Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Towards Automatically Matching Security Advisories to CPEs: String Similarity-based Vendor Matching

When a vulnerability is reported by the National Vulnerability Database (NVD), affected products are listed in the structured Common Platform Enumeration (CPE) format. Unfortunately, if the vulnerability is in a software library (e.g., Log4j), it will not include CPEs for each product containing that library. In these cases, security operators need to manually read the vendor's or third-party security advisories to see if their product is affected. However, these advisories do not report affected products in a structured format, which prevents automated processing, This paper makes the first effort towards automatically constructing structured CPEs for the vulnerable products in a non-NVD security advisory from the unstructured data in the advisory. Since this is a very challenging problem, this paper specifically focuses on the initial but key step of matching the un-structured vendor names in security advisories to the structured vendor representations in the standard CPE format. We explore the feasibility of using string similarity to solve the problem. The basic idea is to compare a vendor name from the non-NVD advisory with each vendor in the official CPE dictionary. The CPE vendor with the highest similarity score to the advisory's vendor will be considered as the match. We first conduct an experimental, comparative study of multiple mainstream string similarity metrics for this matching problem. To improve the performance, we then design a new string similarity metric that is adapted from an existing metric by weighing different tokens in the advisory's vendor name differently.

McClanahan, Kylie↗

Modeling Failure of Electrical Transformers due to Effects of a HEMP Event

Understanding the effect of a high-altitude electromagnetic pulse (HEMP) on the equipment in the United States electrical power grid is important to national security. A present challenge to this understanding is evaluating the vulnerability of transformers to a HEMP. Evaluating vulnerability by direct testing is cost-prohibitive, due to the wide variation in transformers, their high cost, and the large number of tests required to establish vulnerability with confidence. Alternatively, material and component testing can be performed to quantify a model for transformer failure, and the model can be used to assess vulnerability of a wide variety of transformers. This project develops a model of the probability of equipment failure due to effects of a HEMP. Potential failure modes are cataloged, and a model structure is presented which can be quantified by the results of small-scale coupon tests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Security Analysis for Nuclear Reactor Control Systems (Final Technical Report)

This project investigated the cyber-security impacts of moving from an all analog, point-to-point, instrumentation and control (I&C) system to a digital I&C system based on Modbus and a shared communication medium. A formalism called a hybrid attack graph was expanded to support the nuclear research reactor system. The hybrid attack graph allows one to check a system for vulnerabilities, in this case cyber-security vulnerabilities, and to document the attack vectors (scenarios) causing those vulnerabilities. In parallel, a simulation of the system was developed to model both the physical reactor parameters and operations, as well as the network interconnects and communications. This simulation platform was modeled on the nuclear research reactor located at Washington State University. The simulation platform provided a sandbox to evaluate and quantify the impact of identified and proposed vulnerabilities in the system and to determine the effectiveness of countermeasures at stopping these attacks. The simulation and hybrid attack graph tools were integrated to provide a streamlined process of generating attack scenarios, playing those scenarios out in the simulation, and then analyzing the results to correlate system state to states in the hybrid attack graph. This process was used to (1) quantify the impact of attack scenarios and (2) to determine if the system moved through the hybrid attack graph as anticipated. The hybrid attack graph tool was extended and customized to produce a tool to automatically identify critical assets (CAs) and critical digital assets (CDAs) as defined by NRC Regulatory Guide 5.71. This tool was verified using the nuclear research reactor at Washington State University. Finally, a series of educational modules covering the findings of the different aspects of this research have been created.

