Search NASA⌕ Search

SEARCH · Search NASA

Results for “threat profile”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

FIC Threat Profile: Provided by Shamrock Cyber

The FIC team has engaged with PNNL’s Shamrock Cyber Team to produce this Threat Profile. The Threat Profile provides the foundation for a thorough understanding of threats for development teams and stakeholders, and users of the system. The Threat Profile can be used as is, or as content to inform other reports tailored to a specific audience. It is intended to enable decision makers at all levels to improve the security posture of the system.

97 MATHEMATICS AND COMPUTING↗

A Cybersecurity Threat Profile for a Connected Lighting System

In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.

97 MATHEMATICS AND COMPUTING↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Oak Ridge National Laboratory Security by Design: A Plant Design and Component-Based Approach to Technical Solutions to Insider and Outsider Threat

Security costs for nuclear reactors have been shown to rise over the lifecycle of a nuclear facility as new threats, security weaknesses, and the generic threat profile of the plant location change over time. This paper conducts a review of the technological gaps that currently exist in Security by Design (SeBD) based on the literature available and attempts to close those gaps through proposing technological constructs and processes that can integrate safety and security in the design process of a plant, with a primary focus on SMR technology. Under the new modular and mass manufacturing regime, where plant designs attempt to reduce costs with potential economies of scale and modular construction, the current SeBD definitions focusing on state level regulators are not considered adequate since the licensing stage is often too late in the design process to integrate the true cost savings of SeBD. Thus, this paper attempts to remedy the current logic in order to allow for continuous implementation of security alongside the development of the safety concept for the plant. If adopted within the design process the establishment of this type of technology will allow for a technological ecosystem to evolve that will imbed security concepts into the physical design of the components of the plant.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Assessing the Threat: Weaving Cybersecurity into the Building Development Process

Today’s connected lighting systems have the potential to reduce energy consumption and operational costs via the use of the data they collect and share with other building systems (e.g., HVAC, building automation, security). However, many market available products are new to being networked, and when networked components in lighting and other building systems are not sufficiently secured, they present opportunities for criminals to exploit. Further, security vulnerabilities in one system can be used as lateral steppingstones that allow access to other prized assets on the same network. These cybersecurity concerns could deter the adoption and use of connected systems, which then could jeopardize long-term national objectives for reduced energy usage. The workflows described here and presented in more detail in the referenced reports are examples of how these frameworks and tools can be put to practical use during system design and specification.

attack surface, Building development, threat analy↗

Recommendations for Secure Transport: Material Conveyance Physical Protection Technology

Nuclear material is at higher risk of theft and sabotage during transport than during any other phase of the nuclear fuel lifecycle. Nuclear materials are transported in the public domain where adversaries have an upper hand by taking advantage of the time and location of the theft or sabotage attempt. As such, even modest threat profiles for transport of nuclear and radioactive material can require substantial detection and delay measures to support timely response. Conveyance tracking augmented with technology that improves on-the-scene situational awareness at a remote monitoring center has been adopted as a de-facto standard approach for transportation security. At present, the extended tracking and situational awareness capabilities needed for a nuclear material shipment, as is provided by the purpose designed, Transportation – Security, Tracking and Reporting (T-STAR) System, do not exist in a single commercial off-the-shelf (COTS) solution. Typically, the COTS systems that excel in one area are deficient in other areas, presenting challenges to designing well-rounded, robust systems. Still, COTS solutions can offer the basic set of tracking and situational awareness capabilities by indicating last update time, current location, and route taken. By incorporating vehicle and driver performance measures via the vehicle’s controller area network (CAN bus) and video alongside other data streams allows telemetry and other shipment information to be assessed in novel ways.This paper describes the operation, capabilities and features of various conveyance protection systems and approaches, assesses emerging technologies and how they could be used through a unified interface, and enumerates additional ways to provide early detection using vehicle, onboard technologies, effective delay technologies and approaches and simple equipment to improve protection during transport.

