Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Deciphering Discrepancies: A Comparative Analysis of Docker Image Security

As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.

Boles, Brittany [Montana State University]↗

Multi-dimensional resilience: A quantitative exploration of disease outcomes and economic, political, and social resilience to the COVID-19 pandemic in six countries

The COVID-19 pandemic has highlighted a need for better understanding of countries’ vulnerability and resilience to not only pandemics but also disasters, climate change, and other systemic shocks. A comprehensive characterization of vulnerability can inform efforts to improve infrastructure and guide disaster response in the future. In this paper, we propose a data-driven framework for studying countries’ vulnerability and resilience to incident disasters across multiple dimensions of society. To illustrate this methodology, we leverage the rich data landscape surrounding the COVID-19 pandemic to characterize observed resilience for several countries (USA, Brazil, India, Sweden, New Zealand, and Israel) as measured by pandemic impacts across a variety of social, economic, and political domains. We also assess how observed responses and outcomes (i.e., resilience) of the COVID-19 pandemic are associated with pre-pandemic characteristics or vulnerabilities, including (1) prior risk for adverse pandemic outcomes due to population density and age and (2) the systems in place prior to the pandemic that may impact the ability to respond to the crisis, including health infrastructure and economic capacity. Our work demonstrates the importance of viewing vulnerability and resilience in a multi-dimensional way, where a country’s resources and outcomes related to vulnerability and resilience can differ dramatically across economic, political, and social domains. This work also highlights key gaps in our current understanding about vulnerability and resilience and a need for data-driven, context-specific assessments of disaster vulnerability in the future.

59 BASIC BIOLOGICAL SCIENCES↗

Files and scripts to support manuscript Shuman et al 2023 FATES-SPITFIRE ecosystem assembly across tropics

The dataset includes the parameter and domain files, relevant output files, and scripts to generate simulations and perform analysis with Jupyter notebooks that support the manuscript Shuman, JK et al 2023 “Dynamic ecosystem assembly and escaping the “fire-trap” in the tropics: Insights from FATES_15.0.0”. We have adapted the fire-behavior and effects module, SPITFIRE, for use with the Functionally Assembled Terrestrial Ecosystem Simulator (FATES), a size-structured vegetation demographic model. We test how climate, fire regime and fire-tolerance plant traits interact to determine the biogeography of tropical forests and grasslands. We assign different fire-tolerance strategies based on crown, leaf and bark characteristics, which are key observed fire-tolerance traits across woody plants. For these simulations, three types of vegetation compete for resources: a fire-vulnerable tree with thin bark, a vulnerable deep crown and fire-intolerant foliage; a fire-tolerant tree with thick bark, a thin crown and fire-tolerant foliage; and a fire-promoting C4 grass. We explore the model sensitivity to a critical parameter governing fuel moisture, and show that drier fuels promote increased burning, an expansion of area for grass and fire-tolerant trees and a reduction of area for fire-vulnerable trees. This conversion to lower biomass or grass areas with increased fuel drying results in increased fire burned area and its effects, which could fee back to local climate variables. Simulated size-based fire mortality for trees less than 20 cm in diameter and those with fire-vulnerable traits is higher than that for larger and/or fire-tolerant trees, in agreement with observations. Fire-disturbed forests demonstrate reasonable productivity and capture observed patterns of aboveground biomass in areas dominated by natural vegetation for the recent historical period, but have a large bias in less disturbed areas. Though the model predicts a greater extent of burned fraction than observed in areas with grass dominance, the resulting biogeography of fire-tolerant, thick-bark trees and fire-vulnerable, thin-bark trees corresponds to observations across the tropics. In areas with more than 2500 mm of precipitation, simulated fire frequency and burned area are low, with fire intensities below 150 kW m-1, consistent with observed understory fire behavior across the Amazon. Areas drier than this demonstrate fire intensities consistent with those measured in savannas and grasslands, with high values up to 4000 kW m-1. The results support a positive grass-fire feedback across the region, and suggest that forests which have existed without frequent burning may be vulnerable at higher fire intensities, which is of greater concern under intensifying climate and land use pressures. The ability of FATES to capture the connection between fire disturbance and plant fire-tolerance strategies in determining biogeography provides a useful tool for assessing the vulnerability and resilience of these critical carbon storage areas under changing conditions across the tropics.

