Search NASASearch

SEARCH · Search NASA

Results for “Threat Hunting”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Field Insights: Strengthening Digital Assurance Through On-Site Network Monitoring

The accelerating deployment of digital energy infrastructure, ranging from inverter-based resources (IBRs), battery energy storage systems (BESS), to advanced grid control platforms, has brought unprecedented visibility, flexibility, and efficiency to the electric grid. However, this digital transformation also introduces new cybersecurity challenges, particularly in the form of supply chain risks and operational blind spots at the grid edge. Over the past year, the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through its Rapid Risk Assessment initiative, along with the Grid Deployment Office (GDO), through its Technical Assistance for Digital Assurance (TADA) initiative, have supported a series of on-site network engagements led by Idaho National Laboratory (INL). These engagements, conducted in partnership with asset owners across the country, have focused on identifying real-world vulnerabilities and misconfigurations in operational environments, many of which are not detectable through remote assessments or traditional compliance audits. The goal of this report is to distill key findings and lessons learned during network hunt engagements from INL’s fiscal year (FY) 2024 - 2025. It is intended to help asset owners—regardless of their participation in the program—better understand the evolving threat landscape and adopt practical measures to secure their digital energy infrastructure.

24 - POWER TRANSMISSION AND DISTRIBUTION

Quantifying CO 2 Plume Stabilization at Carbon Storage Projects, North Dakota, USA

This study presents an approach for quantifying when injected carbon dioxide (CO 2 ) stabilizes pursuant to carbon capture and storage (CCS) project permitting and site closure requirements. The distribution of mobile-phase CO 2 (CO 2 plume) will evolve within the storage reservoir during and after injection through both physical and chemical trapping mechanisms. CCS policies generally agree that the CO 2 plume’s migratory behavior in post-injection should demonstrate nonendangerment to the environment but do not provide specific guidance on how to meet the definition of plume stabilization, generating some uncertainty for operators. Plume stability herein means the CO 2 plume 1) changes size minimally and predictably in the storage reservoir such that it will not cross key boundaries identified in the permit and 2) does not pose a threat to human health, underground sources of drinking water (USDWs), and the environment because of lateral migration to areas where leakage pathways may exist. Published literature on plume metrics was reviewed to determine which metric(s) may be most appropriate for determining CO 2 plume stability. A technical approach that defines plume stabilization by estimating the rate of change in the geographic footprint of the CO 2 plume with respect to time was developed and illustrated using a case study from North Dakota, USA, as a proposed solution for CCS operators to apply at the project permitting stage. Any prospective CCS operator may benefit from using the same approach to inform the selection of pore space lease and monitoring areas and develop post-injection site care plans.

03 NATURAL GAS