97 MATHEMATICS AND COMPUTING↗

Root Influences on Mobilization and Export of Mineral-bound Soil Organic Matter

Biogeochemical cycles within mountainous watersheds are key regulators of ecosystem carbon storage and downstream nutrient loadings, and they have shown to be particularly vulnerable to climate change impacts. Increasing temperature and persistent droughts have already dramatically changed vegetation cover across the mountainous western US, with unknown consequences for soil carbon and nutrient cycles belowground. What remains elusive is to what extent associated changes in root-soil interactions may mobilize the vast pool of organic matter (OM) that has been stabilized by associations with minerals for centuries or millennia. Although plant root-driven OM mobilization from minerals may be a central control on carbon loss and nutrient export, such mechanisms are currently missing from conceptual and numerical models. The overall objective of this Exploratory Project is to identify the biogeochemical mechanisms by which roots destabilize mineral-associated organic matter (MAOM) and the cumulative impact on carbon and nutrient fate. To accomplish this goal, we integrated well-controlled laboratory experiments with in-field measurements and a scalable modeling approach. First, we conducted model system experiments to assess the vulnerability of MAOM to exudate-mediated mechanisms. Our results show that common root exudates effectively destabilize MAOM not only through direct, ligand-driven mobilization mechanisms, but also indirect, microbially-mediated mechanisms relying on secondary metabolites and enzymes. We further found that OM bound to poorly crystalline Fe and Al (hydr)oxides is more vulnerable to exudate-induced destabilization than OM bound to more crystalline phases, particularly in response to direct, ligand-promoted mechanisms. These findings demonstrate that the stability of MAOM is not just a function of their inherent properties, but also will depend in large parts on the ability of plant roots and microbes to produce exudates capable of triggering suitable mobilization mechanisms. We further employed a well-controlled rhizobox approach, combining advanced microsensor and mass spectrometry techniques, to resolve spatiotemporal variations in the composition and availability of exudates along single growing roots of grasses. Our results show that the composition of functionally relevant exudate compounds varies at extremely short time scales, seemingly shifting from ligands such as aromatic acids around root tips to less reactive metabolites such as amino acids around mature root segments. These results suggest a prevalence of direct MAOM mobilization mechanisms around the root tip, while indirect MAOM mobilization strategies may dominate around more mature root segments. Additionally, we utilized microsensor measurements in rhizoboxes to parameterize a rhizosphere (hydro)biogeochemistry reactive transport model (eSTOMP-ROOTS). The resulting model was used to assess how root exudations affects the stability of MAOM. Model simulations show that diel pulses of root exudation are strong enough to cause oscillations in biogeochemical conditions—particularly in pH, oxygen concentrations, and microbial activity— that repeatedly disrupt MAOM. Finally, we assessed field-scale impacts of root-driven MAOM destabilization over short and long time scales. A combination of in-field incubations and field-based characterizations showed that MAOM may not only be vulnerable to seasonal variations in root activity, but also to root-driven weathering over pedogenic time scales. In sum, results from our Exploratory Award highlight the strong control plant roots exert on MAOM mobilization and, thus, on the potential for carbon and nutrient export from watersheds.

54 ENVIRONMENTAL SCIENCES↗

Adversarial Perturbations Are Not So Weird: Entanglement of Robust and Non-Robust Features in Neural Network Classifiers

Neural networks trained on visual data are well-known to be vulnerable to often imperceptible adversarial perturbations. The reasons for this vulnerability are still being debated in the literature. Recently Ilyas et al. (2019) showed that this vulnerability arises, in part, because neural network classifiers rely on highly predictive but brittle “non-robust” features. In this paper we extend the work of Ilyas et al. by investigating the nature of the input patterns that give rise to these features. In particular, we hypothesize that in a neural network trained in a standard way, non-robust features respond to small, “non-semantic” patterns that are typically entangled with larger, robust patterns, known to be more human-interpretable, as opposed to solely responding to statistical artifacts in a dataset. Thus, adversarial examples can be formed via minimal perturbations to these small, entangled patterns. In addition, we demonstrate a corollary of our hypothesis: robust classifiers are more effective than standard (non-robust) ones as a source for generating transferable adversarial examples in both the untargeted and targeted settings. The results we present in this paper provide new insight into the nature of the non-robust features responsible for adversarial vulnerability of neural network classifiers.

