Search NASA⌕ Search

SEARCH · Search NASA

Results for “threat”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Flexible and Generic Functional Mock-up Unit Based Threat Injection Framework for Grid-interactive Efficient Buildings: A Case Study in Modelica

Grid-interactive efficient buildings (GEBs) have been considered as an important asset to support the power grid reliability by utilizing the demand flexibility offered by GEBs. GEBs are enabled by advances in sensors and controls, and the communication between building equipment, whole buildings, and the grid. The integration of different building technologies and network-based communication system makes GEBs vulnerable to passive threats such as equipment failure and active threats such as cyber-attacks. Modeling and simulation is an effective way to evaluate the impact of threats on the system performance. This paper proposes a generic and flexible threat injection framework for commonly-used building energy simulators such as EnergyPlus and Modelica to support threat modeling and evaluation. This framework leverages functional mock-up unit (FMU) to develop a general modeling interface for threat injection and simulation. A numerical case study using Modelica as a building energy simulator is conducted to demonstrate the capability of the framework for supporting single/multiple-order threat modeling and simulation of a GEB. Four threats and their combinations are injected on a Modelica-based threat-free building energy and control system, including operating supply fan at its full speed, remotely cycling the chiller on and off, blocking the chiller from receiving the chilled water supply temperature setpoints, and hijacking the global zone air temperature setpoint. Simulation results show that the cyber-attack that leads to short-term signal blocking has small effects on the system operation due to the "self-healing" feature of the heating, ventilation, and air-conditioning (HVAC) interactive control system. The threat that takes control of resetting the global zone air temperature setpoints has the most adverse impact on the system energy use, peak power demand, thermal comfort and the provision of demand flexibility. The combination of four threats have aggregative effects on the system but the effects are less than the additive effects of the individual threat.

Fu, Yanyang↗

Performance Evaluation of Vertical Federated Machine Learning Against Adversarial Threats on Wide-Area Control System: Preprint

Federated machine learning (FL) is gaining significant popularity to develop cybersecurity solutions in power grids because of its advanced capability to support decentralized data handing at local devices, its privacy preservation, and its low-bandwidth requirement. However, the evolving adversarial machine learning (AML) threats raise significant concerns for the cybersecurity of FL architectures. The FL-based split neural network (SplitNN) achieves high performance through the decentralized training of local neural network models while preserving data privacy across multiple entities. In this paper, we propose a methodology for evaluating the performance of a vertical FLbased anomaly detector against different types of AML attacks, including denial-of-service attacks, adversarial data injection attacks, and replay attacks on the trained local models deployed in the grid network. For a case study, we consider the modified IEEE 13-bus system, and we develop SplitNN-based binary and multiclass classification models to detect, locate, and identify different types of data integrity attacks on the volt-watt control with two pooling layers: maximum pooling and AvgPool. Our experimental results, computed through performance metrics, reveal that the severity of these AML attacks varies with the integrated pooling mechanism, the type of classification model, and the nature of the cyberattack. Further, the AML attacks negatively impacted the prediction time per sample for the pretrained SplitNN during the online testing.

adversarial threats↗

NASA analysis of space mission options for the 2025 planetary defense conference hypothetical asteroid impact threat scenario

The 2025 Planetary Defense Conference (PDC) hypothetical asteroid impact threat exercise is being conducted in coordination with the United Nations-endorsed Space Mission Planning Advisory Group (SMPAG), exercising SMPAG's processes for assessing space mission options and communicating to decision makers. Here, in this paper, we describe the work performed by our NASA-led team and present the results we contributed to the SMPAG effort for the exercise. Our NASA-led team assessed mission options for asteroid reconnaissance (flyby and rendezvous), deflection, and robust disruption using several viable techniques: kinetic impactors, ion beam deflection, and nuclear explosive devices. Our simulations and analyses considered how much change-in-velocity an asteroid can tolerate before fragmentation onset, and we worked towards establishing requirements for robustly disrupting an asteroid. Heuristics informed by the simulation results are incorporated into optimization of deflection and disruption mission campaign options. Finally, we make some observations about useful generalizations from these results with potential applicability to any planetary defense scenario.