54 ENVIRONMENTAL SCIENCES↗

Dynamic ecosystem assembly and escaping the “fire trap” in the tropics: insights from FATES_15.0.0

Abstract. Fire is a fundamental part of the Earth system, with impacts on vegetation structure, biomass, and community composition, the latter mediated in part via key fire-tolerance traits, such as bark thickness. Due to anthropogenic climate change and land use pressure, fire regimes are changing across the world, and fire risk has already increased across much of the tropics. Projecting the impacts of these changes at global scales requires that we capture the selective force of fire on vegetation distribution through vegetation functional traits and size structure. We have adapted the fire behavior and effects module, SPITFIRE (SPread and InTensity of FIRE), for use with the Functionally Assembled Terrestrial Ecosystem Simulator (FATES), a size-structured vegetation demographic model. We test how climate, fire regime, and fire-tolerance plant traits interact to determine the biogeography of tropical forests and grasslands. We assign different fire-tolerance strategies based on crown, leaf, and bark characteristics, which are key observed fire-tolerance traits across woody plants. For these simulations, three types of vegetation compete for resources: a fire-vulnerable tree with thin bark, a vulnerable deep crown, and fire-intolerant foliage; a fire-tolerant tree with thick bark, a thin crown, and fire-tolerant foliage; and a fire-promoting C4 grass. We explore the model sensitivity to a critical parameter governing fuel moisture and show that drier fuels promote increased burning, an expansion of area for grass and fire-tolerant trees, and a reduction of area for fire-vulnerable trees. This conversion to lower biomass or grass areas with increased fuel drying results in increased fire-burned area and its effects, which could feed back to local climate variables. Simulated size-based fire mortality for trees less than 20 cm in diameter and those with fire-vulnerable traits is higher than that for larger and/or fire-tolerant trees, in agreement with observations. Fire-disturbed forests demonstrate reasonable productivity and capture observed patterns of aboveground biomass in areas dominated by natural vegetation for the recent historical period but have a large bias in less disturbed areas. Though the model predicts a greater extent of burned fraction than observed in areas with grass dominance, the resulting biogeography of fire-tolerant, thick-bark trees and fire-vulnerable, thin-bark trees corresponds to observations across the tropics. In areas with more than 2500 mm of precipitation, simulated fire frequency and burned area are low, with fire intensities below 150 kW m−1, consistent with observed understory fire behavior across the Amazon. Areas drier than this demonstrate fire intensities consistent with those measured in savannas and grasslands, with high values up to 4000 kW m−1. The results support a positive grass–fire feedback across the region and suggest that forests which have existed without frequent burning may be vulnerable at higher fire intensities, which is of greater concern under intensifying climate and land use pressures. The ability of FATES to capture the connection between fire disturbance and plant fire-tolerance strategies in determining biogeography provides a useful tool for assessing the vulnerability and resilience of these critical carbon storage areas under changing conditions across the tropics.