97 MATHEMATICS AND COMPUTING↗

EMP Testing of UL489 Circuit Breakers

Sandia National Laboratories (SNL) is performing a test campaign for the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) to address high-altitude electromagnetic pulse (HEMP) vulnerability of critical components of generation stations, with focus on early-time (E1) HEMP. The campaign seeks to establish response and damage thresholds for these critical elements in response to reasonable HEMP threat levels as a means for determining where vulnerabilities may exist or where mitigations may be needed. This report provides component vulnerability test results that will help to inform site vulnerability assessments and HEMP mitigation planning.

42 ENGINEERING↗

Community Resilience Indicator Analysis: Commonly Used Indicators from Peer-Reviewed Research (Updated for Research Published 2003-2021)

In 2017, FEMA’s National Integration Center (NIC) Technical Assistance (TA) Branch identified a need to establish a data-driven basis for prioritizing locations for TA investment and guiding local emergency management planning. To achieve this goal, FEMA tasked Argonne National Laboratory (Argonne) with identifying commonly used indicators of community resilience across the landscape of published peer-reviewed research. FEMA and Argonne completed the first Community Resilience Indicator Analysis (CRIA) in 2018 and repeated the process in 2022. The CRIA process begins with a literature review and cataloguing of published peer-reviewed assessment methodologies on social vulnerability and community resilience. The literature review findings are then filtered by inclusion criteria established by the CRIA research team to ensure the methodologies are: (1) Quantitative, (2) Data and methodology are publicly available, (3) Calculated at the county level or lower, (4) Examine generalized hazard risk (rather than a singular hazard), and (5) Focused on pre-disaster community conditions. After this, the research team identifies the commonly used indicators across these methodologies and selects the best data source for each indicator. Finally, the research team bins the data for visual display, conducts a correlation analysis and creates a composite index, the FEMA Community Resilience Index (FEMA CRI). In 2018, the CRIA identified eight resilience and vulnerability assessment methodologies and 20 commonly used indicators (indicators used in three or more of the eight methodologies). The FEMA CRI in 2018 was created from these 20 indicators and was produced for at the county level. The 2022 CRIA updated the literature review to expand the list of methodologies examined and followed the same process, resulting in an analysis of 14 methodologies published between 2003 and 2021 and 22 indicators identified as commonly used (indicators used in five or more of the 14 methodologies). In 2022, the research team produced the FEMA CRI at the county and the census tract levels. To make the CRIA data more accessible and more actionable, each individual indicator and the FEMA CRI is binned and included in FEMA’s Resilience Analysis and Planning Tool (RAPT). RAPT enables emergency managers and community partners to quickly visualize relative differences in potential resilience by county, tribe and census tract. By reviewing the data for each of these 22 indicators individually, emergency managers can gain insights for targeted outreach strategies, planning, mitigation investments and response and recovery operations. Communities, regional governments and others can use this data to better understand potential challenges to resilience. As the social science field of examining and validating indicators of resilience evolves, FEMA will update RAPT to provide emergency managers and community partners with additional data and tools to inform planning, mitigation, response and recovery. It is important to understand that the role of the emergency manager is not to change or to “improve” the data, but to plan appropriately for the community characteristics reflected in the data. These datasets are community characteristics that researchers have identified as important considerations for resilience. For example, people with disabilities may have greater challenges to be resilient to disasters. If a community has a high population of people with disabilities, the emergency manager(s) may need to create tailored preparedness outreach programs and strategies to ensure those residents have support if evacuation is necessary. Rather than label these indicators as an absolute measure of resilience, FEMA considers “potential challenges to resilience” a better frame to understand these indicators. Everyone is vulnerable to disasters. While scholars theorize that certain characteristics may make an individual or a household more socially vulnerable, the data does not reflect measures that individuals and/or communities have taken to address potential challenges, such as emergency management planning and outreach or household preparedness measures. To aid emergency managers in understanding how to use these indicators, calling them potential challenges to resilience supports a more positive and strategic application of the data in all phases of emergency management.

