Search NASA⌕ Search

SEARCH · Search NASA

Results for “TTPs”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

SeqMask: Behavior Extraction Over Cyber Threat Intelligence Via Multi-Instance Learning

Abstract Identification and extraction of Tactics, Techniques and Procedures (TTPs) for Cyber Threat Intelligence (CTI) restore the full picture of cyber attacks and guide the analysts to assess the system risk. Existing frameworks can hardly provide uniform and complete processing mechanisms for TTPs information extraction without adequate knowledge background. A multi-instance learning approach named SeqMask is proposed in this paper as a solution. SeqMask extracts behavior keywords from CTI evaluated by the semantic impact, and predicts TTPs labels by conditional probabilities. Still, the framework has two mechanisms to determine the validity of keywords. One using expert experience verification. The other verifies the distortion of the classification effect by blocking existing keywords. In the experiments, SeqMask reached 86.07% and 73.99% in F1 scores for TTPs classifications. For the top 20% of keywords, the expert approval rating is 92.20%, where the average repetition of keywords whose scores between 100% and 90% is 60.02%. Particularly, when the top 65% of the keywords were blocked, the F1 decreased to about 50%; when removing the top 50%, the F1 was under 31%. Further, we also validate the possibility of extracting TTPs from full-size CTI and malware whose F1 are improved by 2.16% and 0.81%.

Ge, Wenhan↗

Coal Fired Power Plant Configuration and Operation Impact on Plant Effluent Contaminants and Conditions

The primary objective of this project is to characterize coal contaminants in coal-fired power plant wastewater as a function of coal type, unit configurations, and unit operation profile with uncertainty analysis. This project was in response to the U.S. Department of Energy (DOE) Solicitation DE-FOA-0001842. The project duration was between September 01, 2018, and December 31, 2021 (no-cost extension filed, due to the Covid-19 pandemic restrictions, and approved). Field and lab test program was conducted with the main goal to characterize coal contaminants in coal-fired power plant wastewater as a function of coal type, unit configurations, and unit operation profile with uncertainty analysis. In this project, the team of Lehigh University (prime recipient) and Western Kentucky University identified two suitable Thermoelectric Power Plants (TTPs) firing bituminous and sub-bituminous coals respectively, designed test plans, and performed sample collection. Sampling included coal from each TTPs power generation units, Wet Flue Gas Desulfurization (WFGD) slurry material and waste-water samples taken from the outlet of the water treatment tank prior to discharge and other pertinent locations. Coal samples are dried, crushed, and pulverized according to the American Society for Testing and Materials (ASTM) methods. The prepared coal samples are analyzed for normal proximate and ultimate analysis tests in addition to the toxic metals and anions according to ASTM methods. The FGD slurry materials are analyzed for toxic metals and anions according to Electric Power Research Institute (EPRI) or Environmental Protection Agency (EPA) methods, as appropriate. The wastewater samples from the water treatment tank outlet are analyzed for toxic metals and anions according to EPA methods. The effluent species analyzed include mercury, arsenic, selenium, nitrate/nitrite, bromide, and chlorine. This project provided results of effluent conditions as a function of coal type, unit configuration, and unit operation profile, and identified the levels of uncertainty in the effluent results.

01 COAL, LIGNITE, AND PEAT↗

HP in Cybersecurity: CyOTE

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through the Cybersecurity for the Operational Technology Environment (CyOTE) Program, worked with energy sector asset owners and operators (AOOs), partners, and Idaho National Laboratory (INL) to develop capabilities for AOOs to independently detect adversarial tactics, techniques, and procedures (TTPs) within their operational technology (OT) environments. Unlike the approach taken with commercial security solutions, CyOTE seeks to tie anomalies in cyber operations to a cyber-attack. By stringing together multiple techniques in the OT environment, AOOs can identify attack campaigns with ever decreasing impacts. The CyOTE methodology applies fundamental concepts of perception and comprehension to a universe of knowns and unknowns increasingly disaggregated into observables, anomalies, and triggering events. MITRE’s ATT&CK® Framework for Industrial Control Systems (ICS) is used as a common lexicon to identify a set of triggering events related to three Use Cases – Alarm Logs, Human-Machine Interface (HMI), and Remote Logins – which together account for 87 percent of the techniques commonly used by adversaries. The CyOTE methodology is also appropriate for OT-related anomalies perceived outside the three Use Cases, such as through the energy system itself.

99 GENERAL AND MISCELLANEOUS↗

Design Considerations for Distributed Energy Resource Honeypots and Canaries

There are now over 2.5 million Distributed Energy Resource (DER) installations connected to the U.S. power system. These installations represent a major portion of American electricity critical infrastructure and a cyberattack on these assets in aggregate would significantly affect grid operations. Virtualized Operational Technology (OT) equipment has been shown to provide practitioners with situational awareness and better understanding of adversary tactics, techniques, and procedures (TTPs). Deploying synthetic DER devices as honeypots and canaries would open new avenues of operational defense, threat intelligence gathering, and empower DER owners and operators with new cyber-defense mechanisms against the growing intensity and sophistication of cyberattacks on OT systems. Well-designed DER canary field deployments would deceive adversaries and provide early-warning notifications of adversary presence and malicious activities on OT networks. In this report, we present progress to design a high-fidelity DER honeypot/canary prototype in a late-start Laboratory Directed Research and Development (LDRD) project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating China's Road to Cyber Super Power