54 ENVIRONMENTAL SCIENCES↗

Reinforcement Learning for feedback-enabled cyber resilience

The rapid growth in the number of devices and their connectivity has enlarged the attack surface and made cyber systems more vulnerable. As attackers become increasingly sophisticated and resourceful, mere reliance on traditional cyber protection, such as intrusion detection, firewalls, and encryption, is insufficient to secure the cyber systems. Cyber resilience provides a new security paradigm that complements inadequate protection with resilience mechanisms. A Cyber-Resilient Mechanism (CRM) adapts to the known or zero-day threats and uncertainties in real-time and strategically responds to them to maintain the critical functions of the cyber systems in the event of successful attacks. Feedback architectures play a pivotal role in enabling the online sensing, reasoning, and actuation process of the CRM. Reinforcement Learning (RL) is an important gathering of algorithms that epitomize the feedback architectures for cyber resilience. It allows the CRM to provide dynamic and sequential responses to attacks with limited or without prior knowledge of the environment and the attacker. In this work, we review the literature on RL for cyber resilience and discuss the cyber-resilient defenses against three major types of vulnerabilities, i.e., posture-related, information-related, and human-related vulnerabilities. Here we introduce moving target defense, defensive cyber deception, and assistive human security technologies as three application domains of CRMs to elaborate on their designs. The RL algorithms also have vulnerabilities themselves. We explain the major vulnerabilities of RL and present develop several attack models where the attacker target the information exchanged between the environment and the agent: the rewards, the state observations, and the action commands. We show that the attacker can trick the RL agent into learning a nefarious policy with minimum attacking effort. The paper introduces several defense methods to secure the RL-enabled systems from these attacks. However, there is still a lack of works that focuses on the defensive mechanisms for RL-enabled systems. Last but not least, we discuss the future challenges of RL for cyber security and resilience and emerging applications of RL-based CRMs.

97 MATHEMATICS AND COMPUTING↗

Towards Software Bill of Materials in the Nuclear Industry

Large, modern industrial facilities often incorporate thousands of digital assets in their operational technology. Regulated facilities, such as nuclear power plants (NPPs), maintain robust cybersecurity and configuration management programs that often use bills of materials (BOMs) for these assets, including make, model, and version of hardware, firmware, and software. However, these BOMs typically capture only first- or second-tier information provided by the original equipment manufacturer (OEM). Unfortunately, as indicated by the increasing number and sophistication of software supply chain attacks, this level of detail is insufficient for identifying all the potential vulnerabilities and risks in software applications. Software BOMs (SBOMs) provide detailed enumeration of components and dependencies within the product or devices, including firmware. SBOMs can be combined with vulnerability data sources and vendor vulnerability attestations to improve vulnerability management and enable rapid identification of affected components when new software vulnerabilities are discovered. Ideally, SBOMs are created by the OEM prior to installation. However, since this practice is not yet commonplace and since NPPs are typically slow to adopt new technology, most NPPs do not incorporate SBOMs into their asset or configuration management programs. Fortunately, SBOMs can be generated by NPPs on existing digital assets to provide further insight into risk management decisions. This report provides an overview of the current SBOM ecosystem and recommends guidance on how to get started in a “crawl, walk, run” manner to develop and implement a sustainable SBOM program for digital assets in an NPP.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

An Analysis of Grid Operator Survey Responses: Inexperience, Workload and Fatigue in the Control Room

Although a wide array of tools and technologies have been developed over the last decade to support power grid operators, deployment of these tools has been less successful. One reason for unsuccessful deployment may be an inadequate understanding of the factors that contribute to operator error in the control room. An analysis of operators’ current vulnerabilities may provide the baseline understanding needed to inform new technology integration. In an attempt to learn more about these vulnerabilities and their perceived impact on human error we collected and analyzed survey data from 20 electric grid control room operators. We asked survey respondents to consider the various operator, technology and interaction vulnerabilities that may arise during work in the control room and record their attitudes and experiences toward each. Results suggest operator inexperience, high mental workload and fatigue are the most common vulnerabilities experienced during a shift. Survey results were analyzed to explore these vulnerabilities in greater depth.