Asteroid deflection↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

GraphCH: A Deep Framework for Assessing Cyber-Human Aspects in Insider Threat Detection

Insider threat is one of the most damaging cyber attacks that could cause the loss of intellectual property and enterprise data security breaches. Action sequence data such as host logs are used to investigate such threats and develop anomaly-based AI detectors. However, insider threat actions are similar to legitimate user activities, causing AI detectors to fail and suffer from high false alarm rates. Therefore, user cyber activity logs are inadequate to fully unfold insider threats. In this study, we adopt human psychological principles of risk-taking and impulsiveness along with host data to assess the influence and usefulness of human behavioral aspects in insider threat detection. Here, we hypothesize that individuals' impulsive and risk-taking behavior correlates with cyberspace activities. To validate our hypothesis, we conducted an IRB-approved study recruiting 35 participants who work in a large U.S. university and collected their cyber and psychological data for 90 days. Host and human-behavioral data analysis and mapping indicate that impulsive and risk-taking users trigger more system errors causing (un)intentional insider threats and are susceptible to attackers' social engineering and cognitive hacking. Utilizing cyber-human aspects, we introduce a Cyber-Human Graph Neural Network (GNN) based framework GraphCH to identify abnormal user behaviors and detect insider threats.

97 MATHEMATICS AND COMPUTING↗

Domestic Extremism: Countering the Threat Posed to Critical Assets

Domestic extremism has been a growing concern in the United States in recent months, as illustrated in multiple bulletins from the Department of Homeland Security (DHS) warning law enforcement partners of the heightened threat. As concerns about these actors grows, it is important that facilities in the U.S. and internationally that protect critical assets, such as sensitive information, hazardous materials, or critical infrastructure, have effective methods in place to secure those assets. DE has challenged security systems through the threat of insider attack and violence, creating a new threat to be countered in the Office of Radiological Security’s radiological source security mission. In this effort, we used a literature review and focus group discussions with experts in critical asset security and extremism to understand the nature of the domestic extremist threat, to identify best practices in securing assets, recognize potential gaps in security measures to be corrected, and recommend actions and next steps. Twenty-two subject matter experts participated in a series of five focus group sessions. Questions focused on definitions of domestic extremism, potential changes in the threat, best practices in securing facilities, assets, and personnel, and any perceived gaps. Upon completion of the focus groups, notes were analyzed thematically to identify any recurring patterns in the results. In addition, a review of academic, industry, and government literature was conducted to understand the threat, describe the process of radicalization to extremism, and to identify empirically informed practices in prevention and response. Results of this project demonstrated that further work is needed to define domestic extremism in law, regulation, and policy, to help the U.S. develop a consistent response to the threat within organizations. This is especially important, as SMEs emphasized the need for early intervention in prevention efforts, noting that organizations need clear guidance on when and how to intervene. In addition, the need for social media monitoring was discussed, although challenges remain to do so with appropriate respect for privacy and civil liberties concerns.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Security Self-Assessment Toolkit for Nuclear Materials Facilities: Focus on Insider Threat Mitigation

Theft or sabotage of weapons-usable nuclear materials is a global concern. To minimize this threat, establishing and maintaining an effective nuclear security regime is required to protect against criminal or other negligent acts. Use of a formalized insider threat mitigation program is one such security measure. Individuals who have or held authorized access to an organization's critical assets, such as nuclear materials, are considered "insiders." Insider threats, or insider adversaries, are motivated individuals who possess access, authority, and knowledge to conduct a malicious act or facilitate that of an external party. To thwart insider threats (both intentional and unintentional), organizations can formalize an enterprise-wide approach to identify and mitigate the unique risks presented by insiders. This report provides an approach to evaluate an insider threat mitigation program at facilities with nuclear materials. Formal program evaluations serve many purposes and can be designed using several different methods and techniques. This report presents a self-assessment approach to program evaluation whereby an organization can assess its strengths, identify key gaps, and set priorities for ongoing improvement efforts to mitigate insider threats. Results of the self-assessment can provide critical information to contribute to the continuous improvement of an organization’s insider threat mitigation program within eight specific domain areas.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

