Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Climate Impact and GIS Education Using Realistic Applications of Data.gov Thematic Datasets in a Structured Lesson-Based Workbook

This project created a workbook which teaches Earth Science to undergraduate and graduate students through guided in-class activities and take-home assignments organized around climate topics which use GIS to teach key geospatial analysis techniques and cartography skills. The workbook is structured to the White House's Data.gov climate change themes, which include Coastal Flooding, Ecosystem Vulnerability, Energy Infrastructure, Arctic, Food Resilience, Human Health, Transportation, Tribal Nations, and Water. Each theme provides access to framing questions, associated data, interactive tools, and further reading (e.g. The US Climate Resilience Toolkit and National Climate Assessment). Lessons make use of the respective theme's available resources. The structured thematic approach is designed to encourage independent exploration. The goal is to teach climate concepts and concerns, GIS techniques and approaches, and effective cartographic representation and communication results; and foster a greater awareness of publicly available resources and datasets. To reach more audiences more effectively, a two level approach was used. Level 1 serves as an introductory study and relies on only freely available interactive tools to reach audiences with fewer resources and less familiarity. Level 2 presents a more advanced case study, and focuses on supporting common commercially available tool use and real-world analysis techniques.

Satellite Imagery↗

Theoretical Analysis and Experimental Validation of Flying-Capacitor Multilevel Converters Under Short-Circuit Fault Conditions

Addressing the increasing demand for high- efficiency and high-power-density converters, the flying-capacitor multilevel converter has shown itself as a promising topology. A key advantage of this topology is the reduced voltage rating of the switches, though also makes it vulnerable to device failure during short-circuit conditions. Despite large interest in fault-tolerant operation of these converters, alongside detailed descriptions of flying capacitor balancing, little research has focused on the converter short-circuit fault analysis, which may cause a switch failure if not properly designed for. Therefore, this work presents a comprehensive model describing the large- signal short-circuit switching behavior of a general N -level flying- capacitor multilevel converter. Highly simplified models used to predict the evolution of the switch current and voltage stress during the fault are proposed, targeted at practicing engineers for conservative design guidelines. These models are used to determine the critical time for remedial action of the converter before reaching some predefined maximum conditions. A 2-to-10- level fully-configurable flying-capacitor multilevel converter and a fault circuit hardware prototype are used to experimentally perform different short-circuit tests that show a good match to the measured behavior.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Understanding the Nature of Capacity Decay and Interface Properties in Li//LiNi 0.5 Mn 1.5 O 4 Cells by Cycling Aging and Titration Techniques

The spinel structure LiNi 0.5 Mn 1.5 O 4 (LNMO) is a propitious cathode material for next-generation lithium-ion batteries for fast charge–discharge applications, but its capacity decay mechanism and rate-limiting process are not yet well understood. In this work, electrochemical impedance spectroscopy (EIS) with galvanostatic intermittent titration (GITT) and cycling aging techniques were employed to investigate the nature of capacity decay in disordered-phase LNMO. Different resistive components were separated after every 10 cycles. Cell overvoltages (ΔVs) due to ohmic conduction, charge transfer (CT), and concentration polarization (CP) were individually determined. Results revealed that the cell exhibited a higher ΔV at a higher discharged state. However, the ΔV value for CP was higher at a higher state of charge (SOC), and the overall LNMO/electrolyte interface played a major role in the rate-determining step. Battery life was estimated based on the results. Battery calendar life was found to be more vulnerable than cycle life. Furthermore, results also indicated that the working SOC range could be optimized based on the resistance analysis by avoiding those SOCs that have the most detrimental impact (e.g., heat generation and fire hazard).