Inexperience, Workload, Fatigue↗

Disproportionate impacts of COVID-19 in a large US city

COVID-19 has disproportionately impacted individuals depending on where they live and work, and based on their race, ethnicity, and socioeconomic status. Studies have documented catastrophic disparities at critical points throughout the pandemic, but have not yet systematically tracked their severity through time. Using anonymized hospitalization data from March 11, 2020 to June 1, 2021 and fine-grain infection hospitalization rates, we estimate the time-varying burden of COVID-19 by age group and ZIP code in Austin, Texas. During this 15-month period, we estimate an overall 23.7% (95% CrI: 22.5–24.8%) infection rate and 29.4% (95% CrI: 28.0–31.0%) case reporting rate. Individuals over 65 were less likely to be infected than younger age groups (11.2% [95% CrI: 10.3–12.0%] vs 25.1% [95% CrI: 23.7–26.4%]), but more likely to be hospitalized (1,965 per 100,000 vs 376 per 100,000) and have their infections reported (53% [95% CrI: 49–57%] vs 28% [95% CrI: 27–30%]). We used a mixed effect poisson regression model to estimate disparities in infection and reporting rates as a function of social vulnerability. We compared ZIP codes ranking in the 75th percentile of vulnerability to those in the 25th percentile, and found that the more vulnerable communities had 2.5 (95% CrI: 2.0–3.0) times the infection rate and only 70% (95% CrI: 60%-82%) the reporting rate compared to the less vulnerable communities. Inequality persisted but declined significantly over the 15-month study period. Our results suggest that further public health efforts are needed to mitigate local COVID-19 disparities and that the CDC’s social vulnerability index may serve as a reliable predictor of risk on a local scale when surveillance data are limited.

60 APPLIED LIFE SCIENCES↗

Warming Response of Deep Soil Carbon (LDRD Final Report)

The overarching objective of this LDRD project was to determine the vulnerability of deep soil organic carbon (SOC) to warming in the Sierra Nevada region. Deep soils (>30 cm) store more than 70% of global SOC, and increased SOC decomposition and CO 2 emissions caused by warming are potentially large climate change feedbacks. According to the Intergovernmental Panel on Climate Change, temperatures are expected to increase by 4°C by the year 2100, warming the land and underlying soil, and making understanding of how warming will influence deep SOC storage and persistence critical to projecting the land carbon sink. However, uncertainty remains in our process-level understanding and ability to quantify how projected warming will impact the stability of carbon in deep soils. We investigated warming effects on deep (up to 16 m) SOC stability across climate, vegetation, and soil mineralogy gradients in California. We sampled soils from the surface to bedrock (down to 16 meters) at four sites representing vastly different ecosystems across the Northern and Southern Sierra Nevada mountains. This study quantified the response of SOC concentration, distribution, and vulnerability to warming using a soil incubation experiment to warm the whole soil profile and radiocarbon and stable isotopes to assess which pools are vulnerable to loss under warming. Our results refine our understanding of the terrestrial carbon cycle by revealing the vulnerability of deep SOC to future changes in climate and how minerology may influence that vulnerability.

58 GEOSCIENCES↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Reinforcement Learning Approach to Cybersecurity in Space (RELACSS)

Securing satellite groundstations against cyber-attacks is vital to national security missions. However, these cyber threats are constantly evolving. As vulnerabilities are discovered and patched, new vulnerabilities are discovered and exploited. In order to automate the process of discovering existing vulnerabilities and the means to exploit them, a reinforcement learning framework is presented in this report. We demonstrate that this framework can learn to successfully navigate an unknown network and detect nodes of interest despite the presence of a moving target defense. The agent then exfiltrates a file of interest from the node as quickly as possible. This framework also incorporates a defensive software agent that learns to impede the attacking agents progress. This setup allows for the agents to work against each other and improve their abilities. We anticipate that this capability will help uncover unforeseen vulnerabilities and the means to mitigate them. The modular nature of the framework enables users to swap out learning algorithms and modify the reward functions in order to adapt the learning tasks to various use cases and environments. Several algorithms, viz., tabular Q learning, deep Q networks, proximal policy optimization, advantage actor-critic, generative adversarial imitation learning, are explored for the agents and the results highlighted. The agent learns to solve the tasks in a light-weight abstract environment. Once the agent learns to perform sufficiently well, it can be deployed in a minimega virtual machine environment (or a real network) with wrappers that map abstract actions to software commands. The agent also uses a local representation of the actions called a ‘slot-mechanism’. This allows the agent to learn in a certain network and generalize it to different networks. The defensive agent learns to predict the actions taken by an offensive agent and uses that information to anticipate the threat. This information can then either be used to raise an alarm or to take actions to thwart the attack. We believe that with the appropriate reward design, a representative environment, and action set, this framework can be generalized to tackle other cybersecurity tasks. By sufficiently training these agents, we can anticipate vulnerabilities leading to robust future designs. We can also deploy automated defensive agents that can help secure satellite groundstation and their vital national security missions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Threat Landscape for BESS and IBR