MetaPoL: Immersive VR based Indoor Patterns of Life (PoL) and Anomalies Data Generation for Insider Threat Modeling in Nuclear Security

Insider threats are perhaps the most serious challenges that nuclear and radiological security systems face. Insiders pose such a great threat due to their access, authority, and knowledge, granting them opportunities to bypass dedicated nuclear and radiological security elements. For example, in one of the latest major insider threat incidents to nuclear security, the Doel-4 nuclear powerplant in Belgium suffered a shutdown, the threat of nuclear materials diversion, and long-term loss of tens of millions of dollars. Seven years of investigation concluded that it was an inside job and attempted sabotage. In this regard, there is an immediate need for R&D and technology integration in the domain of modeling indoor Patterns-of-Life (PoL) and anomaly detection. This can be achieved by using datasets of facility users’ mobility and activity, which can support the design of algorithms for insider threat modeling and detection. However, due to classification, privacy, sensitivity, and safety protocols, such datasets from real physical nuclear reactor facilities are not only hard to share, but also not always feasible to deploy and collect. Aiming to find an alternate solution, our proposed demonstration work - MetaPoL, is the first-ever (for the application space) immersive VR (virtual reality) environment of a real-world secure facility and allows users to move-and-stay through the designed indoor physical layout and also encounter NPCs (non-player characters) that emulate other facility users. In the MetaPoL an interactive user performs realistic spatio-temporal movement, dwelling and activities using a Meta Quest Pro VR headset, and that generates high-frequency (in time) high-resolution (in space) indoor spatial-temporal datasets that are valuable for PoL modeling and anomaly detection research specifically for insider threat modeling and detection mission. Such generated realistic, rich in context, and mission specific datasets can boost AI/Machine Learning based research for modeling and detecting insider threats in nuclear security and nonproliferation.

Gunaratne, Chathika↗

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Threat emulation framework

A method for emulating threats in virtual network computing environment is provided. The method comprises creating a number of virtual machines in the virtual network computing environment. A number of threat actors are emulated, wherein each threat actor comprises a number of threat artifacts that form a sequence of attack steps against the virtual network computing environment. The threat actors are then deployed against the virtual network computing environment. Behavioral data about actions of the threat actors in the virtual network computing environment is collected, as is performance data about the virtual network computing environment in response to the threat actors. The collected behavioral and performance data is then presented to a user via an interface.

Urias, Vincent↗

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Automated Generation of Graph-based Cyber Threat Intel

With the advancement of AI technology and tools, specifically in the cybersecurity domain, both cyber defenders and threat actors are continuously adapting the use of these capabilities to expedite their operations. With this phenomenon, threat intelligence that is up to date, refreshable, and has relevant context to a specific threat becomes more and more important as it enables cybersecurity professionals to gain insight into relevant data and relationships to guide their operations. This project enables users to frequently aggregate threat intelligence from various sources, such as vendor vulnerability advisories affecting critical infrastructure, malware reports, and adversary writeups into a centralized, standardized database. The project utilizes the Structured Threat Intelligence eXpression (STIX) for a standardized, shareable threat intelligence data format and Neo4j as a graph database solution to store STIX nodes and relationships. Initial results of the project include datasets of over 8,000 nodes and 20,000 relationships extracted from over 500 data sources that have been released within the past month.

