Search NASA⌕ Search

SEARCH · Search NASA

Results for “cybersecurity recommendations”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Standardization and Recommendations for EVSE Cybersecurity Standards

Currently, there is an absence of cybersecurity certification programs specifically for EVSE. Many existing standards focus primarily on safety, such as battery safety, while others provide cybersecu rity guidelines for different types of equipment, which could be adapted for EVSE. Among these, ISA/IEC 62443 has been identified as highly aligned with EVSE security needs. This report is a follow on to the previous research published (“Assessment and Coordination of EVSE Cybersecurity Standards,”). This report aims to find appropriate strategies for closing the gaps found in the aforementioned report and continue to work towards a comprehensive cybersecurity certification program for EVSE. Future testing will leverage this standard to assess EVSE security gaps and strengths, providing valuable insights to support certification development and harmonization of cybersecurity standards.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cybersecurity Lessons Learned from Vehicle to Grid Engagement

As the transportation industry continues to become electrified, introduction of additional digital devices within associated actions such as recharging bring additional potential for cybersecurity attacks. Devices that are designed, implemented, and operated with cybersecurity as a crucial consideration exacerbate these concerns by failing to provide strict boundaries on access to and use of the equipment. Emerging use cases such as Vehicle to Grid (V2G) charging may expand the potential physical effects of a cybersecurity attack by providing indirect access to electrical components of a building microgrid or portions of the larger power grid. This paper serves as an overview of findings and recommendations based on cybersecurity testing performed at a V2G implementation site operated by a member of the Memorandum of Understanding (MOU) to Establish the Vehicle-to-Everything (V2X) Collaboration [1]. The Department of Energy Office of Cybersecurity, Energy Security, and Emergency Response is a signatory of the MOU, and has funded this research paper and associated body of work regarding V2X cybersecurity. Sandia has a large background of previous research focused on Electric Vehicle (EV) cybersecurity, such as reference [2], which includes an overall survey of EV infrastructure cybersecurity and recommendations based on those findings. This report seeks to expand knowledge of EV cybersecurity status and needs by focusing on a specific implementation of V2G charging, and providing recommendations based on the relevant findings. This report serves as a publicly available, sanitized description of applied vulnerability testing on an operational V2G implementation. A more in-depth technical version of the report is provided to the MOU partner, but not available at the time of writing due to inclusion of proprietary information. V2G charging comes with many research problems that must be solved before the technology can securely implemented in sites with unrestricted public access or where cybersecurity attacks could have increased consequences, such as government offices. V2G charging requires many stakeholders such as end users, host sites, equipment vendors, and integrators, which all rely on operational safety and security as well as security and trustworthiness of any associated financial transactions.

33 ADVANCED PROPULSION SYSTEMS↗

Securing Solar for the Grid (S2G) (Final Project Report) [Slides]

This is the final technical report for the SETO-funded project Securing Solar for the Grid (S2G) from FY22-24. The project scope included development and dissemination of standards' requirements, best practices, equipment testing procedures, assessment tools, as well as education and training materials for cyber defense, posture and maturity tailored to solar technologies. The outcomes for this work include: co-led the development of cybersecurity certification standard (UL2941), co-led the development of cybersecurity guide (IEEE1547.3), development of recommendations for supply chain cybersecurity, and development of cybersecurity risk profiles and recommendations for DERMS.

14 SOLAR ENERGY↗

ChatGPT and Other Large Language Models for Cybersecurity of Smart Grid Applications

Cybersecurity breaches targeting electrical substations constitute a significant threat to the integrity of the power grid, necessitating comprehensive defense and mitigation strategies. Any anomaly in information and communication technology (ICT) should be detected for secure communications between devices in digital substations. This paper proposes large language models (LLMs), e.g., ChatGPT, for the cybersecurity of IEC 61850-based communications. Multi-cast messages such as generic object oriented system events (GOOSE) and sampled values (SV) are used for case studies. The proposed LLM-based cybersecurity framework includes, for the first time, data pre-processing of communication systems and human-in-the-loop (HITL) training (considering the cybersecurity guidelines recommended by humans). The results show a comparative analysis of detected anomaly data carried out based on the performance evaluation metrics for different LLMs. A hardware-in-the-loop (HIL) testbed is used to generate and extract a dataset of IEC 61850 communications.