Shannon, Michael↗

Disease resistance in coral is mediated by distinct adaptive and plastic gene expression profiles

Infectious diseases are an increasing threat to coral reefs, resulting in altered community structure and hindering the functional contributions of disease-susceptible species. We exposed seven reef-building coral species from the Caribbean to white plague disease and determined processes involved in (i) lesion progression, (ii) within-species gene expression plasticity, and (iii) expression-level adaptation among species that lead to differences in disease risk. Gene expression networks enriched in immune genes and cytoskeletal arrangement processes were correlated to lesion progression rates. Whether or not a coral developed a lesion was mediated by plasticity in genes involved in extracellular matrix maintenance, autophagy, and apoptosis, while resistant coral species had constitutively higher expression of intracellular protein trafficking. This study offers insight into the process involved in lesion progression and within- and between-species dynamics that lead to differences in disease risk that is evident on current Caribbean reefs.

59 BASIC BIOLOGICAL SCIENCES↗

Users Guide for the Anvil Threat Corridor Forecast Tool V1.7.0 for AWIPS

The Applied Meteorology Unit (AMU) originally developed the Anvil Threat Sector Tool for the Meteorological Interactive Data Display System (MIDDS) and delivered the capability in three phases beginning with a feasibility study in 2000 and delivering the operational final product in December 2003. This tool is currently used operationally by the 45th Weather Squadron (45 WS) Launch Weather Officers (LWO) and Spaceflight Meteorology Group (SMG) forecasters. Phase I of the task established the technical feasibility of developing an objective, observations-based tool for short-range anvil forecasting. The AMU was subsequently tasked to develop short-term anvil forecasting tools to improve predictions of the threat of triggered lightning to space launch and landing vehicles. Under the Phase II effort, the AMU developed a nowcasting anvil threat sector tool, which provided the user with a threat sector based on the most current radiosonde upper wind data from a co-located or upstream station. The Phase II Anvil Threat Sector Tool computes the average wind speed and direction in the layer between 300 and 150 mb from the latest radiosonde for a user-designated station. The following threat sector properties are consistent with the propagation and lifetime characteristics of thunderstorm anvil clouds observed over Florida and its coastal waters (Short et al. 2002): a) 20 n mi standoff circle, b) 30 degree sector width, c) Orientation given by 300 to 150 mb average wind direction, d) 1-, 2-, and 3- hour arcs in upwind direction, and e) Arc distances given by 300 to 150 mb average wind speed. Figure 1 is an example of the MIDDS Anvil Threat Sector tool overlaid on a visible satellite image at 2132 UTC 13 May 2001. Space Launch Complex 39A was selected as the center point and the Anvil Threat Sector was determined from upper-level wind data at 1500 UTC in the preconvective environment. Narrow thunderstorm anvil clouds extend from central Florida to the space launch and landing facilities at the Kennedy Space Center (KSC) and Cape Canaveral Air Force Station (CCAFS) and beyond. The anvil clouds were generated around 1930 UTC (1430 EDT) by thunderstorm activity over central Florida and transported 90 n mi east-northeastward within 2 hours, as diagnosed by the anvil forecast tool. Phase III, delivered in February 2003, built upon the results of Phase II by enhancing the Anvil Threat Sector Tool with the capability to use national model forecast winds for depiction of potential anvil lengths and orientations over the KSC/CCAFS area with lead times from 3 through 168 hours (7 days). In September 2003, AMU customers requested the capability to use data from the KSC 50 MHz Doppler Radar Wind Profiler (DRWP) in the Anvil Threat Sector Tool and this capability was delivered by the AMU in December 2003. In March 2005, the AMU was tasked to migrate the MIDDS Anvil Threat Sector Tool capabilities onto the Advanced Weather Interactive Processing System (AWIPS) as the Anvil Threat Corridor Forecast Tool.

Bauman, William H., III↗

Supplier Research & Analysis Approach

"The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supplier Research and Analysis (SRA) capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 95 reports since its start-up in early 2015. This presentation addresses the approach, methodology and performance of the Supplier Research and Analysis (SRA) capability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability."