99 GENERAL AND MISCELLANEOUS↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING↗

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING↗

Air Return Strategies and Airborne SARS-CoV-2

Dedicated ducted air return per zone for heating, ventilating, and air-conditioning (HVAC) systems is sometimes claimed to be a superior technique over plenum return strategy from the viewpoint of exposure reduction to airborne pathogens. While both the return strategies have advantages, there is limited evidence in the literature as to which strategy is superior merely from a standpoint of building vulnerability to airborne contaminants. We performed multizonal airborne contaminant dispersion modelling using CONTAM to simulate the overall building vulnerability to airborne SARS-CoV-2 aerosols when released in an office building and evaluated the two air return strategies. Results showed that for ducted returns, maintaining negative pressure in the release zone coupled with 100% outdoor air supply can greatly reduce overall building vulnerability. However, for a building maintained under a slight positive pressure and a recirculated air percentage as low as 31%, ducted returns do not necessarily outperform plenum returns in terms of overall building vulnerability to airborne pathogens. Building-specific details and factors that are not easily represented with multizone modelling are important, making general preferential statements for either strategy difficult to make. Insights from this study can guide new construction and retrofits of buildings both during and after the COVID-19 pandemic with the aim of safe re-occupancy of buildings while keeping the buildings resilient against potential future epidemics spread by airborne agents.

Shrestha, Prateek↗

Inequality in the availability of residential air conditioning across 115 US metropolitan areas

Continued climate change is increasing the frequency, severity, and duration of populations’ high temperature exposures. Indoor cooling is a key adaptation, especially in urban areas, where heat extremes are intensified—the urban heat island effect (UHI)—making residential air conditioning (AC) availability critical to protecting human health. In the United States, the differences in residential AC prevalence from one metropolitan area to another is well understood, but its intra-urban variation is poorly characterized, obscuring neighborhood-scale variability in populations’ heat vulnerability and adaptive capacity. We address this gap by constructing empirically derived probabilities of residential AC for 45,995 census tracts across 115 metropolitan areas. Within cities, AC is unequally distributed, with census tracts in the urban “core” exhibiting systematically lower prevalence than their suburban counterparts. Moreover, this disparity correlates strongly with multiple indicators of social vulnerability and summer daytime surface UHI intensity, highlighting the challenges that vulnerable urban populations face in adapting to climate-change driven heat stress amplification.

54 ENVIRONMENTAL SCIENCES↗

Towards Improving Container Security by Preventing Runtime Escapes

Container escapes enable the adversary to execute code on the host from inside an isolated container. Notably, these high severity escape vulnerabilities originate from three sources: (1) container profile misconfigurations, (2) Linux kernel bugs, and (3) container runtime vulnerabilities. While the first two cases have been studied in the literature, no works have investigated the impact of container runtime vulnerabilities. In this paper, to fill this gap, we study 59 CVEs for 11 different container runtimes. As a result of our study, we found that five of the 11 runtimes had nine publicly available PoC container escape exploits covering 13 CVEs. Our further analysis revealed all nine exploits are the result of a host component leaked into the container. Here, we apply a user namespace container defense to prevent the adversary from leveraging leaked host components and demonstrate that the defense stops seven of the nine container escape exploits.