25 ENERGY STORAGE↗

Advancing Electric System Resilience with Distributed Energy Resources: A Review of State Policies

Severe weather, cyber-attacks, geomagnetic disturbances, and other hazards and threats have caused or have the potential to cause substantial levels of damage to electricity infrastructure and the global economy. Growth in distributed energy resources (DERs) and increasing attention to the resilience of the electric grid - its ability to "anticipate, absorb, adapt to, and/or rapidly recover" from disruptions, according to the Federal Energy Regulatory Commission (FERC, 2018) - have created an opportunity for energy stakeholders to develop and deploy "resilient DERs," resources in the distribution grid that improve the ability of a customer, critical facility, and/or the distribution system in general to anticipate, absorb, adapt to, and/or rapidly recover from disruptions. This paper explores how existing state regulations intersect with resilience and highlights opportunities where state regulators can employ DERs to advance resilience.

14 SOLAR ENERGY↗

Dynamic analysis of heart rate may predict subsequent ventricular tachycardia after myocardial infarction

Dynamics analysis of RR interval behavior and traditional measures of heart rate variability were compared between postinfarction patients with and without vulnerability to ventricular tachyarrhythmias in a case-control study. Short-term fractal correlation of heart rate dynamics was better than traditional measures of heart rate variability in differentiating patients with and without life-threatening arrhythmias.

NASA Discipline Cardiopulmonary↗

MSW Variability Mapping and Conversion to Biofuel

MSW (Municipal Solid Waste) is a form of biomass which consists of categorized components of waste/trash. The general categories are paper, yard trash, construction & debris, appliances, tires, glass, metals, aluminum & steel cans, plastics, organics, inorganics, and HHW (Household Hazardous Waste). This project focuses on the factors within a region or population that contribute to variability in the composition of MSW and in turn MSW’s convertibility to biofuel. A list of contributors was determined (Social Vulnerability Index, Access to Public Transportation, Racial Distribution, GDP, Personal Income) and then JMP was used to perform a Multivariate analysis to determine correlations and a Partial Least-Squares regression to determine Variable Importance Plots for each MSW category. In addition to data analysis, the convertibility of MSW to biofuel was studied via microwave pyrolysis system in order to separate and characterize the various gaseous and bio-oil products.

09 BIOMASS FUELS↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Climate-driven deoxygenation elevates fishing vulnerability for the ocean's widest ranging shark

Climate-driven expansions of ocean hypoxic zones are predicted to concentrate pelagic fish in oxygenated surface layers, but how expanding hypoxia and fisheries will interact to affect threatened pelagic sharks remains unknown. Here, analysis of satellite-tracked blue sharks and environmental modelling in the eastern tropical Atlantic oxygen minimum zone (OMZ) shows shark maximum dive depths decreased due to combined effects of decreasing dissolved oxygen (DO) at depth, high sea surface temperatures, and increased surface-layer net primary production. Multiple factors associated with climate-driven deoxygenation contributed to blue shark vertical habitat compression, potentially increasing their vulnerability to surface fisheries. Greater intensity of longline fishing effort occurred above the OMZ compared to adjacent waters. Higher shark catches were associated with strong DO gradients, suggesting potential aggregation along suitable DO gradients contributed to habitat compression and higher fishing-induced mortality. Fisheries controls to counteract deoxygenation effects on shark catches will be needed as oceans continue warming.

Vedor, Marisa↗

Investigating the opioid epidemic across the United States: Associations between county-level characteristics and overdose mortality

The opioid crisis remains a critical public health challenge in the United States. Despite national efforts that reduced opioid prescribing by nearly 44% between 2011 and 2021, opioid overdose deaths more than tripled during the same period. This alarming trend reflects a major shift in the crisis, with illegal opioids now driving the majority of overdose deaths instead of prescription opioids. Although supply-side factors fueling this transition have been widely studied, the structural and community-level conditions that shape overdose mortality are less well understood. To help address this gap, this study has three primary objectives: (1) overcome structural gaps in national data to construct a complete nationwide county-level dataset from 2010 to 2022; (2) using data analysis, identify and investigate spatiotemporal anomalies in overdose mortality; and (3) using two machine-learning models, quantify the importance of thirteen social vulnerability variables in predicting overdose mortality. Our results identify unemployment and limited vehicle access as key county-level predictors of overdose mortality. Higher levels of these vulnerabilities are associated with elevated mortality, whereas lower levels are associated with reduced mortality. These findings highlight factors that may be relevant for public health planning and policy prioritization within the context of the opioid crisis.