supplier research and analysis↗

Supply Chain Research and Analysis for Space Systems

The implementation of NASA GSFC's portfolio of mission projects relies upon inter-connected, multi-tiered supply chains of organizations operating under direct and indirect contracts and other agreements throughout the U.S. and around the world. These supply chains are subject to an inter-related array of technical/production, business, market and security risks that are amplified by the ongoing globalization of industry and technology and which can disrupt or threaten the production and delivery of products and services when needed and in conformance with requirements. In recognition of such risks and associated challenges, GSFC's SMA directorate launched an innovative Supply Chain Research and Analysis capability three years ago to gain greater insight into the operating environment, performance, capabilities and viability of current and prospective suppliers for GSFC projects and proposals. The capability uses business intelligence techniques and primarily open source information resources as part of a cost-effective, non-intrusive methodology to produce several types of research and analysis reports. The reports are based on a holistic analytical framework encompassing key technical/production, business enterprise management, market and security factors, and feature in-depth information, summary information profiles, SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis, and candidate risk concerns in order to pro-actively support SMA and project management needs. The SRA capability, which is designed to complement and support ongoing SMA/project management activities and practices, has produced over 105 reports since its start-up in early 2015.This presentation addresses the approach, methodology and performance of the Supply Chain Research and Analysiscapability and its value in assuring the success of NASA mission projects. In doing so, the presentation provides lessons-learned, best practices, case examples and address how it fits into the development of an enterprise-level Supply Chain Risk Management capability.

supply chain risk management↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state, and to rapidly recover operational capabilities for essential functions after a successful attack. The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.” As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state,1 and to rapidly recover operational capabilities for essential functions after a successful attack.2 The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.”3 As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

FIC Consequence Profile - Hypothetical Cybercrime Syndicate Adversary Dossier

The FIC team has engaged PNNL’s Shamrock Cyber team to produce this Consequence Profile. This Consequence Profile is an Adversary Dossier, which provides the foundation for a thorough understanding of unacceptable mission outcomes, and the threats and vulnerabilities that make these outcomes plausible. The dossier helps stakeholders and development teams understand each other’s viewpoints. It also provides a means for reducing overall risk by prioritizing threats and vulnerabilities based on unacceptable outcomes. The Consequence Profile can be used as is, or as content to inform other reports tailored to a specific audience. It is intended to enable decision makers at all levels to improve the security posture of the system.

Beaman, Jacob E.↗

Ground Collision Avoidance System (Igcas)

The present invention is a system and method for aircraft ground collision avoidance (iGCAS) comprising a modular array of software, including a sense own state module configured to gather data to compute trajectory, a sense terrain module including a digital terrain map (DTM) and map manger routine to store and retrieve terrain elevations, a predict collision threat module configured to generate an elevation profile corresponding to the terrain under the trajectory computed by said sense own state module, a predict avoidance trajectory module configured to simulate avoidance maneuvers ahead of the aircraft, a determine need to avoid module configured to determine which avoidance maneuver should be used, when it should be initiated, and when it should be terminated, a notify Module configured to display each maneuver's viability to the pilot by a colored GUI, a pilot controls module configured to turn the system on and off, and an avoid module configured to define how an aircraft will perform avoidance maneuvers through 3-dimensional space.

Skoog, Mark A↗

UAS Activity Profile Survey

Commercial vendors, trying to tap into the physical protection of critical infrastructure, are offering nuclear facilities the opportunity to borrow detection counter-unmanned aircraft systems (CUAS) equipment to survey the airspace over and around the facility. However, using one vendor or method of detection (e.g., radio frequency [RF], radar, acoustic, visual) will not necessarily provide a complete airspace profile since no single method can detect all UAS threats. Using several detection technologies, the unmanned aircraft systems (UAS) Team, who supports the U.S. National Nuclear Security Administration (NNSA) Office of International Nuclear Security (INS), would like to offer partners a comprehensive airspace profile of the types and frequency of UAS that fly within and around critical infrastructure. Improved UAS awareness will aid in the risk assessment process.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Pathway-based analyses of gene expression profiles at low doses of ionizing radiation

Radiation exposure poses a significant threat to human health. Emerging research indicates that even low-dose radiation once believed to be safe, may have harmful effects. This perception has spurred a growing interest in investigating the potential risks associated with low-dose radiation exposure across various scenarios. To comprehensively explore the health consequences of low-dose radiation, our study employs a robust statistical framework that examines whether specific groups of genes, belonging to known pathways, exhibit coordinated expression patterns that align with the radiation levels. Notably, our findings reveal the existence of intricate yet consistent signatures that reflect the molecular response to radiation exposure, distinguishing between low-dose and high-dose radiation. Moreover, we leverage a pathway-constrained variational autoencoder to capture the nonlinear interactions within gene expression data. By comparing these two analytical approaches, our study aims to gain valuable insights into the impact of low-dose radiation on gene expression patterns, identify pathways that are differentially affected, and harness the potential of machine learning to uncover hidden activity within biological networks. This comparative analysis contributes to a deeper understanding of the molecular consequences of low-dose radiation exposure.