42 ENGINEERING↗

Managing Wildfire Risk and Promoting Equity through Optimal Configuration of Networked Microgrids

As climate change increases the risk of large-scale wildfires, wildfire ignitions from electric power lines are a growing concern. To mitigate the wildfire ignition risk, many electric utilities de-energize power lines to prevent electric faults and failures. These preemptive power shutoffs are effective in reducing ignitions, but they could result in wide-scale power outages. Advanced technology, such as networked microgrids, can help reduce the size of the resulting power outages; however, even microgrid technology might not be sufficient to supply power to everyone, thus forcing hard questions about how to prioritize the provision of power among customers. In this paper, we present an optimization problem that configures networked microgrids to manage wildfire risk while maximizing the power served to customers; however, rather than simply maximizing the amount of power served in kilowatts, our formulation also considers the ability of customers to cope with power outages, as measured by social vulnerability, and it discourages the disconnection of particularly vulnerable customer groups. To test our model, we leverage a synthetic but realistic distribution feeder, along with publicly available social vulnerability indices and satellite-based wildfire risk map data, to quantify the parameters in our optimal decision-making model. Our case study results demonstrate the benefits of networked microgrids in limiting load shed and promoting equity during scenarios with high wildfire risk.

distribution systems↗

Machine Learning-based Intrusion Detection for Smart Grid Computing: A Survey

Machine learning (ML)-based intrusion detection system (IDS) approaches have been significantly applied and advanced the state-of-the-art system security and defense mechanisms. In smart grid computing environments, security threats have been significantly increased as shared networks are commonly used, along with the associated vulnerabilities. However, compared to other network environments, ML-based IDS research in a smart grid is relatively unexplored, although the smart grid environment is facing serious security threats due to its unique environmental vulnerabilities. In this article, we conducted an extensive survey on ML-based IDS in smart grids based on the following key aspects: (1) The applications of the ML-based IDS in transmission and distribution side power components of a smart power grid by addressing its security vulnerabilities; (2) dataset generation process and its usage in applying ML-based IDSs in the smart grid; (3) a wide range of ML-based IDSs used by the surveyed papers in the smart grid environment; (4) metrics, complexity analysis, and evaluation testbeds of the IDSs applied in the smart grid; and (5) lessons learned, insights, and future research directions.

SCADA↗

Transportation Fuel Resiliency: Case Study of Tampa Bay

Here, this case study presents findings from an analysis of the emergency preparation and response for Hurricane Irma, the most recent hurricane impacting the Tampa Bay region. The Tampa Bay region, in particular, is considered one of the most vulnerable areas in the United States to hurricanes and severe tropical weather. A particular vulnerability stems from how all petroleum fuel comes to the area by marine transport through Port Tampa Bay, which can be (and has been in the past) impacted by hurricanes and tropical storms. The case study discussed in this paper covers previous fuel challenges, vulnerabilities, and lessons learned by key Tampa Bay public agency fleets during the past 10 years (mainly as a result of the most recent 2017 Hurricane Irma) to explore ways to improve the area’s resilience to natural disasters. Some of the strategies for fuel-supply resiliency include maintaining emergency fuel supply, prioritizing fuel use, strategically placing the assets around the region to help with recovery, investing in backup generators (including generators powered by alternative fuels), planning for redundancies in fuel supply networks, developing more efficient communication procedures between public fleets, hurricane preparedness-planning, and upgrading street drainage systems to reduce the threat of local flooding.

33 ADVANCED PROPULSION SYSTEMS↗

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

Test and Evaluation of Systems with Embedded Machine Learning Components

As Machine Learning (ML) continues to advance, it is being integrated into more systems. Often, the ML component represents a significant portion of the system that reduces the burden on the end user or significantly improves task performance. However, the ML component represents an unknown complex phenomenon that is learned from collected data without the need to be explicitly programmed. Despite the improvement in task performance, the models are often black boxes. Evaluating the credibility and the vulnerabilities of ML models poses a gap in current test and evaluation practice. For high consequence applications, the lack of testing and evaluation procedures represents a significant source of uncertainty and risk. To help reduce that risk, here we present considerations to evaluate systems embedded with an ML component within a red-teaming inspired methodology. We focus on (1) cyber vulnerabilities to an ML model, (2) evaluating performance gaps, and (3) adversarial ML vulnerabilities.

97 MATHEMATICS AND COMPUTING↗