This report examines open source, non-classified qualitative analysis to evaluate China’s current cyber maturity. Evidence for this document draws on materials from academia, private cybersecurity companies, and national security research institutions. Private sector threat intelligence firms produce high quality analysis on Chinese APTs tactics, techniques, and procedures (TTPs), and investigation from companies such as FireEye illuminate China’s ability to wield cyber means for its security ends. None of the materials cited in this assessment originate from classified United States or foreign government sources. Any references to United States government sources are sourced entirely to unclassified information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Requirements and Recommendations for a Physical Attack Characterization Framework

This study seeks to identify existing frameworks or develop requirements and recommendations for a new framework that can consistently characterize physical attacks, analogous to MITRE ATT&CK®. MITRE ATT&CK is widely used across government, research organizations, and the cyber security community to characterize cyber attack tactics, techniques, and procedures (TTPs) in a consistent and commonly understood manner. While physical attack taxonomies, methodologies, and other tools for evaluating physical security do exist, many are sector and/or facility-type specific—and therefore not able to provide comparable scenarios across sectors—or are more focused on security assessment instead of the characterization of attacks themselves. A MITRE ATT&CK analog for physical attacks on critical infrastructure would provide a common language and structure for analysis of physical attacks. Existing attack characterization methodologies do not robustly address cyber-physical security risks. To fully understand a facility’s security needs, it is important to understand the entire vulnerability landscape from both a physical and a cyber perspective. To underscore this need, organizations such as the Cybersecurity and Infrastructure Security Agency (CISA) are calling for a coordinated approach to cyber and physical security, which they refer to as cyber and physical security convergence. A physical attack characterization framework that could be used jointly with MITRE ATT&CK would help support a more robust analysis in support of convergence, enabling the consistent characterization of attacks that utilize both cyber and physical tactics and techniques. This could provide analysts and stakeholders with a clearer understanding of how security mitigations deployed in the physical realm impact security risks in the cyber realm, and vice versa. In this study, the project team evaluates existing physical security taxonomies and methodologies to assess whether an existing method can be used to create a “physical half” of MITRE ATT&CK. This study then provides requirements and recommendations for a framework that can leverage aspects of existing methodologies. The goal of the final framework is for it to be widely adopted and referenced, regardless of critical infrastructure sector, facility type, or facility components. This study also identifies applicable use cases for when and how a framework could be applied across the various critical infrastructure sectors for a variety of attack types or motivations. Through a literature review of existing security-focused methodologies and taxonomies, engagement with relative stakeholders, evaluation of potential physical attack framework use cases, and subsequent identification of requirements, this study identified the following key findings and recommendations: There is a need for a new physical attack characterization framework; A physical attack framework should be interoperable with the MITRE ATT&CK framework; A physical attack framework should be broadly applicable, but with detailed tactics, techniques, and procedures that encompass the entire attack path; A physical attack framework should be based on observed or feasible events; A physical attack framework should adapt features from existing methodologies, frameworks, and taxonomies; A physical attack framework should be owned, overseen, and maintained by one organization.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Emergent Capabilities Converging into M and S 2.0

The continued operational environment complexity faced by the Department of Defense, despite a restricted resource environment, is a mandate for greater adaptability and availability in joint training. To address these constraints, this paper proposes a model for the potential integration of adaptability training, virtual world capabilities and immersive training into the wider Joint Live Virtual and Constructive (JLVC) Federation, supported by human, social, cultural and behavior modeling, and measurement and assessment. By fusing those capabilities and modeling and simulation enhancements into the JLVC federation, it will create a force who is more apt to arrive at and implement correct decisions, and more able to appropriately seize initiative in the field. The model would allow for the testing and training of capabilities and TTPs that cannot be reasonably explored to their logical conclusions in a 'live' environment, as well as enhance training fidelity for all echelons and tasks.

Reitz, Emilie↗

CyOTE ASSET OWNER ENGAGEMENT – SIDE CHANNEL POWER ANALYSIS PROTOTYPE

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through the Cybersecurity for the Operational Technology Environment (CyOTE) Program, worked with energy sector asset owners and operators (AOOs), partners, and Idaho National Laboratory (INL) to develop capabilities for AOOs to independently identify adversarial tactics, techniques, and procedures (TTPs) within their operational technology (OT) environments. The CyOTE methodology seeks to identify adversarial techniques within an AOO OT environment that could result in physical disruptions to energy flow or damage to equipment. CyOTE provides a general roadmap for AOOs, starting from a triggering event, or the point in time and space they perceive an anomalous event or condition meriting investigation, and culminating when the AOO has sufficient confidence to make a business risk decision on the appropriate resolution. This paper outlines the results of one such engagement with the New York Power Authority (NYPA), where the CyOTE program partnered with an AOO to develop a design specification for a power side channel detector to identify anomalous changes to device load. It describes the goal of developing this capability, the development process, the challenges the technical teams faced and the future steps an AOO will need to take to install and use this detector in its OT environment.

99 GENERAL AND MISCELLANEOUS↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