Design of Defensive Cyber Security Architectures Using Event Trees
Explore the source record for details and available documents.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
This presentation provides and overview of the Federated Architecture for Secure and Transactive Distributed Energy Resource Management Solutions (FAST-DERMS) project and progress to date as of December 2024.
Deployment and capability of distributed energy resources (DER) in power systems is growing rapidly. These resources present an opportunity for low-cost provision of energy and grid services. The Federal Energy Regulatory Commission recently provided rulings to enable market participation of these distribution-connected resources, but the prevailing strategies for their management may not scale well to meet future needs. This paper introduces the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FASTDERMS) which was designed to address this need. In it we describe the architectural features of the approach, and a reference controls implementation employing a hierarchical coordination that includes stochastic optimization, model predictive control, and a simple real-time management scheme. Sample results from simulation show firm transmission-level service provision measured at the distribution substation.
Deployment and capability of distributed energy resources (DER) in power systems is growing rapidly. These resources present an opportunity for low-cost provision of energy and grid services. The Federal Energy Regulatory Commission recently provided rulings to enable market participation of these distribution-connected resources, but the prevailing strategies for their management may not scale well to meet future needs. This paper introduces the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FAST-DERMS) which was designed to address this need. In it we describe the architectural features of the approach, and a reference controls implementation employing a hierarchical coordination that includes stochastic optimization, model predictive control, and a simple real-time management scheme. Sample results from simulation show firm transmission-level service provision measured at the distribution substation.
The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.
The Broadband Automation for Distributed Grid Efficiency and Resilience (BADGER) project aligns with national strategic priorities for integrating emerging wireless technologies and advancing AI-driven security. As critical infrastructure modernizes toward increasingly software-defined and interconnected systems, the ability to leverage 5G/NextG networks and AI-enabled control becomes essential. This report outlines work at the National Laboratory of the Rockies (NLR) to develop a NextG-native security architecture powered by AI-RAN concepts and evaluate workflows that enable efficient and reliable architectures. Together, these efforts position the laboratory to accelerate innovation while directly supporting national security and resilience objectives.
This study presents a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture aimed at detecting and mitigating compromised Human Machine Interface (HMI) and Instrumentation & Control (I&C) systems within the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). The approach combines network security solutions, hash-based algorithms, and blockchain technologies to verify system integrity and provide an immutable record of network activity. This integrated three-pronged strategy enhances the detection of system compromises, enabling preemptive action before significant damage occurs.
This study focuses on a multi-layered Industrial Control System (ICS)/Operational Technology (OT) security architecture to aid in the discovery and mitigation of compromised Human Machine Interface (HMI)/Instrumentation & Control (I&C) based systems for modifying a prototypical reactor condition test facility called the Flowing Autoclave System (FAS) at Idaho National Laboratory (INL). This is achieved through a three-layered combination of network security solutions, hash-based algorithms, and blockchain technologies. Hash algorithms are mathematical functions used to generate a predetermined set of fixed-length values. They are widely used in computer security to verify the integrity of system information and data, both on a local network and the wider internet. Even small amounts of unauthorized system modification will cause the hash algorithm to output a set of characters that deviate significantly from its original value. Assisting secure hash functions, blockchain technology is a secure and distributed technology used to provide an immutable set of records replicated on all devices within a decentralized network. Blockchain offers a cost-effective solution to detect system compromise by providing a traceable breadcrumb trail of all network activity and data modification happening on a system. If both are used in conjunction with network monitoring tools, the integration of this three-pronged approach can become an asset in detecting suspected system compromises before any real damage can occur.
The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator’s control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility—attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications
The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator's control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications.
SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.
The evolving landscape of scientific computing requires seamless transitions from experimental to production HPC environments for interactive workflows. This paper presents a structured transition pathway developed at OLCF that bridges the gap between development testbeds and production systems. We address both technological and policy challenges, introducing frameworks for data streaming architectures, secure service interfaces, and adaptive resource scheduling for time-sensitive workloads and improved HPC interactivity. Our approach transforms traditional batch-oriented HPC into a more dynamic ecosystem capable of supporting modern scientific workflows that require near real-time data analysis, experimental steering, and cross-facility integration.
This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.
The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.
Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.