The cyber risk landscape for BESS and IBR can be broken up by threats, vulnerabilities, and consequences for these systems. This presentation walks through the cyber risk landscape for BESS through the lens of consequence-informed awareness and mitigation for each risk factor. Threats with varying capabilities have been demonstrated in real-world events. Though threat actors can rarely be directly influenced by organizations, exposure of systems to adversaries can be limited (a known issue with IBR systems) to reduce likelihood of adversaries accessing systems with disruptive consequences. Common trends in disclosed IBR vulnerabilities include weak password generation or managements for various devices or services and web portal vulnerabilities that provide unauthorized access to data or capabilities or elevated user privileges. Understanding these common vulnerabilities and considering the consequences if these types of vulnerabilities were to occur can help mitigate risk. Consequences range from loss-of-view events that have no reliability impact to asset damage or grid stability impacts. Five case studies are briefly shared to highlight trends in real-world events affecting IBR.

14 - SOLAR ENERGY↗

A critical review of cyber-physical security for building automation systems

Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.

97 MATHEMATICS AND COMPUTING↗

Social-ecological interactions in a disaster context: Puerto Rican farmer households’ food security after Hurricane Maria

Islands are uniquely vulnerable to extreme weather events and food insecurity, and have additional response challenges due to their limited landmasses and economies, isolation, colonial legacies, and high dependence of food imports. Domestic farmers have a key role in producing food for island communities like Puerto Rico, which can safeguard food security when food importation may be challenging. Nevertheless, in the context of disaster, farmers themselves may be vulnerable to food insecurity and unable to contribute to domestic markets. This paper examines Puerto Rican farmers households’ food security in the aftermath of 2017’s Hurricane Maria using a social-ecological lens. Survey data from 405 farmers gathered eight months after Maria, coupled with biophysical data from the hurricane’s impacts (winds, rains, and landslides), were analyzed. Overall, 69% of farmers experienced at least one month of food insecurity in the aftermath of Hurricane Maria, and 38% reported persistent food insecurity (three months or more). A multinomial logistic regression suggests that biophysical impacts, but especially social factors, such as age and constraint access to external sources of support, are linked with persistent food insecurity. This suggests that the biophysical impacts of the hurricane interact with existing infrastructure and social resources to affect farmer vulnerability and the food environment in different ways. Thus, strengthening adaptive capacity in multiple domains can help farmers and vulnerable populations better navigate the disruptions faced during disasters to alleviate food insecurity.

54 ENVIRONMENTAL SCIENCES↗

Anatomical and hydraulic responses to desiccation in emergent conifer seedlings

Premise The young seedling life stage is critical for reforestation after disturbance and for species migration under climate change, yet little is known regarding their basic hydraulic function or vulnerability to drought. Here, we sought to characterize responses to desiccation including hydraulic vulnerability, xylem anatomical traits, and impacts on other stem tissues that contribute to hydraulic functioning. Methods Larix occidentalis , Pseudotsuga menziesii , and Pinus ponderosa (all ≤6 weeks old) were imaged using x‐ray computed microtomography during desiccation to assess seedling biomechanical responses with concurrently measured hydraulic conductivity ( k s ) and water potential ( Ψ ) to assess vulnerability to xylem embolism formation and other tissue damage. Results In non‐stressed samples for all species, pith and cortical cells appeared circular and well hydrated, but they started to empty and deform with decreasing Ψ which resulted in cell tearing and eventual collapse. Despite the severity of this structural damage, the vascular cambium remained well hydrated even under the most severe drought. There were significant differences among species in vulnerability to xylem embolism formation, with 78% xylem embolism in L. occidentalis by Ψ of −2.1 MPa, but only 47.7% and 62.1% in P. ponderosa and P. menziesii at −4.27 and −6.73 MPa, respectively. Conclusions Larix occidentalis seedlings appeared to be more susceptible to secondary xylem embolism compared to the other two species, but all three maintained hydration of the vascular cambium under severe stress, which could facilitate hydraulic recovery by regrowth of xylem when stress is relieved.

