Publications
Showing 29 results for Author: Stacy J. Prowell
Mar, 2026
Conference Paper
Tools, Techniques, and Methodologies: A Survey of Digital Forensics for SCADA Systems
Security aspects of SCADA environments and the systems within are increasingly a center of interest to researchers and security professionals. As the rise of sophisticated and nation-state malware targeting such systems flourishes, traditional digital forensics tools struggle to transfer the same capabilities to systems lacking typical volatile memory primitives, monitorin…
Mar, 2026
ORNL Report
ORNL AI Capabilities Summary
ORNL AI-powered capabilities in cybersecurity: CESER sponsor is cataloging AI-powered lab capabilities in cybersecurity and has asked us to complete this one-page template for each capability. These can be CESER-funded work, LDRD efforts, even projects or efforts funded by other agencies.) Note the request is for capability, not project.
May, 2025
Journal
Entropy of the Quantum–Classical Interface: A Potential Metric for Security
Hybrid quantum–classical systems are emerging as key platforms in quantum computing, sensing, and communication technologies, but the quantum–classical interface (QCI)—the boundary enabling these systems—introduces unique and largely unexplored security vulnerabilities. This position paper proposes using entropy-based metrics to monitor and enhance security, specifically a…
May, 2025
Journal
Simulating quantum-classical interfaces via the Lindblad master equation
In hybrid quantum systems, the interface between quantum and classical domains is essential for the generation, control, and measurement of quantum states. Quantum-classical interfaces (QCIs) are ubiquitous in devices such as optical modulators, quantum sensors, and signal processors, where classical signals influence quantum dynamics. In this paper, we employ the Lindblad…
Jul, 2024
ORNL Report
Black Box Statistical Testing of Key Generation Algorithms
Key generation for cryptographic algorithms is critical to the security of these algorithms. Weak sources of entropy can damage the security of generated keys, but even with a good source of entropy and a good key generation algorithm, errors in the implementation can compromise overall security. In the current work, we consider how to evaluate the robustness of the implem…
Feb, 2024
ORNL Report
Final Report: Energy Delivery Systems with Verifiable Trustworthiness
Energy Delivery Systems (EDS) must be verified to be free from intrusive and malicious software. One way of verifying this software is to perform device scans to detect malicious code. Because it is possible to have “fileless” malware that exists only in device (volatile) memory, offline scanning and even many forms of online scanning is insufficient for detection. This pr…
Feb, 2024
ORNL Report
Heartbeat: Detecting Malware by Periodic Power Signal Injection and Monitoring
Rootkits and other stealthy malware attempt to conceal their presence on a computer by making changes to the host computer’s operating environment. ORNL’s Heartbeat technology detects these changes, and thus the malware itself. Heartbeat operates by directly monitoring the DC power consumption of the computer while a set of operations, the “heartbeat,” is executed periodic…
Nov, 2023
Journal
Use of Thermistor Temperature Sensors for Cyber-Physical System Security
The last few decades have seen a large proliferation in the prevalence of cyber-physical systems. This has been especially highlighted by the explosive growth in the number of Internet of Things (IoT) devices. Unfortunately, the increasing prevalence of these devices has begun to draw the attention of malicious entities which exploit them for their own gain. What makes the…
Nov, 2023
ORNL Report
MYRTLE POINT REPORT – PHASE I
This report presents the status of the first phase of Myrtle Point, a project performed by ORNL to study the Hashgraph algorithm and related blockchain technologies in support of developing a distributed, fault-tolerant network. Hashgraph is a two-dimensional blockchain technology. This project involves experimenting with the technology to better understand its capability…
Nov, 2023
ORNL Report
Automated Vulnerability Detection (AVUD) for Compiled Smart Grid Software
This project developed and implemented a system for conducting cybersecurity vulnerability detection of smart grid components and systems by performing static analysis of compiled software (“firmware”). The resulting system for automated vulnerability detection (AVUD) was implemented as part of Oak Ridge National Laboratory’s existing test bed for smart meters, the Sustain…