)

Pacific Northwest National Laboratory (PNNL), one of the U.S. Department of Energy (DOE) Office of Science’s 10 national laboratories, provides innovative science and technology development in the areas of energy and the environment, fundamental and computational science, and national security. There are three DOE offices within the Richland area. Two are responsible for the Hanford Site, whereas the Pacific Northwest Site Office (PNSO) oversees PNNL. PNNL prepares this Annual Site Environmental Report to meet the requirements of DOE Order 231.1B, Environmental, Safety and Health Reporting, and DOE Order 458.1, Radiation Protection of the Public and the Environment, assuring that the public is informed of any PNNL-Richland Campus or PNNL-Sequim Campus event that could adversely affect the health and safety of the public, site staff, or the environment. The report provides a synopsis of ongoing environmental management performance and compliance activities for operations that occur on the PNNL-Richland Campus in Richland, Washington, and at the PNNL-Sequim Campus near Sequim, Washington. It describes the location of and background for each facility; addresses compliance with applicable DOE, federal, state, and local regulations, and site-specific permits; documents environmental monitoring efforts and their status; presents potential radiation doses to staff and the public in the surrounding areas; and describes DOE-required data quality assurance methods used for data verification. The ASER summarizes site compliance with federal, state, and local environmental laws, regulations, policies, directives, permits, and Orders, and provides environmental management performance benchmarks and their status to the public, regulatory agencies, community officials, Native American tribes, and public interest groups.

54 ENVIRONMENTAL SCIENCES↗

Pacific Northwest National Laboratory Annual Site Environmental Report for Calendar Year 2023

Pacific Northwest National Laboratory (PNNL), one of the U.S. Department of Energy (DOE) Office of Science’s 10 national laboratories, provides innovative science and technology development in the areas of energy and the environment, fundamental and computational science, and national security. There are three DOE offices within the Richland area. Two are responsible for the Hanford Site, whereas the Pacific Northwest Site Office oversees PNNL. PNNL prepares an Annual Site Environmental Report to meet the requirements of DOE Order 231.1B, Environment, Safety and Health Reporting, and DOE Order 458.1, Radiation Protection of the Public and the Environment, thus assuring that the public is informed of any PNNL-Richland campus or PNNL-Sequim campus event that could adversely affect the health and safety of the public, site staff, or the environment. The report provides a synopsis of ongoing environmental management performance and compliance activities for operations that occur at the PNNL-Richland campus in Richland, Washington, and at the PNNL-Sequim campus near Sequim, Washington. It describes the location of and background for each facility; addresses compliance with applicable DOE, federal, state, and local regulations, and site-specific permits; documents environmental monitoring efforts and their status; presents potential radiation doses to staff and the public in the surrounding areas; and describes DOE-required data quality assurance methods used for data verification. The ASER report describes Compliance with Federal, State, and Local Laws and Regulations in 2023, Environmental Sustainability, Environmental monitoring and dose assessment, Natural and Cultural Resource Management, and Quality Assurance activities that took place during Calendar Year 2023.

40 CFR 61 Subpart H↗

RePOWERD: Restoration of Power Outage from Wide-area Severe Weather Disruptions

The purpose of the RePOWERD project is to develop a probabilistic and a simulation based power restoration forecasting model for tropical storms based on geographic utility service areas, impacts to energy infrastructures and transportation networks, time-varying customer outage number, crew information (i.e., crew size, crew staging requirements), and utility restoration plans. Energy infrastructure is a critical lifeline essential for the United States’ national and economic security. Like other critical infrastructures, this infrastructure is aging and is at a high risk of damages from extreme weather events. Based on the number of reported outages in EAGLE-I during 2020 and 2021, it is evident that the current energy infrastructure is not equipped to handle extreme event impacts and will contribute to significant outages. From a resilience perspective, it is essential to forecast restoration time in the event of a severe weather induced power outage to assist the US Department of Energy, emergency managers, and first responders with resource planning. This project contributes to this crucial need. This report details the models, that were developed in this pilot study, to determine the rate of restoration and estimated time of restoration (ETR) during tropical storm events within counties and utility service areas based on damage to energy infrastructures and total number of customers experiencing outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Datashare

Datashare facilitates communication and data sharing within local networks in potentially dangerous situations such as an explosive ordnance disposal. During such events, there is a need to transmit information rapidly around the incident area. It is a distributed database that does not require an internet connection for operation. In addition, Datashare interfaces with XTK and other software applications, allowing for seamless integration and data management. Datashare supports video calls over the network, enabling real-time communication among users. This software serves to organize, package, and share between responders on location and export data to those off location. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Eldridge, Bryce [Sandia National Lab. (SNL-CA), Li↗

Integrating Cybersecurity with System Operations and Restoration

This presentation covers the interaction of the discipline of system operations with the discipline of cybersecurity. First, a common mental model for risk - both cybersecurity and all-hazards - is presented, followed by a discussion of high-level management strategies for different kinds of cyber harm facing system operators, based on the consequences and frequencies of the harm. The next section covers the importance of cybersecurity for a system operator organization and explains some general concepts to understand the relationships. Finally the role of system operators in the security of the grid as a larger system of systems is discussed over the framework of a resilience event.

24 POWER TRANSMISSION AND DISTRIBUTION↗