63 RADIATION, THERMAL, AND OTHER ENVIRON. POLLUTAN↗

What Reliability Engineers Should Know about Space Radiation Effects

Space radiation in space systems present unique failure modes and considerations for reliability engineers. Radiation effects is not a one size fits all field. Threat conditions that must be addressed for a given mission depend on the mission orbital profile, the technologies of parts used in critical functions and on application considerations, such as supply voltages, temperature, duty cycle, and redundancy. In general, the threats that must be addressed are of two types-the cumulative degradation mechanisms of total ionizing dose (TID) and displacement damage (DD). and the prompt responses of components to ionizing particles (protons and heavy ions) falling under the heading of single-event effects. Generally degradation mechanisms behave like wear-out mechanisms on any active components in a system: Total Ionizing Dose (TID) and Displacement Damage: (1) TID affects all active devices over time. Devices can fail either because of parametric shifts that prevent the device from fulfilling its application or due to device failures where the device stops functioning altogether. Since this failure mode varies from part to part and lot to lot, lot qualification testing with sufficient statistics is vital. Displacement damage failures are caused by the displacement of semiconductor atoms from their lattice positions. As with TID, failures can be either parametric or catastrophic, although parametric degradation is more common for displacement damage. Lot testing is critical not just to assure proper device fi.mctionality throughout the mission. It can also suggest remediation strategies when a device fails. This paper will look at these effects on a variety of devices in a variety of applications. This paper will look at these effects on a variety of devices in a variety of applications. (2) On the NEAR mission a functional failure was traced to a PIN diode failure caused by TID induced high leakage currents. NEAR was able to recover from the failure by reversing the current of a nearby Thermal Electric Cooler (turning the TEC into a heater). The elevated temperature caused the PIN diode to anneal and the device to recover. It was by lot qualification testing that NEAR knew the diode would recover when annealed. This paper will look at these effects on a variety of devices in a variety of applications. Single Event Effects (SEE): (1) In contrast to TID and displacement damage, Single Event Effects (SEE) resemble random failures. SEE modes can range from changes in device logic (single-event upset, or SEU). temporary disturbances (single-event transient) to catastrophic effects such as the destructive SEE modes, single-event latchup (SEL). single-event gate rupture (SEGR) and single-event burnout (SEB) (2) The consequences of nondestructive SEE modes such as SEU and SET depend critically on their application--and may range from trivial nuisance errors to catastrophic loss of mission. It is critical not just to ensure that potentially susceptible devices are well characterized for their susceptibility, but also to work with design engineers to understand the implications of each error mode. -For destructive SEE, the predominant risk mitigation strategy is to avoid susceptible parts, or if that is not possible. to avoid conditions under which the part may be susceptible. Destructive SEE mechanisms are often not well understood, and testing is slow and expensive, making rate prediction very challenging. (3) Because the consequences of radiation failure and degradation modes depend so critically on the application as well as the component technology, it is essential that radiation, component. design and system engineers work togetherpreferably starting early in the program to ensure critical applications are addressed in time to optimize the probability of mission success.

DiBari, Rebecca↗

Ransomware Security Threat Modeling for Photovoltaic Systems

Ransomware attacks are one of the most dangerous cyber-attacks which can disrupt the operation of photovoltaic (PV) systems and incur an enormous economic loss. This paper introduces a ransomware security threat modeling method that identifies potential vulnerabilities, threats, and impacts of ransomware attacks targeting a PV system. Here, the security threat modeling consists of three steps: 1) system identification, 2) threat modeling that finds existing vulnerabilities, 3) attack modeling that designs attack profiles to succeed ransomware attacks, and 4) penetration testing that performs authorized cyber-attacks and analyzes impacts of the ransomware attack profiles using a real-time hardware-in-the-loop (HIL) PV system security testbed.

attack modeling↗