Publications
Showing 25 results for Author: Stacy J. Prowell
Mar, 2026
Conference Paper
Tools, Techniques, and Methodologies: A Survey of Digital Forensics for SCADA Systems
Security aspects of SCADA environments and the systems within are increasingly a center of interest to researchers and security professionals. As the rise of sophisticated and nation-state malware targeting such systems flourishes, traditional digital forensics tools struggle to transfer the same capabilities to systems lacking typical volatile memory primitives, monitorin…
May, 2025
Journal
Entropy of the Quantum–Classical Interface: A Potential Metric for Security
Hybrid quantum–classical systems are emerging as key platforms in quantum computing, sensing, and communication technologies, but the quantum–classical interface (QCI)—the boundary enabling these systems—introduces unique and largely unexplored security vulnerabilities. This position paper proposes using entropy-based metrics to monitor and enhance security, specifically a…
May, 2025
Journal
Simulating quantum-classical interfaces via the Lindblad master equation
In hybrid quantum systems, the interface between quantum and classical domains is essential for the generation, control, and measurement of quantum states. Quantum-classical interfaces (QCIs) are ubiquitous in devices such as optical modulators, quantum sensors, and signal processors, where classical signals influence quantum dynamics. In this paper, we employ the Lindblad…
Feb, 2024
ORNL Report
Final Report: Energy Delivery Systems with Verifiable Trustworthiness
Energy Delivery Systems (EDS) must be verified to be free from intrusive and malicious software. One way of verifying this software is to perform device scans to detect malicious code. Because it is possible to have “fileless” malware that exists only in device (volatile) memory, offline scanning and even many forms of online scanning is insufficient for detection. This pr…
Feb, 2024
ORNL Report
Heartbeat: Detecting Malware by Periodic Power Signal Injection and Monitoring
Rootkits and other stealthy malware attempt to conceal their presence on a computer by making changes to the host computer’s operating environment. ORNL’s Heartbeat technology detects these changes, and thus the malware itself. Heartbeat operates by directly monitoring the DC power consumption of the computer while a set of operations, the “heartbeat,” is executed periodic…
Nov, 2023
Conference Paper
Towards Malware Detection via CPU Power Consumption: Data Collection Design and Analytics
This paper presents an experimental design and data analytics approach aimed at power-based malware detection on general-purpose computers. Leveraging the fact that malware executions must consume power, we explore the postulate that malware can be accurately detected via power data analytics. Our experimental design and implementation allow for programmatic collection of…
Nov, 2023
ORNL Report
Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software
This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustain…
Nov, 2023
Conference Paper
Shifting Left for Machine Learning: An Empirical Study of Security Weaknesses in Supervised Learning-based Projects
Context: Supervised learning-based projects (SLPs), i.e., software projects that use supervised learning algorithms, such as decision trees are useful for performing classification-related tasks. Yet, security weaknesses, such as the use of hard-coded passwords in SLPs, can make SLPs susceptible to security attacks. A characterization of security weaknesses in SLPs can hel…
Nov, 2023
Journal
A Taxonomy and Review of Remote Attestation Schemes in Embedded Systems
Embedded systems that make up the Internet of Things (IoT), Supervisory Control and Data Acquisition (SCADA) networks, and Smart Grid applications are coming under increasing scrutiny in the security field. Remote Attestation (RA) is a security mechanism that allows a trusted device, the verifier, to determine the trustworthiness of an untrusted device, the prover. RA has…
Nov, 2023
Conference Paper
Companion Assisted Software Based Remote Attestation in SCADA Networks
Critical infrastructure such as power generation and water distribution systems have become a priority target in cyber warfare because of their recent computerization and introduction to the internet. As a result, Supervisory Control and Data Acquisition (SCADA) system security has become a hot topic in academic and industrial research. Among these topics, Remote Attestati…