Miller, Megan L.↗

Relative effect of anthropogenic warming and natural climate variability to changes in Compound drought and heatwaves

Compound drought and heatwave (CDHW) events can be influenced by large scale teleconnections and anthropogenic warming, leading to severe socio-economic impacts across various climate regions. Here, the relative influence of six different teleconnection patterns and anthropogenic global warming on the global CDHW occurrences is quantified systematically using the instrumental data period, 1982–2016. The results from the study suggest a substantial increase in the CDHW events (1–5 events per year) across various parts of the globe at the beginning of 21st century (2000–2016). A Bayesian approach is implemented to identify the most vulnerable climate regions based on the degree of susceptibility of heatwaves (DSHW) towards drought. As such, top ten most vulnerable regions are selected based on the DSHW magnitude, and a partial correlation analysis is performed to select the natural and anthropogenic drivers of CDHW in those regions, separately. A logistic regression model is then used to determine significant changes in the odds of CDHW due to changes in the selected drivers that suggest a significantly positive, and multiplicative effect of anthropogenic global warming in the top ten most vulnerable climate regions. Finally, the same logistic regression model, integrated with an analytical framework, is applied to determine the relative influence of anthropogenic global warming on the changes in odds of CDHW for the future, 1.5 °C and 2 °C warming limits. Finally, the results suggest that relative to the 2 °C global warming, constraining to the 1.5 °C global warming limit may conduce about 17-fold reduction in the odds of CDHW in the most vulnerable climate region, East Asia, 5–8-fold reduction in Western North America, Northern Australia, Central North America, Central Europe, South Asia, and the Mediterranean region, and 3–4-fold reduction in Northeastern Brazil, Eastern North America, and West Asia.

54 ENVIRONMENTAL SCIENCES↗

Distinct xylem responses to acute vs prolonged drought in pine trees

Increasing dryness challenges trees’ ability to maintain water transport to the leaves. Most plant hydraulics models use a static xylem response to water stress. Yet, in reality, lower soil moisture and warmer temperatures during growing seasons feed back onto xylem development. In turn, adjustments to water stress in the newly built xylem influence future physiological responses to droughts. In this study, we investigate the annual variation of anatomical traits in branch xylem in response to different soil and atmospheric moisture conditions and tree stress levels, as indicated by seasonal predawn leaf water potential (??L,pd). We used a 6-year field experiment in southwestern USA with three soil water treatments applied to Pinus edulis Engelm trees—ambient, drought (45% rain reduction) and irrigation (15–35% annual water addition). All trees were also subject to a natural 1-year acute drought (soil and atmospheric) that occurred during the experiment. The irrigated trees showed only moderate changes in anatomy-derived hydraulic traits compared with the ambient trees, suggesting a generally stable, well-balanced xylem structure under unstressed conditions. The artificial prolonged soil drought increased hydraulic efficiency but lowered xylem construction costs and decreased tracheid implosion safety ((t/b)2), suggesting that annual adjustments of xylem structure follow a safety–efficiency trade-off. The acute drought plunged hydraulic efficiency across all treatments. The combination of acute and prolonged drought resulted in vulnerable and inefficient new xylem, disrupting the stability of the anatomical trade-off observed in the rest of the years. The xylem hydraulic traits showed no consistent direct link to ??L,pd. In the future, changes in seasonality of soil and atmospheric moisture are likely to have a critical impact on the ability of P. edulis to acclimate its xylem to warmer climate. Furthermore, the increasing frequency of acute droughts might reduce hydraulic resilience of P. edulis by repeatedly creating vulnerable and less efficient anatomical structure.

Guerin, Marceau↗