ChatGPT↗

DER Cybersecurity Standards: Assessment and Gap Analysis

The purpose of this report is to share the comprehensive gap analysis of existing cybersecurity standards applicable to Distributed Energy Resources (DERs) within the electric power sector. This analysis aims to identify critical deficiencies in current standards, assess their alignment with industry needs, and provide actionable recommendations for enhancing cybersecurity measures. The scope encompasses various DER technologies, including solar, wind, energy storage, and hydrogen fuel cells, and emphasizes the significance of establishing robust cybersecurity frameworks and standards to safeguard these increasingly integrated systems. The report provides valuable insights for stakeholders in the DER ecosystem, including manufacturers, utilities, and regulators. It underscores the importance of continued development and refinement of cybersecurity standards to keep up with the technical advances in DERs and associated cybersecurity challenges. The analysis evaluated IEC, IEEE, ISA, ISO, and UL standards relevant to DER cybersecurity. Standards were assessed on their coverage of key requirements including data availability, integrity, confidentiality, access control, authentication, encryption, and system hardening. For each standard, the analysis assessed its alignment with current industry practices, regulatory compliance, effectiveness in addressing known risks, coverage of emerging risks, and how it promotes interoperability. The evaluation also considered potential integration challenges and barriers to adoption.

97 MATHEMATICS AND COMPUTING↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Verification and Validation of Performance with Dissemination of Best Practices in District Energy and CHP for Enhanced Resiliency, Energy Efficiency, and Cybersecurity

This report contains the results of the International District Energy Association’s work to analyze, validate, and verify performance data of existing district energy systems and identify industy best practices for the purpose of improving system reliability, resiliency, and efficiency, and to accellerate decarbonization. In addition to a technical evaluation of the surveyed systems and identification of a series of technical performance metrics, the report illustrates the accompanying operations and financial best practices employed by surveyed systems to fully serve their customer base. Additionally, the third chapter of the report describes the current landscape of cybersecurity threats and counteracting measures, and recommends a series of steps for effectively guarding highly networked district energy systems against cybersecurity attacks.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

The Cybersecurity Value-at-Risk Framework: Informing Cybersecurity Decisions

The Cybersecurity Value-at-Risk Framework is a tool that can be used by hydropower plant manager to make more educated cybersecurity investments. Users can take a self guided assessment allowing the tools to generate risk, impact and cybersecurity scores and be given risk-based recommendations to enhance decision-making.

CVF↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in Urban Air Mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex components has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens safety and the efficiency of transportation networks.In response to these challenges, this paper presents a study on the need for cyber resilient techniques within future air traffic environments. It will pay specific attention to the implementation of a Host-Based Intrusion Detection System (HIDS) utilizing Atomic OSSEC software, tailored specifically to a NASA simulation of an UrbanAirMobility environments’ unique demands. Further, this study seeks to outline the rational for NASA’s recommendation for a HIDS in such environments. It explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the Urban Air Mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organizations overall cybersecurity posture. Finally, this study aims to provide recommendations and include learned takeaways that the Urban Air Mobility industry should consider. In brief, this paper highlights the significance of host-based intrusion detection in UrbanAirMobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM↗

Equipment Assessment Guide: A Technical Inspection and Hardening Guide for Devices in Power Grid Operations

This Equipment Assessment Guide, developed by Idaho National Laboratory (INL), provides a comprehensive framework designed to enhance the security of operational technology (OT) devices within power grid operations. The guide outlines essential steps for asset owners to conduct technical inspections and harden vulnerable hardware and firmware components commonly found in embedded systems. It focuses on components frequently targeted by cyber threats, offering valuable identification techniques for locating and recognizing critical components on devices. Additionally, the guide presents recommended secure configurations aimed at minimizing exposure and reinforcing defenses, along with impact analysis that highlights the potential consequences for grid operations if components are compromised. By implementing the recommendations outlined in this guide, asset owners can significantly enhance their cybersecurity posture, reduce the attack surface of field-deployed devices, and improve the resilience of grid services against emerging cyber threats.

42 - ENGINEERING↗

Test & Measurement System Security in an IT World

Automated test and measurement systems are coming under increased cybersecurity scrutiny. Most of these systems fall under the “Operational Technology” designation, as defined by NIST, and often have unique requirements that conflict with enterprise security policy. These systems are typically not well understood by traditional enterprise IT personnel, which leaves them ill-supported or invalidated.▪This presentation attempts to help Test System owners recognize the security landscape, determine their unique system requirements and concerns, and negotiate a peer-level working arrangement with an existing IT department while maintaining a NIST-recommended level of autonomy and sovereignty.

automated test↗

Evaluation of IEC 62443 Standard Gaps for Electric Grid Substation Model Use Case

This report presents an evaluation of the IEC 62443 standards in the context of electric grid substations, as part of a collaborative effort among Sandia National Laboratories (SNL), Idaho National Laboratory (INL), and the National Renewable Energy Laboratory (NREL). The primary objective is to assess the applicability of these standards to enhance cybersecurity measures for industrial automation and control systems (IACS) within the energy sector. The evaluation identifies strengths, such as the scalability of security levels and the structured lifecycle guidance provided by IEC 62443. However, it also highlights significant gaps, including limited integration of physical security, insufficient guidance for legacy systems, and challenges in addressing emerging threats like supply chain vulnerabilities. Recommendations for refining the standards are proposed, including the need for tailored guidance for securing legacy systems, integrating physical security with cybersecurity frameworks, and enhancing interoperability across multi-vendor environments. By addressing these gaps, the IEC 62443 standards can be strengthened to ensure comprehensive cybersecurity for electric grid substations, thereby supporting the resilience and reliability of critical energy infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Building Nuclear-Specific Cybersecurity Expertise in Higher Education