Threat Intelligence↗

Cyber Threat Landscape for Distribution Systems

INL cyber analysts will present an overview of the current threat landscape for distribution systems. We will begin with examples of known attacks that have occurred recently to motivate the threat analysis and mitigation discussed in the remainder of the presentation. Examples may include the attacks affecting wind plants in Europe in Spring 2022, ransomware attacks on city utilities and commercial distribution systems, and advanced persistent threats (APTs) including the attacks on Ukrainian electric system in 2015 and 2016, as well as more recent evidence of other APT activity. We will present the end-to-end attack paths and discuss the various attacker skills, financing, motivations, and access that contributed to these attacks. In the second part of this presentation, we will discuss mitigating the cyber threats for distribution systems. We will discuss recent publicly disclosed vulnerabilities and explain their relevant context for distribution system security. Likely attacks to affect distribution systems, such as denial-of-service (DoS), ransomware, edge-device compromise, and advanced persistent threats (APTs) will be described. In addition to an overview of these kinds of attacks, we will provide examples of the various ways in which these attacks can start and what systems they can affect. Simple, cost-effective counter-measures to these attacks will be discussed and we will emphasize how these mitigations can reduce threats when properly applied and maintained.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Threat Dictionary Using MITRE ATT&CK Matrix and NIST Cybersecurity Framework Mapping

Cyber-attack and defense frameworks offer numerous ways to protect systems and networks from threats. However, only a few of these numerous attack and defense frameworks provide countermeasures by linking multiple frameworks. Due to the lack of attack-defense mapped frameworks, a number of cyber security practitioners are often puzzled how to cope with cyber-attacks when it occurs. The objective of this paper is to present a tool called the “Cyber Threat Dictionary” to solve the problem . Cyber Threat Dictionary offers approaches and practical solutions to the threats by mapping MITRE ATT&CK Matrix to the NIST Cybersecurity Framework. By providing immediate solutions to cyber security practitioners, Cyber Threat Dictionary enables effective responses against cyber-attacks.

MITRE ATT&CK MATRIX, NIST Cybersecurity Framework,↗

Analysing a multi‐stage cyber threat and its impact on the power system

Abstract Electric power systems are composed of physical and cyber sub‐systems. The sub‐systems depend on each other. If the cyber sub‐system is compromised by a cyber threat, what is the impact on the physical system? This paper presents a case study that shows the steps of a multi‐stage cyber threat involving a database injection attack, and what happens to the power system if this threat is not detected in its early stages. The threat first affects one utility but it can spread to the balancing authority, which is responsible for keeping the voltage and frequency stable in the power grid. During the cyber threat, the authors also show defence tools, such as a cyber‐physical data fusion tool that displays and analyses power and cyber telemetry.

Al Homoud, Leen [Texas A&amp,M University College ↗

The future of fungi: threats and opportunities

The fungal kingdom represents an extraordinary diversity of organisms with profound impacts across animal, plant, and ecosystem health. Fungi simultaneously support life, by forming beneficial symbioses with plants and producing life-saving medicines, and bring death, by causing devastating diseases in humans, plants, and animals. With climate change, increased antimicrobial resistance, global trade, environmental degradation, and novel viruses altering the impact of fungi on health and disease, developing new approaches is now more crucial than ever to combat the threats posed by fungi and to harness their extraordinary potential for applications in human health, food supply, and environmental remediation. To address this aim, the Canadian Institute for Advanced Research (CIFAR) and the Burroughs Wellcome Fund convened a workshop to unite leading experts on fungal biology from academia and industry to strategize innovative solutions to global challenges and fungal threats. This report provides recommendations to accelerate fungal research and highlights the major research advances and ideas discussed at the meeting pertaining to 5 major topics: (1) Connections between fungi and climate change and ways to avert climate catastrophe; (2) Fungal threats to humans and ways to mitigate them; (3) Fungal threats to agriculture and food security and approaches to ensure a robust global food supply; (4) Fungal threats to animals and approaches to avoid species collapse and extinction; and (5) Opportunities presented by the fungal kingdom, including novel medicines and enzymes.

59 BASIC BIOLOGICAL SCIENCES↗