Anomaly analysis↗

CARVE: The Carbon in Arctic Reservoirs Vulnerability Experiment

The Carbon in Arctic Reservoirs Vulnerability Experiment (CARVE) is a NASA Earth Ventures (EV-1) investigation designed to quantify correlations between atmospheric and surface state variables for the Alaskan terrestrial ecosystems through intensive seasonal aircraft campaigns, ground-based observations, and analysis sustained over a 5-year mission. CARVE bridges critical gaps in our knowledge and understanding of Arctic ecosystems, linkages between the Arctic hydrologic and terrestrial carbon cycles, and the feedbacks from fires and thawing permafrost. CARVE's objectives are to: (1) Directly test hypotheses attributing the mobilization of vulnerable Arctic carbon reservoirs to climate warming; (2) Deliver the first direct measurements and detailed maps of CO2 and CH4 sources on regional scales in the Alaskan Arctic; and (3) Demonstrate new remote sensing and modeling capabilities to quantify feedbacks between carbon fluxes and carbon cycle-climate processes in the Arctic (Figure 1). We describe the investigation design and results from 2011 test flights in Alaska.

Arctic Carbon Cycle↗

Stem hydraulic conductivity and vulnerability to cavitation for 26 tree species in Panama

Stem hydraulic conductivity and vulnerability to cavitation were measured for 26 tree species located in Panama. The data were generated to better understand the ecology of the focal tree species. Complementary NGEE-Tropics datasets for these species include sap flow, leaf-level gas exchange, and leaf water potential. Stem samples were collected from distal branches of canopy trees, brought to the Smithsonian Tropical Research Institute laboratory in Gamboa, Panama, and allowed to dry to various water potentials before measurements. For each species, a Weibull function was fit to the 90% quantile of the relationship between stem area specific hydraulic conductivity (Ks) and stem water potential. From these functions, maximum Ks and vulnerability parameters were derived. The data files in the package include raw data, derived parameters, and the R script used for analysis.

54 ENVIRONMENTAL SCIENCES↗

tell: a Python package to model future total electricity loads in the United States

The purpose of the Total ELectricity Load (tell) model is to generate 21st century profiles of hourly electricity load (demand) across the Conterminous United States (CONUS). tell loads reflect the impact of climate and socioeconomic change at a spatial and temporal resolution adequate for input to an electricity grid operations model. tell uses machine learning to develop profiles that are driven by projections of climate/meteorology and population. tell also harmonizes its results with United States (U.S.) state-level, annual projections from a national- to global-scale energy-economy model. This model accounts for a wide range of other factors affecting electricity demand, including technology change in the building sector, energy prices, and demand elasticities, which stems from model coupling with the U.S. version of the Global Change Analysis Model (GCAM-USA). tell was developed as part of the Integrated Multisector Multiscale Modeling (IM3) project. IM3 explores the vulnerability and resilience of interacting energy, water, land, and urban systems in response to compound stressors, such as climate trends, extreme events, population, urbanization, energy system transitions, and technology change

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Precision Projector Laboratory: Detector Characterization with an Astronomical Emulation Testbed