The rapid digitalization of nuclear power plants (NPPs) and the deployment of advanced and small modular reactors (A/SMRs) have expanded the cybersecurity attack surface within the nuclear sector. This evolution introduces unique challenges beyond those faced in general information technology (IT), operational technology (OT) and industrial control system (ICS) security, due to nuclear power’s regulatory rigor, safety-critical nature, and operational needs. A pressing workforce gap persists; cybersecurity graduates typically lack nuclear-specific context and retraining them for industry readiness requires 12–18 months, creating a significant burden. This paper addresses this gap by defining the domains of knowledge that nuclear cybersecurity specialists must master, spanning cybersecurity, nuclear engineering, OT/ICS security, and regulatory governance. We propose a curricular framework integrating technical, regulatory, and applied learning components to accelerate workforce readiness. Our approach builds on existing findings that current curricula inadequately integrate nuclear engineering and cybersecurity, shifting the discourse from why specialization is needed to what knowledge must be taught. The recommendations have implications for workforce development and long-term resilience of the nuclear energy sector.

99 - GENERAL AND MISCELLANEOUS↗

NASA’s Secured Airspace for Urban Air Mobility (UAM)

The Urban Air Mobility (UAM) architecture is leveraged from the Unmanned Traffic Management (UTM) concept of operations. Within the UAM environment, UAM operators work collaboratively to manage aerial vehicles in the urban environment. Providers of Services for UAM (PSU), UAM operators, and Supplemental Data Service Providers (SDSP) provide services to support flight operations within that environment. As a recognized need, various views of UAM flight information are provided to the public and public safety entities. To accomplish this, among other goals, the Federal Aviation Administration (FAA) can coordinate flight information between the FAA controlled National Airspace System (NAS) and the UAM environments through the FAA-Industry Data Exchange Protocol (FIDXP). This concept of UAM proposes to develop short-range, point-to-point transportation systems in metropolitan areas using vertical take-off and landing (VTOL) or short take-off and landing (STOL) aircraft to overcome increasing surface congestion. To garner the support of UAM and to realize its potential, an assurance of cybersecurity is critical for public acceptance. Understanding the various components communicating with one-another cybersecurity, like in other industries, has come to the forefront highlighting the need to protect these networks and systems from cyberattacks. With the planned growth and reach of UAM systems, it’s clear that the associated data exchange and service interactions will be at risk due to numerous types of cybersecurity attacks. Consequently, as these threats evolve, the UAM cybersecurity capabilities must adapt to these changes as well. While learning is always the goal, the overall intent of this workshop is to make recommendations on the following: (1) how future UAM environments can be protected against cyber-attacks, and (2) what mechanisms should be put in place to detect attacks against UAM environments.

UAM↗

Cyber-Informed Engineering (CIE) Benefits Quantification: Recommendations for Consideration

Cyber-Informed Engineering (CIE) integrates engineering principles into the design, development, and operation of cyber-physical systems (CPS) to mitigate or eliminate the impact of cyber-enabled attacks. In July 2024, Idaho National Laboratory (INL) engaged MITRE researchers to investigate methods for systematically measuring the benefits of CIE implementation. This included evaluating the success and outcomes of CIE, identifying and quantifying the value of early adoption, and determining the business justification for its implementation, especially in existing infrastructure. MITRE reviewed existing methods in engineering and cybersecurity to understand how organizations prioritize security investments, considering their strengths, weaknesses, and relevance to CIE stakeholders. Based on this analysis, MITRE proposed potential approaches for quantifying CIE benefits and provided recommendations for INL's consideration.

42 ENGINEERING↗

Cyber-Attack Methods, Why They Work on Us, and What to Do

Basic cyber-attack methods are well documented, and even automated with user-friendly GUIs (Graphical User Interfaces). Entire suites of attack tools are legal, conveniently packaged, and freely downloadable to anyone; more polished versions are sold with vendor support. Our team ran some of these against a selected set of projects within our organization to understand what the attacks do so that we can design and validate defenses against them. Some existing defenses were effective against the attacks, some less so. On average, every machine had twelve easily identifiable vulnerabilities, two of them "critical". Roughly 5% of passwords in use were easily crack-able. We identified a clear set of recommendations for each project, and some common patterns that emerged among them all.

cybersecurity↗