As astronomical observations benefit from improved sensitivity, the effectiveness of scientific programs is becoming limited by systematics that often originate in poorly understood image sensor behavior. Traditional, bottom-up detector characterization methods provide one way to model underlying detector physics, and generate ever more faithful numerical simulations, but this approach is vulnerable to preconceptions and over-simplification. The alternative top-down approach is laboratory emulation, which enables observation, calibration, and analysis scenarios to be tested without relying on a complete understanding of the underlying physics. This complements detector characterization and simulation efforts by testing their validity. We describe a laboratory facility and experimental testbed that supports the emulation of a wide range of mission concepts such as gravitational weak lensing measurements by WFIRST and high precision spectrophotometry of transiting exoplanets by JWST. An Offner relay projects readily customizable "scenes" (e.g. stars, galaxies, spectra) with very low optical aberration over the full area of a typical optical or near infrared image sensor. f/8 and slower focal ratios may be selected, spanning those of most proposed space missions and approximating the point spread function (PSF) size of seeing limited ground based surveys. Diffraction limited PSFs are projected over a wide field of view and wavelength range to deliver highly predictable image patterns down to sub-pixel scales with stable intensity and fine motion control. The testbed enables realistic validation of detector performance on science-like images, which aids mission design and survey strategy, as well as targeted investigations of various detector effects.

Seshadri, Suresh↗

Simulating Alpha Particles Incident on MKID Chips for Quantum Sensitivity Analysis

Superconducting quantum devices, such as microwave kinetic inductance detectors (MKIDs), are highly sensitive instruments used in quantum computing and advanced sensing technologies. However, their extreme sensitivity also makes them vulnerable to background noise from natural sources like radiation. One significant contributor to this noise is alpha particles emitted by 210Po, a radon decay daughter that accumulates on surfaces near the detector. This project investigates how alpha particles emitted from 210Po interact with MKID chips. These particles can deposit energy on the detector surface, disrupting its operation and generating false signals. Understanding the energy and behavior of these particles is crucial for improving the design and reliability of quantum devices. To explore this, we first modeled the decay chain starting from 210Pb to 210Po using differential equations. This allowed us to predict how the activity of alpha-emitting isotopes changes over time, reaching a steady state after about two years. Next, we simulated alpha particle interactions with the MKID chip using the Geant4 software toolkit. We built a detailed computer model of the detector housing, including the copper lid where alpha particles originate, the silicon chip, and a thin aluminum sensor layer. Alpha particles were emitted isotropically from just beneath the copper lid’s surface, mimicking natural decay conditions. The simulation tracked how these particles deposit energy on the chip, generating electron-hole pairs and phonons. The results provide insight into the behavior of the resultant electron-hole pairs and phonons, giving us a clear understanding of the energy deposition distribution on the chip. This work supports efforts to mitigate background noise in superconducting sensors, advancing their use in quantum computing and sensitive physics experiments.

Hall, Matthew [Fermilab; UCLA]↗

Accelerating Hanford Site Cleanup through Operations Research Modeling - 20238

The Hanford Site cleanup effort will require the integration of dozens of unique facilities and processes, many of which will be first-of-a-kind in implementation and design. Each facility will be governed by its own set of operating logic, configured with a unique array of unit operations, and subject to a set of constraints that will affect its behavior. The collection of facilities have multiple points of interface, making the operations of any one facility potentially significant to the operations of other up- or downstream processes. It is therefore highly desirable to accurately predict these operations, as it allows for Site officials to identify and preempt bottlenecks and vulnerabilities before they unexpectedly inhibit the cleanup mission. With the quantity and complexity of the processes that will be on Site, building a pen-and-paper or even a spreadsheet-assisted model of the cleanup mission quickly becomes overwhelming in scope and inaccurate in execution. The Engineering organization for the Site's Tank Operations Contract (TOC) has therefore implemented the use of operations research (OR) modeling to simulate and predict future operations of Site facilities. These models are created using a discrete event simulation tool that allows for the development of detailed, versatile, and robust models. Not only can these models account for complex logical behaviors, but they can also simulate process details down to the level of vessel sizing, labor utilization, equipment reliability, and resource availability. To date, the TOC has developed OR models for several facilities on Site, including for single-shell tank (SST) farms, double-shell tank (DST) farms, the Effluent Treatment Facility (ETF), and the waste transfer system. These models have focused on identifying bottlenecks and operational constraints, and have been used to quantify the effects of implementing process changes. This latter point is particularly valuable, as it allows for several alternatives to be studied in a virtual setting before committing resources to making a change in the field. The decision to develop OR models has gained tremendous support from the Site's stakeholders and the U.S. Department of Energy (DOE) management, and has prompted the use of the tool to support additional internal and external initiatives. Recently, an initiative was proposed to use the models to help identify and provide quantitative backing for risks and opportunities for the TOC. This application of OR could not only help inform how the TOC manages its risks (e.g. quantities and types of spare parts), but could also help drive process improvements whose benefits might otherwise be hard to quantify. The models have also been used to drive the TOC's cloud computing, artificial intelligence (AI), and machine learning (ML) initiatives. These initiatives will not only improve the ability of the TOC to more rapidly respond to the needs of its customers, but it will also aid in the ability of the TOC to analyze and improve the processes it studies. Partnership with two external software development and consulting companies (Lanner and Ynformed) has furthered not only the application of AI and ML within the TOC, but has also spurred the development of new/improved software tools and platforms used by the companies. These partnerships have proven to be mutually beneficial and productive, and have set a precedent for the types of gains that can be made by exploring such options. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Requirements and Recommendations for a Physical Attack Characterization Framework

This study seeks to identify existing frameworks or develop requirements and recommendations for a new framework that can consistently characterize physical attacks, analogous to MITRE ATT&CK®. MITRE ATT&CK is widely used across government, research organizations, and the cyber security community to characterize cyber attack tactics, techniques, and procedures (TTPs) in a consistent and commonly understood manner. While physical attack taxonomies, methodologies, and other tools for evaluating physical security do exist, many are sector and/or facility-type specific—and therefore not able to provide comparable scenarios across sectors—or are more focused on security assessment instead of the characterization of attacks themselves. A MITRE ATT&CK analog for physical attacks on critical infrastructure would provide a common language and structure for analysis of physical attacks. Existing attack characterization methodologies do not robustly address cyber-physical security risks. To fully understand a facility’s security needs, it is important to understand the entire vulnerability landscape from both a physical and a cyber perspective. To underscore this need, organizations such as the Cybersecurity and Infrastructure Security Agency (CISA) are calling for a coordinated approach to cyber and physical security, which they refer to as cyber and physical security convergence. A physical attack characterization framework that could be used jointly with MITRE ATT&CK would help support a more robust analysis in support of convergence, enabling the consistent characterization of attacks that utilize both cyber and physical tactics and techniques. This could provide analysts and stakeholders with a clearer understanding of how security mitigations deployed in the physical realm impact security risks in the cyber realm, and vice versa. In this study, the project team evaluates existing physical security taxonomies and methodologies to assess whether an existing method can be used to create a “physical half” of MITRE ATT&CK. This study then provides requirements and recommendations for a framework that can leverage aspects of existing methodologies. The goal of the final framework is for it to be widely adopted and referenced, regardless of critical infrastructure sector, facility type, or facility components. This study also identifies applicable use cases for when and how a framework could be applied across the various critical infrastructure sectors for a variety of attack types or motivations. Through a literature review of existing security-focused methodologies and taxonomies, engagement with relative stakeholders, evaluation of potential physical attack framework use cases, and subsequent identification of requirements, this study identified the following key findings and recommendations: There is a need for a new physical attack characterization framework; A physical attack framework should be interoperable with the MITRE ATT&CK framework; A physical attack framework should be broadly applicable, but with detailed tactics, techniques, and procedures that encompass the entire attack path; A physical attack framework should be based on observed or feasible events; A physical attack framework should adapt features from existing methodologies, frameworks, and taxonomies; A physical attack framework should be owned, overseen, and maintained by one organization.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